arduino / arduino/ArduinoCore-API

Uninitalised memory when copying String with embedded NUL character

Ouverte
#111 2 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
C++
Étoiles
306
Forks
150
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

When you create a String object with an embedded NUL character, and you copy this String, the memory after the NUL byte is not copied, leading to uninitialised memory being used.

Here's sample code to show the error:
```
String sGlobal;

void dumpString(const String &s)
{
Serial.print("Got a string of length ");
Serial.println(s.length());
Serial.print(">");
for (size_t t = 0; t < s.length(); ++t) {
if (s.charAt(t) != '\0' && isascii(s.charAt(t))) {
Serial.print(s.charAt(t));
} else if (s.charAt(t) == '\0') {
Serial.print("\\0");
} else {
Serial.print("\\x");
Serial.print(s.charAt(t), HEX);
}
}
Serial.print("<");

Serial.println();
}

void encode(String &s)
{
while (s.length() < 12)
{
s += ' ';
}

Serial.println("s in encode is, after filling with spaces:");
dumpString(s);

s.setCharAt(11, '!');
s.setCharAt(10, 'd');
s.setCharAt(9, 'l');
s.setCharAt(8, 'r');
s.setCharAt(7, 'o');
s.setCharAt(6, 'w');
s.setCharAt(5, '\0');
s.setCharAt(4, 'o');
s.setCharAt(3, 'l');
s.setCharAt(2, 'l');
s.setCharAt(1, 'e');
s.setCharAt(0, 'H');

Serial.println("s in encode is, after setting its chars:");
dumpString(s);

}

void test() {
String sLocal;
Serial.println("sLocal in test is, after init:");
dumpString(sLocal);
Serial.println("sGlobal in test is, after init:");
dumpString(sGlobal);

encode(sLocal);
Serial.println("sLocal in test is, after encode:");
dumpString(sLocal);
Serial.println("sGlobal in test is, after encode:");
dumpString(sGlobal);

sGlobal = sLocal;
Serial.println("sGlobal in test is, after assignment:");
dumpString(sGlobal);
}

void setup()
{
Serial.begin(115200);

test();
}

void loop()
{
}
```

Output of the code:
```
Local in test is, after init:
Got a string of length 0
><
sGlobal in test is, after init:
Got a string of length 0
><
s in encode is, after filling with spaces:
Got a string of length 12
> <
s in encode is, after setting its chars:
Got a string of length 12
>Hello\0world!<
sLocal in test is, after encode:
Got a string of length 12
>Hello\0world!<
sGlobal in test is, after encode:
Got a string of length 0
><
sGlobal in test is, after assignment:
Got a string of length 12
>Hello\0n\xFFFFFFEF\xFFFFFFD6\xFFFFFFFF\<
```

Please merge #97 to fix this issue, or at least use ``memcpy()`` instead of ``strcpy()`` to initialise the data.

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

Commencez par reproduire le sketch Arduino fourni et examinez les chemins de copie et d’affectation de String impliqués dans sGlobal = sLocal. Comparez le comportement avec le fix proposé dans issue #97, en vous concentrant sur le cas d’un NUL intégré. C’est terminé lorsque la copie préserve la valeur complète de 12 octets, y compris les octets situés après le NUL, sans données non initialisées.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
cpp
Domaine
embedded-iot
Type d'issue
Bug
Difficulté
2/5
Temps estimé
1-3 heures
Activité
À l'abandon
Clarté
Clairement spécifiée
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.