roll: pw_toolchain, pw_toolchain: pw_grpc: Avoid buffer overflow when processing corrupt frames

HTTP2 HEADERS and DATA frames are variable-length frames, that include
flags that enable certain features that take up space in the frame: e.g.
a "padding" bit that adds a 1-byte "padding" field, or a "priority" flag
that adds a 5-byte "priority" field.

The handlers for these frames did not verify the size of the frame
payloads when reading these optional fields, if present. Thus, an
undersized frame that had these flag bits set would lead to a buffer
overread.

This commit improves the handlers to explicitly check the frame sizes,
and send the appropriate connection errors (according to the RFC) if
they occur, without reading past the end of the payload buffer.
If this occurs, it's almost certainly due to some underlying transport
corruption.

Original-Reviewed-on: https://pigweed-review.googlesource.com/c/pigweed/pigweed/+/216651
Lint: Lint 🤖 <android-build-ayeaye@system.gserviceaccount.com>

https://pigweed.googlesource.com/pigweed/pigweed
pw_toolchain, pw_toolchain Rolled-Commits: 9650f5fcbae1ea3..49d5876907ba804
Roller-URL: https://ci.chromium.org/b/8744757712942869777
GitWatcher: ignore
CQ-Do-Not-Cancel-Tryjobs: true
Change-Id: I2a74e69fbffecdca4ba419706f89395dc6bd1a40
Reviewed-on: https://pigweed-review.googlesource.com/c/pigweed/quickstart/bazel/+/216816
Commit-Queue: Pigweed Roller <pigweed-roller@pigweed-service-accounts.iam.gserviceaccount.com>
Lint: Lint 🤖 <android-build-ayeaye@system.gserviceaccount.com>
Bot-Commit: Pigweed Roller <pigweed-roller@pigweed-service-accounts.iam.gserviceaccount.com>
1 file changed
tree: b8f4a8a7395a0830012af8e3a67f8a8f3c2bf0db
  1. .github/
  2. src/
  3. targets/
  4. tools/
  5. .bazelrc
  6. .bazelversion
  7. .gitignore
  8. BUILD.bazel
  9. echo.bzl
  10. LICENSE
  11. pigweed.json
  12. README.md
  13. requirements.in
  14. requirements_lock.txt
  15. WORKSPACE
README.md

Pigweed: minimal Bazel example

This repository contains a minimal example of a Bazel-based Pigweed project. It's an echo application for the STM32F429 Discovery Board.

Cloning

git clone --recursive https://pigweed.googlesource.com/pigweed/quickstart/bazel

If you already cloned but forgot to include --recursive, run git submodule update --init to pull all submodules.

TODO: b/300695111 - Don't require submodules for this example.

Building

We‘ll assume you already have Bazel on your system. If you don’t, the recommended way to get it is through Bazelisk.

To build the entire project (including building the application for both the host and the STM32 Discovery Board), run

bazel build //...

To run the application locally on your machine, run,

bazel run //src:echo

Flashing

To flash the firmware to a STM32F429 Discovery Board connected to your machine, run,

bazel run //tools:flash

Note that you don't need to build the firmware first: Bazel knows that the firmware images are needed to flash the board, and will build them for you. And if you edit the source of the firmware or any of its dependencies, it will get rebuilt when you flash.

Communicating

Run,

bazel run //tools:miniterm -- /dev/ttyACM0 --filter=debug

to communicate with the board. When you transmit a character, you should get the same character back!