Skip to content

Add CBMC memory-safety proofs for MQTTPropAdd UTF-8 property APIs - #385

Merged
AniruddhaKanhere merged 5 commits into
FreeRTOS:mainfrom
AniruddhaKanhere:add-mqttpropadd-utf8-proofs
Aug 18, 2026
Merged

AniruddhaKanhere merged 5 commits into
FreeRTOS:mainfrom
AniruddhaKanhere:add-mqttpropadd-utf8-proofs

Conversation

@AniruddhaKanhere

Copy link
Copy Markdown
Member

Description

Adds CBMC memory-safety proofs for the remaining public MQTTPropAdd_* APIs that serialize a UTF-8 string property through the file-local addPropUtf8 helper:

  • MQTTPropAdd_AuthData
  • MQTTPropAdd_AuthMethod
  • MQTTPropAdd_ContentType
  • MQTTPropAdd_CorrelationData
  • MQTTPropAdd_ResponseTopic

Each proof confirms the bounds check in addPropUtf8 reserves space for the full on-wire encoding (1 byte property ID + 2 byte UTF-8 length prefix + the string itself) and never writes past the end of the property builder buffer. This complements the existing MQTTPropAdd_ReasonString proof, bringing per-API proof coverage to the full set of UTF-8 property builders.

Each harness allocates a property builder backed by a buffer of exactly bufferLength bytes with a nondeterministic currentIndex, bounds the string length, and lets the string pointer be possibly NULL so the parameter-validation branches are also exercised. MQTTPropAdd_ResponseTopic additionally uses memchr to reject wildcard characters, so its proof links the existing stubs/memchr.c.

Test Steps

Ran each proof locally with CBMC 6.9.0; all report VERIFICATION SUCCESSFUL. Confirmed the proofs are non-trivial by temporarily reintroducing the off-by-one in the addPropUtf8 bounds check, which makes the proofs report an out-of-bounds write in addPropUtf8.

Checklist:

  • I have tested my changes. No regression in existing tests.
  • I have added proofs to cover the code paths in this Pull Request.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

Adds a CBMC proof harness for MQTTPropAdd_AuthData, a public entry point into
the file-local addPropUtf8 helper. The proof confirms the buffer bounds check
reserves space for the full encoding (1 byte property ID + 2 byte UTF-8 length
prefix + the string) and never writes past the property builder buffer.
Adds a CBMC proof harness for MQTTPropAdd_AuthMethod, a public entry point into
the file-local addPropUtf8 helper. The proof confirms the buffer bounds check
reserves space for the full encoding (1 byte property ID + 2 byte UTF-8 length
prefix + the string) and never writes past the property builder buffer.
Adds a CBMC proof harness for MQTTPropAdd_ContentType, a public entry point into
the file-local addPropUtf8 helper. The proof confirms the buffer bounds check
reserves space for the full encoding (1 byte property ID + 2 byte UTF-8 length
prefix + the string) and never writes past the property builder buffer.
Adds a CBMC proof harness for MQTTPropAdd_CorrelationData, a public entry point into
the file-local addPropUtf8 helper. The proof confirms the buffer bounds check
reserves space for the full encoding (1 byte property ID + 2 byte UTF-8 length
prefix + the string) and never writes past the property builder buffer.
Adds a CBMC proof harness for MQTTPropAdd_ResponseTopic, a public entry point into
the file-local addPropUtf8 helper. The proof confirms the buffer bounds check
reserves space for the full encoding (1 byte property ID + 2 byte UTF-8 length
prefix + the string) and never writes past the property builder buffer.
@AniruddhaKanhere
AniruddhaKanhere force-pushed the add-mqttpropadd-utf8-proofs branch from 02c2beb to 1c70295 Compare August 17, 2026 21:39
@AniruddhaKanhere
AniruddhaKanhere enabled auto-merge (squash) August 17, 2026 21:45
@AniruddhaKanhere
AniruddhaKanhere merged commit b7741e3 into FreeRTOS:main Aug 18, 2026
20 of 22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants