[BlueZ 2/3] unit: Adapt poc_*_oob.c test into a new test
Bastien Nocera <[email protected]>
| Newsgroups | org.kernel.vger.linux-bluetooth |
|---|---|
| Message-ID | <[email protected]> |
Adapt poc_avrcp_oob.c and poc_folder_oob.c into unit tests. Co-authored-by: Elman Shahbazov <[email protected]> --- Makefile.am | 9 +++++ unit/test-avrcp-sec.c | 76 +++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 85 insertions(+) create mode 100644 unit/test-avrcp-sec.c diff --git a/Makefile.am b/Makefile.am index 19c468d3a504..e3baa4155c1f 100644 --- a/Makefile.am +++ b/Makefile.am @@ -660,6 +660,15 @@ unit_test_avrcp_SOURCES = unit/test-avrcp.c \ unit_test_avrcp_LDADD = lib/libbluetooth-internal.la \ src/libshared-glib.la $(GLIB_LIBS) +unit_tests += unit/test-avrcp-sec + +unit_test_avrcp_sec_SOURCES = unit/test-avrcp-sec.c \ + profiles/audio/avrcp-parse.c \ + profiles/audio/avrcp-parse.h \ + src/log.h src/log.c +unit_test_avrcp_sec_LDADD = lib/libbluetooth-internal.la \ + src/libshared-glib.la $(GLIB_LIBS) + unit_tests += unit/test-hfp unit_test_hfp_SOURCES = unit/test-hfp.c diff --git a/unit/test-avrcp-sec.c b/unit/test-avrcp-sec.c new file mode 100644 index 000000000000..a100b2d68e35 --- /dev/null +++ b/unit/test-avrcp-sec.c @@ -0,0 +1,76 @@ +// SPDX-License-Identifier: GPL-2.0-or-later +/* + * + * BlueZ - Bluetooth protocol stack for Linux + * + * Copyright (C) 2026 Red Hat Inc. + * + * + */ + +#ifdef HAVE_CONFIG_H +#include <config.h> +#endif + +#include <glib.h> + +#include "src/shared/util.h" +#include "src/shared/tester.h" +#include "src/log.h" + +#include "profiles/audio/avrcp-parse.h" + +static void avrcp_element_name_oob(gconstpointer data) +{ + char name[255]; + uint16_t namesize; + gboolean ret; + + /* Crafting a malicious payload. + * Actual packet length (len) = 14 bytes */ + uint8_t malicious_packet[14] = {0}; + + /* Specify namesize = 1000 (0x03E8 in Big Endian) at offset 11 */ + malicious_packet[11] = 0x03; + malicious_packet[12] = 0xE8; + + /* Launching the PoC. We transmit a 14-byte packet, but namesize=1000... */ + ret = parse_media_element_name(malicious_packet, sizeof(malicious_packet), + name, &namesize); + if (ret) + tester_test_passed(); + else + tester_test_failed(); +} + +static void avrcp_folder_name_oob(gconstpointer data) +{ + char name[255]; + gboolean ret; + + /* Crafting a malicious payload. + * Actual packet length (len) = 14 bytes */ + uint8_t malicious_packet[14] = {0}; + + /* Specify namesize = 1000 (0x03E8 in Big Endian) at offset 12 */ + malicious_packet[12] = 0x03; + malicious_packet[13] = 0xE8; + + /* Launching the PoC. We transmit a 14-byte packet, but namesize=1000... */ + ret = parse_media_folder_name(malicious_packet, sizeof(malicious_packet), + name); + if (ret) + tester_test_passed(); + else + tester_test_failed(); +} + +int main(int argc, char *argv[]) +{ + tester_init(&argc, &argv); + + tester_add("/avrcp-element-name-oob", NULL, NULL, avrcp_element_name_oob, NULL); + tester_add("/avrcp-folder-name-oob", NULL, NULL, avrcp_folder_name_oob, NULL); + + return tester_run(); +} -- 2.55.0