fix wrong length returned from l2_eth_rx

This commit is contained in:
Sergio R. Caprile
2025-12-19 14:11:13 -03:00
parent 16d8e3b4f9
commit 2bfcfeb359
4 changed files with 53 additions and 39 deletions
+1 -1
View File
@@ -3416,7 +3416,7 @@ bool mg_l2_eth_rx(struct mg_tcpip_if *ifp, enum mg_l2proto *proto,
return false;
}
pay->buf = (char *) (eth + 1);
pay->len = len;
pay->len = len - sizeof(*eth);
type = mg_htons(eth->type);
for (i = 0; i < sizeof(eth_types) / sizeof(uint16_t); i++) {
+35 -35
View File
@@ -3932,6 +3932,41 @@ struct mg_tcpip_driver_tms570_data {
#if MG_ENABLE_TCPIP && defined(MG_ENABLE_DRIVER_XMC7) && MG_ENABLE_DRIVER_XMC7
struct mg_tcpip_driver_xmc7_data {
int mdc_cr; // Valid values: -1, 0, 1, 2, 3, 4, 5
uint8_t phy_addr;
};
#ifndef MG_TCPIP_PHY_ADDR
#define MG_TCPIP_PHY_ADDR 0
#endif
#ifndef MG_DRIVER_MDC_CR
#define MG_DRIVER_MDC_CR 3
#endif
#define MG_TCPIP_DRIVER_INIT(mgr) \
do { \
static struct mg_tcpip_driver_xmc7_data driver_data_; \
static struct mg_tcpip_if mif_; \
driver_data_.mdc_cr = MG_DRIVER_MDC_CR; \
driver_data_.phy_addr = MG_TCPIP_PHY_ADDR; \
mif_.ip = MG_TCPIP_IP; \
mif_.mask = MG_TCPIP_MASK; \
mif_.gw = MG_TCPIP_GW; \
mif_.driver = &mg_tcpip_driver_xmc7; \
mif_.driver_data = &driver_data_; \
MG_SET_MAC_ADDRESS(mif_.mac); \
mg_tcpip_init(mgr, &mif_); \
MG_INFO(("Driver: xmc7, MAC: %M", mg_print_mac, mif_.mac)); \
} while (0)
#endif
#if MG_ENABLE_TCPIP && defined(MG_ENABLE_DRIVER_XMC) && MG_ENABLE_DRIVER_XMC
struct mg_tcpip_driver_xmc_data {
@@ -3978,41 +4013,6 @@ struct mg_tcpip_driver_xmc_data {
#endif
#if MG_ENABLE_TCPIP && defined(MG_ENABLE_DRIVER_XMC7) && MG_ENABLE_DRIVER_XMC7
struct mg_tcpip_driver_xmc7_data {
int mdc_cr; // Valid values: -1, 0, 1, 2, 3, 4, 5
uint8_t phy_addr;
};
#ifndef MG_TCPIP_PHY_ADDR
#define MG_TCPIP_PHY_ADDR 0
#endif
#ifndef MG_DRIVER_MDC_CR
#define MG_DRIVER_MDC_CR 3
#endif
#define MG_TCPIP_DRIVER_INIT(mgr) \
do { \
static struct mg_tcpip_driver_xmc7_data driver_data_; \
static struct mg_tcpip_if mif_; \
driver_data_.mdc_cr = MG_DRIVER_MDC_CR; \
driver_data_.phy_addr = MG_TCPIP_PHY_ADDR; \
mif_.ip = MG_TCPIP_IP; \
mif_.mask = MG_TCPIP_MASK; \
mif_.gw = MG_TCPIP_GW; \
mif_.driver = &mg_tcpip_driver_xmc7; \
mif_.driver_data = &driver_data_; \
MG_SET_MAC_ADDRESS(mif_.mac); \
mg_tcpip_init(mgr, &mif_); \
MG_INFO(("Driver: xmc7, MAC: %M", mg_print_mac, mif_.mac)); \
} while (0)
#endif
#ifdef __cplusplus
}
#endif
+1 -1
View File
@@ -87,7 +87,7 @@ bool mg_l2_eth_rx(struct mg_tcpip_if *ifp, enum mg_l2proto *proto,
return false;
}
pay->buf = (char *) (eth + 1);
pay->len = len;
pay->len = len - sizeof(*eth);
type = mg_htons(eth->type);
for (i = 0; i < sizeof(eth_types) / sizeof(uint16_t); i++) {
+16 -2
View File
@@ -86,9 +86,19 @@ int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
// Test built-in TCP/IP stack
if (size > 0) {
struct mg_tcpip_if mif = {.ip = 0x01020304,
struct mg_tcpip_if mif = {.ip = 1,
.mask = 255,
.gw = 0x01010101,
.gw = 1,
.gw_ready = true,
.state = MG_TCPIP_STATE_READY,
#if MG_ENABLE_IPV6
.ip6[0] = 1;
.prefix[0] = 1;
.prefix_len = 64;
.gw6[0] = 1;
.gw6_ready = true;
.state6 = MG_TCPIP_STATE_READY; // so mg_send() works and RS stops
#endif
.driver = &mg_tcpip_driver_mock};
struct mg_mgr mgr;
mg_mgr_init(&mgr);
@@ -151,6 +161,10 @@ int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
}
}
#if defined(MAIN)
printf("Sending to net_builtin:\n");
mg_hexdump(pkt, size);
#endif
mg_tcpip_rx(&mif, pkt, size);
// Test HTTP serving (via our built-in TCP/IP stack)