Skip to content

[net][at] Reject overlong numeric hostnames - #11782

Open
wyf-777 wants to merge 1 commit into
RT-Thread:masterfrom
wyf-777:fix/at-resolver-numeric-host-overflow
Open

[net][at] Reject overlong numeric hostnames#11782
wyf-777 wants to merge 1 commit into
RT-Thread:masterfrom
wyf-777:fix/at-resolver-numeric-host-overflow

Conversation

@wyf-777

@wyf-777 wyf-777 commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

拉取/合并请求描述:(PR description)

为什么提交这份PR (why to submit this PR)

_gethostbyname_by_device() copied numeric-looking hostnames into a 16-byte
stack buffer with strncpy(ipstr, name, strlen(name)). A 16-byte input removed
the terminator, while a 17-byte or longer input wrote beyond the buffer before
inet_aton() could reject it.

This path is reachable through the AT-backed resolver APIs, including
getaddrinfo() and gethostbyname*().

你的解决方案是什么 (what is your solution)

Cache the hostname length once, classify characters with the required unsigned
ctype input, and reject numeric-looking strings that cannot fit in ipstr.
For accepted strings, copy the validated length and add the terminator
explicitly. This keeps the existing AT/domain resolution behavior unchanged and
removes the unbounded stack write.

Fixes #11332

请提供验证的bsp和config (provide the config and bsp)

  • BSP: Host-side validation using bsp/simulator headers and MSVC; no physical hardware required.
  • .config: Compile-time coverage for RT_USING_AT, AT_USING_SOCKET, RT_USING_SAL, and RT_USING_NETDEV.
  • action: GitHub Actions pending.

Testing

  • PASS: MSVC /W4 /RTC1 /GS boundary harness using the numeric-host branch:
    15 bytes accepted, 16 and 17 bytes rejected.
  • PASS: Direct compile of components/net/at/at_socket/at_socket.c with MSVC
    /W4; no warnings in the changed lines.
  • PASS: MSVC /analyze; no diagnostics in the changed code.
  • PASS: clang-format --dry-run --Werror -style=file -lines=1409:1457.
  • PASS: git diff --check.

AI assistance: OpenAI Codex:GPT-5 assisted with investigation, implementation,
and local verification. The commit contains the matching Assisted-by trailer.

当前拉取/合并请求的状态 Intent for your PR

必须选择一项 Choose one (Mandatory):

  • 本拉取/合并请求是一个草稿版本 This PR is for a code-review and is intended to get feedback
  • 本拉取/合并请求是一个成熟版本 This PR is mature, and ready to be integrated into the repo

代码质量 Code Quality:

我在这个拉取/合并请求中已经考虑了 As part of this pull request, I've considered the following:

  • 已经仔细查看过代码改动的对比 Already check the difference between PR and old code
  • 代码风格正确,包括缩进空格,命名及其他风格 Style guide is adhered to, including spacing, naming and other styles
  • 没有垃圾代码,代码尽量精简,不包含#if 0代码,不包含已经被注释了的代码 All redundant code is removed and cleaned up
  • 所有变更均有原因及合理的,并且不会影响到其他软件组件代码或BSP All modifications are justified and not affect other components or BSP
  • 对难懂代码均提供对应的注释 I've commented appropriately where code is tricky
  • 代码是高质量的 Code in this PR is of high quality
  • 已经使用clang-format 源码格式化工具确保格式符合RT-Thread代码规范 This PR has been formatted with clang-format and complies with RT-Thread code specification
  • 如果是新增bsp, 已经添加ci检查到.github/ALL_BSP_COMPILE.json 详细请参考链接BSP自查

Numeric hostnames were copied into a fixed stack buffer without a length bound.

Cache the length, reject values that cannot fit, and terminate the copy explicitly.

Fixes RT-Thread#11332

Assisted-by: OpenAI Codex:GPT-5
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

👋 感谢您对 RT-Thread 的贡献!Thank you for your contribution to RT-Thread!

为确保代码符合 RT-Thread 的编码规范,请在你的仓库中执行以下步骤运行代码格式化工作流(如果格式化CI运行失败)。
To ensure your code complies with RT-Thread's coding style, please run the code formatting workflow by following the steps below (If the formatting of CI fails to run).


🛠 操作步骤 | Steps

  1. 前往 Actions 页面 | Go to the Actions page
    点击进入工作流 → | Click to open workflow →

  2. 点击 Run workflow | Click Run workflow

  • Use workflow from 保持默认分支(通常为 master
    Keep the default branch (usually master) in Use workflow from
  • branch 输入框填写 PR 分支 fix/at-resolver-numeric-host-overflow
    Enter PR branch fix/at-resolver-numeric-host-overflow in the branch field
  • 设置需排除的文件/目录(目录请以"/"结尾)
    Set files/directories to exclude (directories should end with "/")
  1. 等待工作流完成 | Wait for the workflow to complete
    格式化后的代码将作为独立提交推送至你的分支。
    The formatting changes will be pushed to your branch as a separate commit.

完成后,提交将自动更新至 fix/at-resolver-numeric-host-overflow 分支,关联的 Pull Request 也会同步更新。
Once completed, commits will be pushed to the fix/at-resolver-numeric-host-overflow branch automatically, and the related Pull Request will be updated.

如有问题欢迎联系我们,再次感谢您的贡献!💐
If you have any questions, feel free to reach out. Thanks again for your contribution!

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

📌 Code Review Assignment

🏷️ Tag: components

Reviewers: @Maihuanyi

Changed Files (Click to expand)
  • components/net/at/at_socket/at_socket.c

🏷️ Tag: components_net_at

Reviewers: @Ryan-CW-Code @lizhen9880

Changed Files (Click to expand)
  • components/net/at/at_socket/at_socket.c

📊 Current Review Status (Last Updated: 2026-09-07 12:13 CST)


📝 Review Instructions

  1. 维护者可以通过单击此处来刷新审查状态: 🔄 刷新状态
    Maintainers can refresh the review status by clicking here: 🔄 Refresh Status

  2. 确认审核通过后评论 LGTM/lgtm
    Comment LGTM/lgtm after confirming approval

  3. PR合并前需至少一位维护者确认
    PR must be confirmed by at least one maintainer before merging

ℹ️ 刷新CI状态操作需要具备仓库写入权限。
ℹ️ Refresh CI status operation requires repository Write permission.

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] RT-Thread AT socket resolver: user-controlled numeric hostname triggers kernel stack overflow via getaddrinfo()/gethostbyname*()

1 participant