Pull Request已成功合入, 合并人@openeuler-ci-bot
(感谢 hanjinpeng 的贡献)Welcome To openEuler Community
Hey @protkhn , thanks for your contribution to the community.
Bot Usage Manual
I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands. You can self-configure the PR merge rules for this repository. For more details, please refer to Here.
Contact Guide
If you have any questions, please contact the SIG: iSulad ,
and any of the maintainers: @Yekelu, @chantsztung, @haomintsai, @jingxiaolu ,


当前仓库存在以下 保护分支 :
| Protected Branch | Version | Release |
|---|---|---|
| master | 4.3.3 | 6 |
| openEuler-26.09-DevStation | 4.3.3 | 6 |
| openEuler-26.09 | 4.3.3 | 6 |
| openEuler-24.03-LTS-SP4 | 4.3.3 | 5 |
| openEuler-22.03-LTS-SP4 | 4.3.0 | 8 |
| openEuler-24.03-LTS-SP3 | 4.3.3 | 5 |
| openEuler-24.03-LTS-SP1 | 4.3.3 | 5 |
| openEuler-24.03-LTS-Next | 4.3.3 | 5 |
| openEuler-20.03-LTS-SP4 | 4.3.0 | 8 |
| sync-pr68--to-openEuler-24.03-LTS-SP1 | 4.3.3 | 3 |
| sync-pr68--to-openEuler-24.03-LTS | 4.3.3 | 3 |
| openEuler1.0-base | 2.4.2 | 3 |
| openEuler1.0 | 2.4.2 | 2 |
评论 /sync <branch1> <branch2> ... 可将当前 PR 修改同步到其它分支(创建同步 PR):
a) 如果当前 PR 是 Open 状态,同步操作将延迟到 PR 被合并时执行
b) 如果当前 PR 已经 Merged,将立即执行同步操作
注意:
- /sync 命令可以指定同步到多个分支,仅最后一个 /sync 命令生效
- 如果创建的同步 PR 不正确,可通过向同步 PR 的源分支提交轻量级 PR 完善,或使用 /close 命令关闭


门禁正在运行, 您可以通过以下链接查看实时门禁检查结果.
若您对门禁结果含义不清晰或者遇到问题不知如何解决,可参考门禁指导手册
门禁入口及编码规范检查: multiarch/src-openeuler/trigger/libwebsockets/24/console


x86_64架构构建及构建后检查:multiarch/src-openeuler/x86-64/libwebsockets/24/console


aarch64架构构建及构建后检查:multiarch/src-openeuler/aarch64/libwebsockets/24/console


| Check Name | Build Result | 详情 | Build Details | |
|---|---|---|---|---|
| check_binary_file | ✅SUCCESS | #24 | ||
| check_lfsconfig | :ballot_box_with_check:EXCLUDE | |||
| check_package_yaml_file | ✅SUCCESS | |||
| check_repo_in_maintain | ✅SUCCESS | |||
| check_consistency | ✅SUCCESS | |||
| check_spec_file | ✅SUCCESS | |||
| x86_64 | check_build | ✅SUCCESS | #24 | |
| check_install | ✅SUCCESS | |||
| check_license | ✅SUCCESS | |||
| aarch64 | check_build | ✅SUCCESS | #24 | |
| check_install | ✅SUCCESS | |||
| check_license | ✅SUCCESS | |||


如下为接口变更检查结果,目标分支为openEuler-24.03-LTS-Next,请PR提交者check差异信息
| Arch Name | Check Items | Rpm Name | Check Result | Build Details |
|---|---|---|---|---|
| compare_package(x86_64) | add_rpms | ✅SUCCESS | #24 | |
| delete_rpms | ✅SUCCESS | |||
| rpm_abi | ✅SUCCESS | |||
| rpm_cmd | ✅SUCCESS | |||
| rpm_files | ✅SUCCESS | |||
| rpm_header | ✅SUCCESS | |||
| rpm_lib | ✅SUCCESS | |||
| rpm_provides | ✅SUCCESS | |||
| rpm_requires | ✅SUCCESS | |||
| rpm_symbol | ✅SUCCESS | |||
| compare_package(aarch64) | add_rpms | ✅SUCCESS | #24 | |
| delete_rpms | ✅SUCCESS | |||
| rpm_abi | ✅SUCCESS | |||
| rpm_cmd | ✅SUCCESS | |||
| rpm_files | ✅SUCCESS | |||
| rpm_header | ✅SUCCESS | |||
| rpm_lib | ✅SUCCESS | |||
| rpm_provides | ✅SUCCESS | |||
| rpm_requires | ✅SUCCESS | |||
| rpm_symbol | ✅SUCCESS |


