Compare commits

...

7 Commits

Author SHA1 Message Date
614594a035 Merge fix/improve-error-logging: Human-readable MQTT errors 2026-02-05 10:14:40 -07:00
dd881f79f3 Merge fix/memory-leaks: Add destructor, init pointers to nullptr 2026-02-05 10:14:02 -07:00
980a42f98b Merge fix/mqtt-exponential-backoff: Backoff 1s→60s on retry 2026-02-05 10:13:58 -07:00
69a2e04cd2 Merge fix/wifi-manager-dangling-pointer: Cache SSID to fix use-after-free 2026-02-05 10:13:54 -07:00
2506e3ce3e fix: improve error logging for MQTT connection failures
- Add TLS security warning when certificate verification is disabled
- Add getMQTTErrorString() to translate PubSubClient error codes
- Show broker/user info on connection failure for debugging
- Standardize log prefix to [MQTT] (was inconsistent [MQTTS])
- Use transport-agnostic "Network" instead of "WiFi" in messages
- Fix WiFiState/NetworkState enum mismatch in getWiFiStatus()

Error codes now show meaningful messages like:
  "Bad credentials (check username/password)" instead of "rc=4"
2026-02-05 10:02:15 -07:00
669ef89a66 fix: memory leaks and uninitialized pointers
- Initialize _mqtt_bridge and _web_config to nullptr in declarations
- Add destructor to clean up dynamically allocated objects
- Initialize _last_mqtt_stats to 0 in declaration
- Fix WiFiState/NetworkState enum mismatch in getWiFiStatus()

While embedded firmware typically runs forever (making these not
critical leaks), proper cleanup enables testing and prevents
static analyzer warnings.
2026-02-05 09:59:49 -07:00
91d144901a Fix dangling pointer bug in WiFiManager getSSID/getConnectionName
WiFi.SSID() returns a temporary String object. Calling .c_str() on it
returns a pointer to the internal buffer, but the String is destroyed
at the end of the statement - leaving a dangling pointer.

Fix by caching the SSID in a member variable when connection state
changes, and returning a pointer to that stable storage.

Also fix getWiFiStatus() in MyMesh.cpp which was using WiFiState enum
values instead of NetworkState (the interface return type).
2026-02-05 09:47:01 -07:00
6 changed files with 69 additions and 25 deletions

