|
FastLED 3.10.6
|
Range-checked conversion of an untrusted integer to a TCP/UDP port.
JSON-RPC and config surfaces hand port numbers around as a wide signed integer, but the socket APIs take a u16. Narrowing with a bare static_cast<u16> silently wraps: 70000 becomes 4464, so a request that should have been rejected instead targets a completely different endpoint and the failure surfaces much later as a confusing connection error (FastLED#3956).
A low-side-only guard (port > 0 ? static_cast<u16>(port) : 0) does not help — it rejects 65536 only by the accident of it truncating to zero, while 65537 still slips through as port 1.
Definition in file port.h.
Include dependency graph for port.h:Go to the source code of this file.
Namespaces | |
| namespace | fl |
| Base definition for an LED controller. | |
| namespace | fl::net |
Functions | |
| fl::optional< u16 > | fl::net::tryParsePort (i64 value) |
| Convert an untrusted integer to a port number. | |
Variables | |
| constexpr i64 | fl::net::kMaxPort = 65535 |
| Highest port representable in the 16-bit wire field. | |
| constexpr i64 | fl::net::kMinPort = 1 |
| Lowest port a caller may request. | |