Repository navigation
fix(ap-mode): validate cidr prefix range in bring up interface - #6086
Closed
vaibhavsrv wants to merge 1 commit into
Closed
vaibhavsrv wants to merge 1 commit into
vaibhavsrv wants to merge 1 commit into
Conversation
Collaborator
|
Thanks for this contribution. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why this matters
In
ods/scripts/ap-mode.sh,bring_up_interface()resolved the network prefix from$ODS_AP_PREFIX(or derived it from$ODS_AP_NETMASK) and directly executedip addr add "${ODS_AP_GATEWAY_IP}/${prefix}" dev "${ODS_AP_INTERFACE}"without bounds checking the prefix value. If an operator set an invalid or out-of-range CIDR prefix (such as0,33,99, negative values, or non-numeric tokens), the script brought the interface up, flushed IP addresses, and then aborted with an unhandled iproute2 command failure, leaving the wireless interface in a detached, unconfigured state.This change introduces strict range validation (
[[ "$prefix" =~ ^[0-9]+$ ]] && (( prefix >= 1 && prefix <= 32 ))) before performing interface configuration. Invalid prefix values fail early with a descriptive error message. Existing netmask conversion, gateway IP defaults, and captive portal iptables rules remain untouched.Validation
bring_up_interfacewith an invalidODS_AP_PREFIX=99or non-numeric value progressed toip addr addwithout prefix validation.ods/tests/test_ap_mode_prefix_validation.pyasserts that invalid CIDR prefixes (0,33,99,-1,"abc") are rejected immediately with exit code 1 and error messaging, while standard valid subnets pass validation.test_ap_mode_prefix_validation.pypasses cleanly (exit code 0). Wired into Linux CI workflow under AP network identity preflight.Overlap check
_netmask_to_prefix.patch-hermes-config.py.Risk / AI disclosure
AI-assisted investigation, implementation, and test regressions. This strengthens CIDR prefix validation during AP interface bring-up. Independent human review and platform/runtime qualification remain gates. No running configuration, deployment or upstream merge changed.
Follow-up integration evidence
Composed with #6076, #6077, #6078, #6079, #6080, #6081, #6082, #6083, #6084, and #6085 at HEAD without conflicts. Production and test diffs passed together; AP mode and network identity checks remain intact.
Backlog composition was local-only (production/test diffs, excluding workflow/Makefile wiring); it is not an upstream merge or independent human approval. Declared live-review gates remain open.