/lgtm


/sync openEuler-24.03-LTS-SP4 openEuler-24.03-LTS-SP3 openEuler-24.03-LTS-SP1


In response to this:
/sync openEuler-24.03-LTS-SP4 openEuler-24.03-LTS-SP3 openEuler-24.03-LTS-SP1
@zhengxiaoxiaoGitee
一旦当前 PR 被合入,以下同步操作将会执行:
| Branch | Status |
|---|---|
| openEuler-24.03-LTS-SP4 | 当前 PR 合并后,将创建同步 PR |
| openEuler-24.03-LTS-SP3 | 当前 PR 合并后,将创建同步 PR |
| openEuler-24.03-LTS-SP1 | 当前 PR 合并后,将创建同步 PR |


当前补丁在调用 LECPCB_LITERAL_CBOR 回调前将 ctx->cbor_pos 清零,但该字段正是现有 raw-CBOR 回调接口及 lib/cose/cose_validate.c 用来表示 ctx->cbor[] 有效长度的字段。因此回调只能看到长度 0,COSE protected header 的原始 CBOR 不会被复制,可能导致签名/MAC 校验及互操作性回归。
上游已在后续提交 https://github.com/warmcat/libwebsockets/commit/edf432f54fef8d1b9463483c421a7b2d7b56365d修正该问题:增加 cbor_len,在清零 cbor_pos 前保存长度,并将 COSE 消费方改为读取 cbor_len。
请不要单独合入当前 1d44554 回移。建议补回 0a5b4b8 中与以下文件有关的最小修改:
include/libwebsockets/lws-lecp.h
lib/misc/lecp.c
lib/cose/cose_validate.c
同时请更新 raw-CBOR API 文档,并增加 LWS_WITH_CBOR=ON 下的回归测试,至少覆盖缓冲区填满、回调拒绝、继续解析不越界,以及正常回调能获得准确长度和字节内容。由于 struct lecp_ctx 是公开结构,新增字段后也请修正 PR 中“不修改公开头文件/结构体”的 ABI 说明并重新评估。


/lgtm
/approve


In response to this:
/sync openEuler-24.03-LTS-SP4 openEuler-24.03-LTS-SP3 openEuler-24.03-LTS-SP1
同步操作执行结果:
| Branch | Status | Pull Request |
|---|---|---|
| openEuler-24.03-LTS-SP4 | 创建同步 PR | https://gitcode.com/src-openeuler/libwebsockets/merge_requests/107 |
| openEuler-24.03-LTS-SP3 | 创建同步 PR | https://gitcode.com/src-openeuler/libwebsockets/merge_requests/108 |
| openEuler-24.03-LTS-SP1 | 创建同步 PR | https://gitcode.com/src-openeuler/libwebsockets/merge_requests/109 |


当前PR是否有AI参与
[ ] 否
[x] Yes
参考:openEuler社区
https://www.openeuler.org/zh/community/aigc/PR功能描述 / 为什么需要这个合入
cbor: overflow
修复 CVE-2026-78161:
lib/misc/lecp.c中report_raw_cbor()在回调返回失败时未复位ctx->cbor_pos,且lecp_parse()先写入再检查边界,导致解析恶意 LECP CBOR 数据时发生越界写(CWE-787)。上游修复将cbor_pos复位提前到回调之前,并在写入ctx->cbor[]之前先做边界检查。上游来源:https://github.com/warmcat/libwebsockets/commit/1d44554a1bb262db63ff4e240152a9deecd99054
修复类型:安全修复
回合说明:基于 libwebsockets 4.3.3 版本回合上游补丁。ABI:仅修改 lib/misc/lecp.c 内部实现(static 函数 report_raw_cbor 与 lecp_parse 函数体),未修改公开头文件、导出符号或结构体定义,不破坏 ABI。
该PR关联的issue
fixes #24
希望检视人员了解
代码由AI辅助编写,已人工逐行核对逻辑、校验功能正确性,确保与预期一致。