Merge branch 'bugfix/esp_local_ctrl_arg_check_v6.0' into 'release/v6.0'

fix(esp_local_ctrl): validate payload_case matches msg_type in command dispatcher (v6.0)

See merge request espressif/esp-idf!45924
This commit is contained in:
Mahavir Jain
2026-03-04 13:09:56 +05:30
7 changed files with 36 additions and 1 deletions
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2019-2024 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2019-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -25,6 +25,7 @@ static const char* TAG = "esp_local_ctrl_handler";
typedef struct esp_local_ctrl_cmd {
int cmd_num;
int expected_payload_case;
esp_err_t (*command_handler)(LocalCtrlMessage *req,
LocalCtrlMessage *resp, void **ctx);
} esp_local_ctrl_cmd_t;
@@ -41,14 +42,17 @@ static esp_err_t cmd_set_prop_vals_handler(LocalCtrlMessage *req,
static esp_local_ctrl_cmd_t cmd_table[] = {
{
.cmd_num = LOCAL_CTRL_MSG_TYPE__TypeCmdGetPropertyCount,
.expected_payload_case = LOCAL_CTRL_MESSAGE__PAYLOAD_CMD_GET_PROP_COUNT,
.command_handler = cmd_get_prop_count_handler
},
{
.cmd_num = LOCAL_CTRL_MSG_TYPE__TypeCmdGetPropertyValues,
.expected_payload_case = LOCAL_CTRL_MESSAGE__PAYLOAD_CMD_GET_PROP_VALS,
.command_handler = cmd_get_prop_vals_handler
},
{
.cmd_num = LOCAL_CTRL_MSG_TYPE__TypeCmdSetPropertyValues,
.expected_payload_case = LOCAL_CTRL_MESSAGE__PAYLOAD_CMD_SET_PROP_VALS,
.command_handler = cmd_set_prop_vals_handler
}
};
@@ -238,6 +242,12 @@ static esp_err_t esp_local_ctrl_command_dispatcher(LocalCtrlMessage *req,
return ESP_ERR_INVALID_ARG;
}
if (req->payload_case != cmd_table[cmd_index].expected_payload_case) {
ESP_LOGE(TAG, "Payload type mismatch: msg_type %d expects payload %d, got %d",
req->msg, cmd_table[cmd_index].expected_payload_case, req->payload_case);
return ESP_ERR_INVALID_ARG;
}
esp_err_t ret = cmd_table[cmd_index].command_handler(req, resp, ctx);
if (ret != ESP_OK) {
ESP_LOGE(TAG, "Error executing command handler");
+4
View File
@@ -5,6 +5,8 @@ menu "Protocomm"
default n
help
Enable support of security version 0.
This version provides no encryption or authentication and should
not be used in production. Use only for development and testing.
Disabling this option saves some code size.
Consult the Enabling protocomm security version section of the
Protocomm documentation in ESP-IDF Programming guide for more details.
@@ -14,6 +16,8 @@ menu "Protocomm"
default n
help
Enable support of security version 1.
Security version 2 (SRP6a + AES-GCM) is recommended over this
version for new designs.
Disabling this option saves some code size.
Consult the Enabling protocomm security version section of the
Protocomm documentation in ESP-IDF Programming guide for more details.