You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
GatherConfigSettings reads max_channels_to_use straight from the user's config with no range validation, and TransferSettingsToDevicesConfig then loops for (int ch = 0; ch < node.configInputs.maxChannelsToUse; ++ch) writing through references into node.config.channel[ch] - a fixed 16-entry array. A larger value writes out of bounds.
LimePlugin_Init checks the status of GatherPortSettings, ConnectInitializeDevices and LoadDevicesConfigurationFile, but discards the one from TransferSettingsToDevicesConfig, which returns InvalidValue when an antenna path name is not found - after it has already written trx.path = 0 and trx.enabled = false through its references. The plugin reports success with a partially applied RF configuration.
port.calibrationStream, created in ConfigureStreaming, is never stopped or reset anywhere. LimePlugin_Destroy then calls DeviceRegistry::freeDevice on devices whose FPGA and LMS7002M objects the still-alive TRXLooper inside that stream holds as raw pointers.
GatherConfigSettingsreadsmax_channels_to_usestraight from the user's config with no range validation, andTransferSettingsToDevicesConfigthen loopsfor (int ch = 0; ch < node.configInputs.maxChannelsToUse; ++ch)writing through references intonode.config.channel[ch]- a fixed 16-entry array. A larger value writes out of bounds.LimePlugin_Initchecks the status ofGatherPortSettings,ConnectInitializeDevicesandLoadDevicesConfigurationFile, but discards the one fromTransferSettingsToDevicesConfig, which returnsInvalidValuewhen an antenna path name is not found - after it has already writtentrx.path = 0andtrx.enabled = falsethrough its references. The plugin reports success with a partially applied RF configuration.port.calibrationStream, created inConfigureStreaming, is never stopped or reset anywhere.LimePlugin_Destroythen callsDeviceRegistry::freeDeviceon devices whoseFPGAandLMS7002Mobjects the still-aliveTRXLooperinside that stream holds as raw pointers.