From d7c88780e1df54f34563d60bd7fa01011d2eef03 Mon Sep 17 00:00:00 2001
From: chenluhua1980 <Chenluhua@qq.com>
Date: 星期一, 26 一月 2026 23:17:17 +0800
Subject: [PATCH] 1.CSVData.cpp 里 unserialize 用了 8*2、125*2,但 serialize 只写 8 + 125 字节。 m_svRawData.insert 的 end 指针是 pszBuffer + 125*2,没有用 index 计算,可能把无效区域一起拷进去。 一旦 size 实际是 133(不是 266),就会直接越界,堆会被破坏,m_svDatas.clear() 在销毁元素时崩。
---
SourceCode/Bond/Servo/CEqStatusStep.cpp | 40 ++++++++++++++++++++++++++++++++++------
1 files changed, 34 insertions(+), 6 deletions(-)
diff --git a/SourceCode/Bond/Servo/CEqStatusStep.cpp b/SourceCode/Bond/Servo/CEqStatusStep.cpp
index 9df8a03..3f8195a 100644
--- a/SourceCode/Bond/Servo/CEqStatusStep.cpp
+++ b/SourceCode/Bond/Servo/CEqStatusStep.cpp
@@ -5,11 +5,11 @@
namespace SERVO {
- CEqStatusStep::CEqStatusStep() : CStep()
+ CEqStatusStep::CEqStatusStep() : CReadStep()
{
m_nStatusDev = 0;
for (int i = 0; i < STATUS_MAX; i++) {
- m_nStatus[i] = 7;
+ m_nStatus[i] = 0;
m_nReasonCode[i] = 0;
}
@@ -21,9 +21,37 @@
}
+ void CEqStatusStep::getAttributeVector(CAttributeVector& attrubutes)
+ {
+ CReadStep::getAttributeVector(attrubutes);
+
+ unsigned int weight = 31;
+ char szName[256];
+ for (int i = 0; i < STATUS_MAX; i++) {
+ sprintf_s(szName, 256, "Status %d", i + 1);
+ attrubutes.addAttribute(new CAttribute(szName,
+ std::to_string(m_nStatus[i]).c_str(), "", weight++));
+ sprintf_s(szName, 256, "Reason Code %d", i + 1);
+ attrubutes.addAttribute(new CAttribute(szName,
+ std::to_string(m_nReasonCode[i]).c_str(), "", weight++));
+ }
+
+ std::string strTemp;
+ attrubutes.addAttribute(new CAttribute("Status Dev",
+ ("W" + CToolUnits::toHexString(m_nStatusDev, strTemp)).c_str(), "", weight++));
+ }
+
+ int CEqStatusStep::getStatus(unsigned int uint)
+ {
+ if (uint < STATUS_MAX) {
+ return m_nStatus[uint];
+ }
+
+ return -1;
+ }
int CEqStatusStep::onReadData()
{
- CStep::onReadData();
+ CReadStep::onReadData();
char szBuffer[64];
int nRet = m_pCclink->ReadData2(m_station, DeviceType::W,
@@ -56,7 +84,7 @@
int CEqStatusStep::onComplete()
{
- CStep::onComplete();
+ CReadStep::onComplete();
LOGI("<CEqStatusStep> onComplete.");
return 0;
@@ -64,8 +92,8 @@
int CEqStatusStep::onTimeout()
{
- CStep::onTimeout();
- LOGI("<CEqStatusStep> onTimeout.");
+ CReadStep::onTimeout();
+ LOGE("<CEqStatusStep> onTimeout.");
return 0;
}
--
Gitblit v1.9.3