aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorPhilipp Maier <pmaier@sysmocom.de>2017-04-20 18:40:37 +0200
committerNeels Hofmeyr <nhofmeyr@sysmocom.de>2017-05-08 15:19:20 +0200
commit316b977d903fab9c35b9969a350ae7b841da1222 (patch)
treeabaa5df8a507095f76e8617a27b7e10ba38813bf
parent618aeed27b9566a5b559396baa02e8f4b6c97c5c (diff)
libmsc: make pitfall in gsm0408_dispatch() more obvious
The function gsm0408_dispatch() accepts a message buffer pointer and accesses the l3h pointer. Even in a properly allocated message buffer, this may lead into a segfault if the user forgets to set the l3h pointer. This commit adds assertions to popup a more expressive error message.
-rw-r--r--openbsc/src/libmsc/gsm_04_08.c8
1 files changed, 6 insertions, 2 deletions
diff --git a/openbsc/src/libmsc/gsm_04_08.c b/openbsc/src/libmsc/gsm_04_08.c
index c731cf924..d204d3ac6 100644
--- a/openbsc/src/libmsc/gsm_04_08.c
+++ b/openbsc/src/libmsc/gsm_04_08.c
@@ -3583,13 +3583,17 @@ void cm_service_request_concludes(struct gsm_subscriber_connection *conn,
/* Main entry point for GSM 04.08/44.008 Layer 3 data (e.g. from the BSC). */
int gsm0408_dispatch(struct gsm_subscriber_connection *conn, struct msgb *msg)
{
- struct gsm48_hdr *gh = msgb_l3(msg);
- uint8_t pdisc = gsm48_hdr_pdisc(gh);
+ struct gsm48_hdr *gh;
+ uint8_t pdisc;
int rc = 0;
+ OSMO_ASSERT(msg->l3h)
OSMO_ASSERT(conn);
OSMO_ASSERT(msg);
+ gh = msgb_l3(msg);
+ pdisc = gsm48_hdr_pdisc(gh);
+
LOGP(DRLL, LOGL_DEBUG, "Dispatching 04.08 message %s (0x%x:0x%x)\n",
gsm48_pdisc_msgtype_name(pdisc, gsm48_hdr_msg_type(gh)),
pdisc, gsm48_hdr_msg_type(gh));