Refuse a PDU whose optional parameters do not end on command_length (#87)

* Regression tests for a truncated TLV tail refused rather than accepted

* Refuse a PDU whose optional parameters do not end on command_length

* Assert the bare TLV header refusal against jsmpp instead of recording it as a defect

* Note the truncated TLV tail defect as fixed in the java-client findings

* Derive the padding position, share the bare TLV fixture and trim the decision record

* Regression tests for a PDU whose trailing C-Octet String a peer left out

* An absent trailing C-Octet String consumes no octet, so a bodyless PDU still parses

* Bound the TLV loop by the buffer it was given rather than a second spelling of its length

* Answer the stability review's questions in the record and pin the array contract
This commit is contained in:
2026-09-06 18:01:35 +02:00
committed by GitHub
parent c89005168d
commit 039951e69b
11 changed files with 215 additions and 85 deletions
+9
View File
@@ -38,3 +38,12 @@ export function truncatedTlv(input: PduObjectInput): Buffer {
return appended;
}
/** The same, ending in a bare TLV header: a tag, a declared length, and no value octets at all. */
export function bareTlvHeader(input: PduObjectInput): Buffer {
const appended = Buffer.concat([pduBytes(input), Buffer.from('001d00c8', 'hex')]);
appended.writeUInt32BE(appended.length, 0);
return appended;
}