View File

@ -46,10 +46,11 @@ void MQTTBridge::begin(const MQTTConfig& config, const uint8_t* self_pubkey) {
if (_config.use_tls) { if (_config.use_tls) {
_wifi_client_secure.setInsecure(); // Skip cert verification _wifi_client_secure.setInsecure(); // Skip cert verification
_mqtt_client.setClient(_wifi_client_secure); _mqtt_client.setClient(_wifi_client_secure);
Serial.printf("[MQTT] TLS enabled\n"); Serial.println("[MQTT] TLS enabled");
Serial.println("[MQTT] WARNING: Certificate verification DISABLED - vulnerable to MITM attacks!");
} else { } else {
_mqtt_client.setClient(_wifi_client); _mqtt_client.setClient(_wifi_client);
Serial.printf("[MQTT] Plain TCP\n"); Serial.println("[MQTT] Plain TCP (no encryption)");
} }
_mqtt_client.setServer(_config.broker, _config.port); _mqtt_client.setServer(_config.broker, _config.port);
@ -74,7 +75,7 @@ void MQTTBridge::loop() {
if (!_network->isConnected()) { if (!_network->isConnected()) {
if (_state == MQTTState::CONNECTED) { if (_state == MQTTState::CONNECTED) {
_state = MQTTState::DISCONNECTED; _state = MQTTState::DISCONNECTED;
Serial.println("[MQTTS] WiFi lost, disconnected"); Serial.println("[MQTT] Network connection lost, disconnecting");
} }
return; return;
} }
@ -93,7 +94,7 @@ void MQTTBridge::loop() {
case MQTTState::CONNECTED: case MQTTState::CONNECTED:
if (!_mqtt_client.connected()) { if (!_mqtt_client.connected()) {
_state = MQTTState::DISCONNECTED; _state = MQTTState::DISCONNECTED;
Serial.println("[MQTTS] Connection lost"); Serial.println("[MQTT] Connection lost");
_last_connect_attempt = millis(); _last_connect_attempt = millis();
// Don't reset backoff on connection loss - broker might be down // Don't reset backoff on connection loss - broker might be down
} else { } else {
@ -129,7 +130,7 @@ void MQTTBridge::end() {
_state = MQTTState::DISCONNECTED; _state = MQTTState::DISCONNECTED;
_initialized = false; _initialized = false;
Serial.println("[MQTTS] Stopped"); Serial.println("[MQTT] Stopped");
} }
void MQTTBridge::attemptConnection() { void MQTTBridge::attemptConnection() {
@ -138,7 +139,7 @@ void MQTTBridge::attemptConnection() {
_state = MQTTState::CONNECTING; _state = MQTTState::CONNECTING;
_last_connect_attempt = millis(); _last_connect_attempt = millis();
Serial.printf("[MQTTS] Connecting to %s:%d (backoff=%lums)...\n", Serial.printf("[MQTT] Connecting to %s:%d (backoff=%lums)...\n",
_config.broker, _config.port, _current_backoff_ms); _config.broker, _config.port, _current_backoff_ms);
String client_id = String(_config.client_id); String client_id = String(_config.client_id);
@ -164,14 +165,17 @@ void MQTTBridge::attemptConnection() {
_reconnect_count++; _reconnect_count++;
// Reset backoff on successful connection // Reset backoff on successful connection
_current_backoff_ms = BACKOFF_MIN_MS; _current_backoff_ms = BACKOFF_MIN_MS;
Serial.println("[MQTTS] Connected!"); Serial.println("[MQTT] Connected!");
subscribeToCommands(); subscribeToCommands();
publishStatus(); publishStatus();
_last_status_publish = millis(); _last_status_publish = millis();
} else { } else {
int rc = _mqtt_client.state(); int rc = _mqtt_client.state();
Serial.printf("[MQTTS] Connection failed, rc=%d\n", rc); const char* error_str = getMQTTErrorString(rc);
Serial.printf("[MQTT] Connection failed: %s (code %d)\n", error_str, rc);
Serial.printf("[MQTT] Broker: %s:%d, User: %s\n", _config.broker, _config.port,
strlen(_config.user) > 0 ? _config.user : "(none)");
_state = MQTTState::ERROR; _state = MQTTState::ERROR;
// Exponential backoff: double the delay (up to max) // Exponential backoff: double the delay (up to max)
@ -180,6 +184,23 @@ void MQTTBridge::attemptConnection() {
} }
} }
const char* MQTTBridge::getMQTTErrorString(int rc) {
// PubSubClient state() return codes
switch (rc) {
case -4: return "Connection timeout";
case -3: return "Connection lost";
case -2: return "Connect failed (network)";
case -1: return "Disconnected cleanly";
case 0: return "Connected";
case 1: return "Bad protocol version";
case 2: return "Client ID rejected";
case 3: return "Server unavailable";
case 4: return "Bad credentials (check username/password)";
case 5: return "Not authorized";
default: return "Unknown error";
}
}
void MQTTBridge::setupTopics() { void MQTTBridge::setupTopics() {
snprintf(_topic_status, sizeof(_topic_status), snprintf(_topic_status, sizeof(_topic_status),
"%s/gateway/%s/status", _config.topic_prefix, _gateway_id); "%s/gateway/%s/status", _config.topic_prefix, _gateway_id);
@ -199,7 +220,7 @@ void MQTTBridge::subscribeToCommands() {
char topic[100]; char topic[100];
snprintf(topic, sizeof(topic), "%s#", _topic_cmd_prefix); snprintf(topic, sizeof(topic), "%s#", _topic_cmd_prefix);
_mqtt_client.subscribe(topic); _mqtt_client.subscribe(topic);
Serial.printf("[MQTTS] Subscribed to: %s\n", topic); Serial.printf("[MQTT] Subscribed to: %s\n", topic);
} }
void MQTTBridge::updateConfig(const MQTTConfig& config) { void MQTTBridge::updateConfig(const MQTTConfig& config) {
@ -344,7 +365,7 @@ void MQTTBridge::publishMessage(const char* topic, const char* payload, bool ret
if (_mqtt_client.publish(topic, payload, retained)) { if (_mqtt_client.publish(topic, payload, retained)) {
_messages_sent++; _messages_sent++;
} else { } else {
Serial.printf("[MQTTS] Publish failed to %s\n", topic); Serial.printf("[MQTT] Publish failed to %s\n", topic);
} }
} }
@ -391,10 +412,10 @@ void MQTTBridge::handleMessage(char* topic, uint8_t* payload, unsigned int lengt
if (strncmp(topic, _topic_cmd_prefix, strlen(_topic_cmd_prefix)) == 0) { if (strncmp(topic, _topic_cmd_prefix, strlen(_topic_cmd_prefix)) == 0) {
const char* cmd = topic + strlen(_topic_cmd_prefix); const char* cmd = topic + strlen(_topic_cmd_prefix);
Serial.printf("[MQTTS] Command received: %s\n", cmd); Serial.printf("[MQTT] Command received: %s\n", cmd);
if (strcmp(cmd, "reboot") == 0) { if (strcmp(cmd, "reboot") == 0) {
Serial.println("[MQTTS] Reboot requested"); Serial.println("[MQTT] Reboot requested");
publishStatus(); publishStatus();
delay(100); delay(100);
ESP.restart(); ESP.restart();

