From bbacf47a10fc3ca65de2c625ab76ef53de774894 Mon Sep 17 00:00:00 2001 From: Pieter Viljoen Date: Mon, 5 Oct 2026 13:44:09 -0700 Subject: [PATCH] Reject a negative `sensor list` start index `sensor list ` passes two NULL pointers to sprintf("%s=%s\n", ...) for any n in [2147483648, 4294967295]. On the C libraries these targets link against, that faults rather than printing "(null)". _atoi() returns uint32_t, and its result goes straight into an int start, so `sensor list 4294967295` gives start == -1. The guard `start >= end` can't catch that: -1 >= end is false for every setting count, end == 0 included. The loop then runs from a negative index, where getSettingName() and getSettingValue() return NULL. The branch sits behind no #if, and the base SensorManager accessors always return NULL, so a plain repeater with no sensors is affected too. The command also works over remote admin. The effect depends on the target: an ESP32-S3 panics (LoadProhibited at address 0) and reboots, while an nRF52840 hangs until someone resets it by hand. Add `start < 0` to the guard, so a wrapped start gets the existing "no custom var" reply. This is the same line as liquidraver/ZephCore#100. Every sensor manager on dev exposes at most one setting, `gps`, so the paging loop's fixed 134-byte bound can't overrun today. That bound is left as it is. Co-Authored-By: Claude Opus 5.5 --- src/helpers/CommonCLI.cpp | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/helpers/CommonCLI.cpp b/src/helpers/CommonCLI.cpp index 04199e24d1..c77d559887 100644 --- a/src/helpers/CommonCLI.cpp +++ b/src/helpers/CommonCLI.cpp @@ -323,7 +323,7 @@ void CommonCLI::handleCommand(uint32_t sender_timestamp, char* command, char* re if (strlen(command) > 11) { start = _atoi(command+12); } - if (start >= end) { + if (start < 0 || start >= end) { // _atoi() is unsigned: a start of 2^31 or more wraps negative strcpy(reply, "no custom var"); } else { sprintf(dp, "%d vars\n", end);