roll: pw_toolchain, pw_toolchain: pw_grpc: Avoid buffer overflow when processing corrupt frames HTTP2 HEADERS and DATA frames are variable-length frames, that include flags that enable certain features that take up space in the frame: e.g. a "padding" bit that adds a 1-byte "padding" field, or a "priority" flag that adds a 5-byte "priority" field. The handlers for these frames did not verify the size of the frame payloads when reading these optional fields, if present. Thus, an undersized frame that had these flag bits set would lead to a buffer overread. This commit improves the handlers to explicitly check the frame sizes, and send the appropriate connection errors (according to the RFC) if they occur, without reading past the end of the payload buffer. If this occurs, it's almost certainly due to some underlying transport corruption. Original-Reviewed-on: https://pigweed-review.googlesource.com/c/pigweed/pigweed/+/216651 Lint: Lint 🤖 <android-build-ayeaye@system.gserviceaccount.com> https://pigweed.googlesource.com/pigweed/pigweed pw_toolchain, pw_toolchain Rolled-Commits: 9650f5fcbae1ea3..49d5876907ba804 Roller-URL: https://ci.chromium.org/b/8744757712942869777 GitWatcher: ignore CQ-Do-Not-Cancel-Tryjobs: true Change-Id: I2a74e69fbffecdca4ba419706f89395dc6bd1a40 Reviewed-on: https://pigweed-review.googlesource.com/c/pigweed/quickstart/bazel/+/216816 Commit-Queue: Pigweed Roller <pigweed-roller@pigweed-service-accounts.iam.gserviceaccount.com> Lint: Lint 🤖 <android-build-ayeaye@system.gserviceaccount.com> Bot-Commit: Pigweed Roller <pigweed-roller@pigweed-service-accounts.iam.gserviceaccount.com>
This repository contains a minimal example of a Bazel-based Pigweed project. It's an echo application for the STM32F429 Discovery Board.
git clone --recursive https://pigweed.googlesource.com/pigweed/quickstart/bazel
If you already cloned but forgot to include --recursive, run git submodule update --init to pull all submodules.
TODO: b/300695111 - Don't require submodules for this example.
We‘ll assume you already have Bazel on your system. If you don’t, the recommended way to get it is through Bazelisk.
To build the entire project (including building the application for both the host and the STM32 Discovery Board), run
bazel build //...
To run the application locally on your machine, run,
bazel run //src:echo
To flash the firmware to a STM32F429 Discovery Board connected to your machine, run,
bazel run //tools:flash
Note that you don't need to build the firmware first: Bazel knows that the firmware images are needed to flash the board, and will build them for you. And if you edit the source of the firmware or any of its dependencies, it will get rebuilt when you flash.
Run,
bazel run //tools:miniterm -- /dev/ttyACM0 --filter=debug
to communicate with the board. When you transmit a character, you should get the same character back!