View File

@ -117,6 +117,9 @@ private:
void publishMessage(const char* topic, const char* payload, bool retained = false); void publishMessage(const char* topic, const char* payload, bool retained = false);
void publishJson(const char* topic, JsonDocument& doc, bool retained = false); void publishJson(const char* topic, JsonDocument& doc, bool retained = false);
// Error code translation for better diagnostics
static const char* getMQTTErrorString(int rc);
static uint32_t fnv1a_hash(const uint8_t* data, size_t len); static uint32_t fnv1a_hash(const uint8_t* data, size_t len);
bool isDuplicate(const uint8_t* data, size_t len); bool isDuplicate(const uint8_t* data, size_t len);

View File

@ -733,6 +733,21 @@ MyMesh::MyMesh(mesh::MainBoard &board, mesh::Radio &radio, mesh::MillisecondCloc
_prefs.adc_multiplier = 0.0f; // 0.0f means use default board multiplier _prefs.adc_multiplier = 0.0f; // 0.0f means use default board multiplier
} }
MyMesh::~MyMesh() {
// Clean up dynamically allocated resources
#ifdef WITH_MQTT
delete _web_config;
_web_config = nullptr;
delete _mqtt_bridge;
_mqtt_bridge = nullptr;
#endif
#ifdef WITH_ETHERNET
delete _mqtt_bridge;
_mqtt_bridge = nullptr;
#endif
}
void MyMesh::begin(FILESYSTEM *fs) { void MyMesh::begin(FILESYSTEM *fs) {
mesh::Mesh::begin(); mesh::Mesh::begin();
_fs = fs; _fs = fs;

View File

@ -125,21 +125,21 @@ class MyMesh : public mesh::Mesh, public CommonCLICallbacks {
#ifdef WITH_MQTT #ifdef WITH_MQTT
WiFiManager _wifi_mgr; WiFiManager _wifi_mgr;
MQTTBridge* _mqtt_bridge; MQTTBridge* _mqtt_bridge = nullptr;
WebConfig* _web_config; WebConfig* _web_config = nullptr;
WiFiConfig _wifi_config; WiFiConfig _wifi_config;
MQTTConfig _mqtt_config; MQTTConfig _mqtt_config;
unsigned long _last_mqtt_stats; unsigned long _last_mqtt_stats = 0;
void initMQTT(); void initMQTT();
#endif #endif
#ifdef WITH_ETHERNET #ifdef WITH_ETHERNET
EthernetManager _eth_mgr; EthernetManager _eth_mgr;
MQTTBridge* _mqtt_bridge; MQTTBridge* _mqtt_bridge = nullptr;
MQTTConfig _mqtt_config; MQTTConfig _mqtt_config;
EthernetConfig _eth_config; EthernetConfig _eth_config;
unsigned long _last_mqtt_stats; unsigned long _last_mqtt_stats = 0;
void initEthernet(); void initEthernet();
#endif #endif
@ -196,6 +196,7 @@ protected:
public: public:
MyMesh(mesh::MainBoard& board, mesh::Radio& radio, mesh::MillisecondClock& ms, mesh::RNG& rng, mesh::RTCClock& rtc, mesh::MeshTables& tables); MyMesh(mesh::MainBoard& board, mesh::Radio& radio, mesh::MillisecondClock& ms, mesh::RNG& rng, mesh::RTCClock& rtc, mesh::MeshTables& tables);
~MyMesh(); // Clean up dynamically allocated resources
void begin(FILESYSTEM* fs); void begin(FILESYSTEM* fs);

