Files
soma0212 6352192839 [netdata] check sub-TLV bounds in GetCommissioningDataset() walk (#13560)
The walk over the Commissioning Data sub-TLVs in
`Leader::GetCommissioningDataset()`, which determines `mHasExtraTlv`,
has no bounds guard, so a truncated sub-TLV makes `GetNext()` read the
length byte(s) past the end of the value. The content is untrusted:
`NetworkData::ValidateTlvs()` skips the Commissioning Data value, and
the value is stored verbatim from an MLE Data Response and from
`MGMT_COMMISSIONER_SET`.

This commit adds the header, extended-header, and `GetNext() <= end`
checks that `Tlv::FindTlv()` already uses:

- A sub-TLV that runs past the end of the value is malformed content,
  so it ends the walk and is not reported as an extra TLV.
- An extended-format sub-TLV is skipped over by `GetNext()` and the
  walk continues, which keeps the iteration compatible with both TLV
  formats, same as the sub-TLV readers.

Adds `TestNetworkDataCommissioningData()` covering an extended sub-TLV
followed by a known and by an unknown base sub-TLV, plus truncated
header, truncated extended header, truncated value, and truncated
extended value cases, each with a known and an unknown sub-TLV type.
`TestLeader` is moved to namespace scope and shared across the tests
in this file.
2026-10-01 10:51:20 -07:00
..

OpenThread Unit Tests

This page describes how to build and run OpenThread unit tests. It will be helpful for developers to debug failed unit test cases if they got one in CI or to add some new test cases.

Build Simulation

The unit tests cannot be built solely without building the whole project. So first build OpenThread on the simulation platform, which will also build all unit tests:

# Go to the root directory of OpenThread
$ script/cmake-build simulation

List all tests

To see what tests are available in OpenThread:

# Make sure you are at the simulation build directory (build/simulation)
$ ctest -N

Run the Unit Tests

To run all the unit tests:

# Make sure you are at the simulation build directory (build/simulation)
$ ctest

To run a specific unit test, for example, ot-test-spinel:

# Make sure you are at the simulation build directory (build/simulation)
$ ctest -R ot-test-spinel

Update a Test Case

If you are developing a unit test case and have made some changes in the test source file, you will need rebuild the test before running it:

# Make sure you are at the simulation build directory (build/simulation)
$ ninja <test_name>

This will only build the test and take a short time.

If any changes or fixes were made to the OpenThread code, then you'll need to rebuild the entire project:

# Make sure you are at the simulation build directory (build/simulation)
$ ninja

This will build the updated OpenThread code as well as the test cases.