hanjinpeng
8月24日

当前PR是否有AI参与

[ ] 否

[x] Yes

  1. AI Agent平台: Claude Code
  2. AI模型: Claude Opus 5
  3. Prompt上下文: 基于上游 commit 1d44554a1bb262db63ff4e240152a9deecd99054 生成 backport patch,完成 spec 修改与 changelog 更新

参考:openEuler社区https://www.openeuler.org/zh/community/aigc/

PR功能描述 / 为什么需要这个合入

cbor: overflow

修复 CVE-2026-78161:lib/misc/lecp.c 中 report_raw_cbor() 在回调返回失败时未复位 ctx->cbor_pos,且 lecp_parse() 先写入再检查边界,导致解析恶意 LECP CBOR 数据时发生越界写(CWE-787)。上游修复将 cbor_pos 复位提前到回调之前,并在写入 ctx->cbor[] 之前先做边界检查。

上游来源:https://github.com/warmcat/libwebsockets/commit/1d44554a1bb262db63ff4e240152a9deecd99054

修复类型:安全修复

回合说明:基于 libwebsockets 4.3.3 版本回合上游补丁。ABI:仅修改 lib/misc/lecp.c 内部实现(static 函数 report_raw_cbor 与 lecp_parse 函数体),未修改公开头文件、导出符号或结构体定义,不破坏 ABI。

该PR关联的issue

fixes #24

希望检视人员了解

代码由AI辅助编写,已人工逐行核对逻辑、校验功能正确性,确保与预期一致。

likedislike
Pull Request已成功合入, 合并人@openeuler-ci-bot
(感谢 hanjinpeng 的贡献)
Hhanjinpeng
8月24日 创建了 pull request,commit 1d747128
Hhanjinpeng
8月24日 关联了issue:CVE-2026-78161
openeuler-ci-botopeneuler-ci-bot成员
8月24日 将jingxiaolu,Yekelu,haomintsai,chantsztung设为审查人
openeuler-ci-botopeneuler-ci-bot成员
8月24日 添加了label:sig/iSulad
openeuler-ci-bot
openeuler-ci-bot成员
8月24日 评论:

Welcome To openEuler Community

Hey @protkhn , thanks for your contribution to the community.

Bot Usage Manual

I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands. You can self-configure the PR merge rules for this repository. For more details, please refer to Here.

Contact Guide

If you have any questions, please contact the SIG: iSulad ,
and any of the maintainers: @Yekelu, @chantsztung, @haomintsai, @jingxiaolu ,

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月24日 添加了label:ai-co-authored
openeuler-ci-botopeneuler-ci-bot成员
8月24日 添加了label:openeuler-cla/yes
openeuler-ci-botopeneuler-ci-bot成员
8月24日 添加了label:ai-includes-code
openeuler-ci-bot
openeuler-ci-bot成员
8月24日 评论:

CLA Signature Pass

protkhn, thanks for your pull request. All authors of the commits have signed the CLA. 👍

likedislike
openeuler-ci-bot
openeuler-ci-bot成员
8月24日 评论:

当前仓库存在以下 保护分支 :

Protected Branch Version Release
master 4.3.3 6
openEuler-26.09-DevStation 4.3.3 6
openEuler-26.09 4.3.3 6
openEuler-24.03-LTS-SP4 4.3.3 5
openEuler-22.03-LTS-SP4 4.3.0 8
openEuler-24.03-LTS-SP3 4.3.3 5
openEuler-24.03-LTS-SP1 4.3.3 5
openEuler-24.03-LTS-Next 4.3.3 5
openEuler-20.03-LTS-SP4 4.3.0 8
sync-pr68--to-openEuler-24.03-LTS-SP1 4.3.3 3
sync-pr68--to-openEuler-24.03-LTS 4.3.3 3
openEuler1.0-base 2.4.2 3
openEuler1.0 2.4.2 2

评论 /sync <branch1> <branch2> ... 可将当前 PR 修改同步到其它分支(创建同步 PR):
a) 如果当前 PR 是 Open 状态,同步操作将延迟到 PR 被合并时执行
b) 如果当前 PR 已经 Merged,将立即执行同步操作

注意:

  1. /sync 命令可以指定同步到多个分支,仅最后一个 /sync 命令生效
  2. 如果创建的同步 PR 不正确,可通过向同步 PR 的源分支提交轻量级 PR 完善,或使用 /close 命令关闭
likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月24日 添加了label:ai-compliance-successful
openeuler-ci-bot
openeuler-ci-bot成员
8月24日 评论:

门禁正在运行, 您可以通过以下链接查看实时门禁检查结果.
若您对门禁结果含义不清晰或者遇到问题不知如何解决,可参考门禁指导手册
门禁入口及编码规范检查: multiarch/src-openeuler/trigger/libwebsockets/24/console

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月24日 添加了label:ci_processing
openeuler-ci-bot
openeuler-ci-bot成员
8月24日 评论:

x86_64架构构建及构建后检查:multiarch/src-openeuler/x86-64/libwebsockets/24/console

likedislike
openeuler-ci-bot
openeuler-ci-bot成员
8月24日 评论:

aarch64架构构建及构建后检查:multiarch/src-openeuler/aarch64/libwebsockets/24/console

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月24日 删除了label:ci_processing
openeuler-ci-bot
openeuler-ci-bot成员
8月24日 评论:
Check Name Build Result 详情 Build Details
check_binary_file ✅SUCCESS #24
check_lfsconfig :ballot_box_with_check:EXCLUDE
check_package_yaml_file ✅SUCCESS
check_repo_in_maintain ✅SUCCESS
check_consistency ✅SUCCESS
check_spec_file ✅SUCCESS
x86_64 check_build ✅SUCCESS #24
check_install ✅SUCCESS
check_license ✅SUCCESS
aarch64 check_build ✅SUCCESS #24
check_install ✅SUCCESS
check_license ✅SUCCESS
likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月24日 添加了label:ci_successful
openeuler-ci-bot
openeuler-ci-bot成员
8月24日 评论:

如下为接口变更检查结果,目标分支为openEuler-24.03-LTS-Next,请PR提交者check差异信息

Arch Name Check Items Rpm Name Check Result Build Details
compare_package(x86_64) add_rpms ✅SUCCESS #24
delete_rpms ✅SUCCESS
rpm_abi ✅SUCCESS
rpm_cmd ✅SUCCESS
rpm_files ✅SUCCESS
rpm_header ✅SUCCESS
rpm_lib ✅SUCCESS
rpm_provides ✅SUCCESS
rpm_requires ✅SUCCESS
rpm_symbol ✅SUCCESS
compare_package(aarch64) add_rpms ✅SUCCESS #24
delete_rpms ✅SUCCESS
rpm_abi ✅SUCCESS
rpm_cmd ✅SUCCESS
rpm_files ✅SUCCESS
rpm_header ✅SUCCESS
rpm_lib ✅SUCCESS
rpm_provides ✅SUCCESS
rpm_requires ✅SUCCESS
rpm_symbol ✅SUCCESS
likedislike
openeuler-ci-bot
openeuler-ci-bot成员
8月24日 评论:
likedislike
zhengxiaoxiao
8月27日 评论:

/lgtm

likedislike
openeuler-ci-bot
openeuler-ci-bot成员
8月27日 评论:

Label Command Feedback

  • Thanks for your review, your opinion is very important to us. The maintainers will consider your advice carefully.
  • The label(s) lgtm permission is outside.
likedislike
zhengxiaoxiao
8月27日 评论:

/sync openEuler-24.03-LTS-SP4 openEuler-24.03-LTS-SP3 openEuler-24.03-LTS-SP1

likedislike
openeuler-ci-bot
openeuler-ci-bot成员
8月27日 评论:

In response to this:

/sync openEuler-24.03-LTS-SP4 openEuler-24.03-LTS-SP3 openEuler-24.03-LTS-SP1

@zhengxiaoxiaoGitee
一旦当前 PR 被合入,以下同步操作将会执行:

Branch Status
openEuler-24.03-LTS-SP4 当前 PR 合并后,将创建同步 PR
openEuler-24.03-LTS-SP3 当前 PR 合并后,将创建同步 PR
openEuler-24.03-LTS-SP1 当前 PR 合并后,将创建同步 PR
likedislike
Yekelu
Yekelu成员
8月28日 评论:

当前补丁在调用 LECPCB_LITERAL_CBOR 回调前将 ctx->cbor_pos 清零,但该字段正是现有 raw-CBOR 回调接口及 lib/cose/cose_validate.c 用来表示 ctx->cbor[] 有效长度的字段。因此回调只能看到长度 0,COSE protected header 的原始 CBOR 不会被复制,可能导致签名/MAC 校验及互操作性回归。
上游已在后续提交 https://github.com/warmcat/libwebsockets/commit/edf432f54fef8d1b9463483c421a7b2d7b56365d修正该问题:增加 cbor_len,在清零 cbor_pos 前保存长度,并将 COSE 消费方改为读取 cbor_len。
请不要单独合入当前 1d44554 回移。建议补回 0a5b4b8 中与以下文件有关的最小修改:
include/libwebsockets/lws-lecp.h
lib/misc/lecp.c
lib/cose/cose_validate.c
同时请更新 raw-CBOR API 文档,并增加 LWS_WITH_CBOR=ON 下的回归测试,至少覆盖缓冲区填满、回调拒绝、继续解析不越界,以及正常回调能获得准确长度和字节内容。由于 struct lecp_ctx 是公开结构,新增字段后也请修正 PR 中“不修改公开头文件/结构体”的 ABI 说明并重新评估。

likedislike
Yekelu
Yekelu成员
14 天前 评论:

/lgtm
/approve

likedislike
openeuler-ci-botopeneuler-ci-bot成员
14 天前 添加了label:approvedlgtm
openeuler-ci-bot
openeuler-ci-bot成员
14 天前 评论:

Review Code Feedback

  • The label lgtm, approved was added to this pull request. It means that Yekelu reviewed the code changes. 👋
Tips
  • If this pull request is not merged while all conditions are met, comment /check-pr to try again. 😄
likedislike
openeuler-ci-botopeneuler-ci-bot成员
14 天前 合入了pull request,合并节点 SHA:3a763759f8ade17c2f27673340b961d865093929
openeuler-ci-bot
openeuler-ci-bot成员
14 天前 评论:

In response to this:

/sync openEuler-24.03-LTS-SP4 openEuler-24.03-LTS-SP3 openEuler-24.03-LTS-SP1

@zhengxiaoxiaoGitee

同步操作执行结果:

Branch Status Pull Request
openEuler-24.03-LTS-SP4 创建同步 PR https://gitcode.com/src-openeuler/libwebsockets/merge_requests/107
openEuler-24.03-LTS-SP3 创建同步 PR https://gitcode.com/src-openeuler/libwebsockets/merge_requests/108
openEuler-24.03-LTS-SP1 创建同步 PR https://gitcode.com/src-openeuler/libwebsockets/merge_requests/109
likedislike