View File

@ -10,6 +10,7 @@ WiFiManager::WiFiManager()
_retry_count(0), _retry_count(0),
_initialized(false) { _initialized(false) {
memset(&_config, 0, sizeof(_config)); memset(&_config, 0, sizeof(_config));
memset(_cached_ssid, 0, sizeof(_cached_ssid));
} }
void WiFiManager::begin(const WiFiConfig& config) { void WiFiManager::begin(const WiFiConfig& config) {
@ -82,6 +83,9 @@ void WiFiManager::loop() {
_state = WiFiState::CONNECTED; _state = WiFiState::CONNECTED;
_connected_since = millis(); _connected_since = millis();
_retry_count = 0; _retry_count = 0;
// Cache SSID to avoid dangling pointer from WiFi.SSID().c_str()
strncpy(_cached_ssid, WiFi.SSID().c_str(), sizeof(_cached_ssid) - 1);
_cached_ssid[sizeof(_cached_ssid) - 1] = '\0';
Serial.printf("[WiFi] Connected! IP: %s, RSSI: %d dBm\n", Serial.printf("[WiFi] Connected! IP: %s, RSSI: %d dBm\n",
WiFi.localIP().toString().c_str(), WiFi.RSSI()); WiFi.localIP().toString().c_str(), WiFi.RSSI());
} else if (status == WL_NO_SSID_AVAIL) { } else if (status == WL_NO_SSID_AVAIL) {
@ -184,6 +188,9 @@ void WiFiManager::startAPMode() {
if (success) { if (success) {
_state = WiFiState::AP_MODE; _state = WiFiState::AP_MODE;
// Cache AP SSID to avoid dangling pointer
strncpy(_cached_ssid, ap_ssid.c_str(), sizeof(_cached_ssid) - 1);
_cached_ssid[sizeof(_cached_ssid) - 1] = '\0';
Serial.printf("[WiFi] AP started: SSID='%s', IP=%s\n", Serial.printf("[WiFi] AP started: SSID='%s', IP=%s\n",
ap_ssid.c_str(), WiFi.softAPIP().toString().c_str()); ap_ssid.c_str(), WiFi.softAPIP().toString().c_str());
} else { } else {
@ -221,10 +228,8 @@ int32_t WiFiManager::getRSSI() const {
} }
const char* WiFiManager::getSSID() const { const char* WiFiManager::getSSID() const {
if (_state == WiFiState::CONNECTED) { if (_state == WiFiState::CONNECTED || _state == WiFiState::AP_MODE) {
return WiFi.SSID().c_str(); return _cached_ssid;
} else if (_state == WiFiState::AP_MODE) {
return WiFi.softAPSSID().c_str();
} }
return ""; return "";
} }
@ -264,10 +269,8 @@ NetworkState WiFiManager::getState() const {
} }
const char* WiFiManager::getConnectionName() const { const char* WiFiManager::getConnectionName() const {
if (_state == WiFiState::CONNECTED) { if (_state == WiFiState::CONNECTED || _state == WiFiState::AP_MODE) {
return WiFi.SSID().c_str(); return _cached_ssid;
} else if (_state == WiFiState::AP_MODE) {
return WiFi.softAPSSID().c_str();
} }
return "Not connected"; return "Not connected";
} }

View File

@ -61,6 +61,7 @@ private:
unsigned long _connected_since; unsigned long _connected_since;
uint8_t _retry_count; uint8_t _retry_count;
bool _initialized; bool _initialized;
char _cached_ssid[33]; // Cached SSID to avoid dangling pointer from WiFi.SSID().c_str()
void attemptConnection(); void attemptConnection();
void checkConnection(); void checkConnection();