mirror of
https://github.com/logicog/RTLPlayground.git
synced 2026-08-30 14:52:51 +08:00
The handler took one raw character of the request line and passed it to send_counters(), which uses it to index machine.phys_to_log_port. That array has nine entries and the character is whatever the client sent, so the read ran up to 246 entries past the end and the result went on to STAT_GET as a port number. is_word() accepts any request whose name is followed by a question mark, so nothing constrained the byte to a digit. Bounding it where it is read keeps the check beside the assumption it protects and needs nothing from the machine description. sdcc leaves plain char unsigned and the subtraction wraps in eight bits, so a byte below '0' comes out above 200 and one upper test covers both ends: exactly '0' to '8' now reach send_counters. The compiled test is add a,#0xf7 followed by jnc, which I read back out of the assembly rather than assuming. Out of range answers 400 by the path the other malformed requests already take, rather than an empty array. An empty array would have been worse than useless here, since the statistics page calls BigInt on the first element before it looks at the length. The page asks only for index zero to the port count minus one, so nothing that answered before stops answering, and a non-200 reply makes its handler do nothing at all. 11 bytes of BANK1, nothing in the common segment, BANK2, xdata or internal RAM. Built for SWTGW218AS and KP_9000_6XHML_X2 on sdcc 4.5.0.