agessaman 8d1a0eb333 fix(mqtt): reject invalid path encodings before serializing
canSerialize() validated payload_len and the destination size but not whether the
path encoding is one writePath() will actually emit. writePath() self-guards
against overrunning the path array, but it does so by writing nothing and
returning 0 — a correctness problem, not a safety one, because getRawLength()
still counts the path. An over-long or reserved encoding therefore passed the
size check and then serialized to a truncated frame that was published as the
packet.

Worst case is path_len 0xFF with no payload: 63 hops of 4 bytes counts as 254
bytes, inside the 255-byte buffer, while writeTo() emits just the 2-byte header.
The `raw` field would carry 4 hex chars presented as the frame. Reserved 4-byte
hash encodings passed too, producing frames Packet::readFrom() rejects.

Now gated on Packet::isValidPathLen(), which rejects the reserved 4-byte hash
size and any count * size above MAX_PATH_SIZE in one predicate. It is the same
check readFrom() applies to every received packet, and TX packets are built via
setPathHashSizeAndCount() with real hash sizes, so no decodable packet is turned
away.

Two tests added for the cases a destination-size check cannot reach. The existing
truncation test passed for the wrong reason -- its payload_len of 4 pushed
getRawLength() to 258 and tripped the size check, masking the hole -- so it is
split into the >0xFF truncation case and the counted-length-fits case, with the
254/2-byte asymmetry asserted explicitly so it cannot be masked again.

274/274 native tests; both observer envs and an nRF52 repeater build clean.
2026-08-04 14:06:32 -07:00
2026-06-05 09:49:57 -07:00
2026-04-28 21:39:34 +10:00
2025-01-13 14:07:48 +11:00
2025-06-05 20:35:40 +12:00
2026-02-03 13:47:43 +13:00
2026-03-23 14:26:56 +01:00
2025-01-20 10:20:42 +11:00
2025-01-25 23:09:09 +11:00
2026-03-31 00:51:15 +13:00
2025-03-03 18:08:00 +13:00
2026-06-05 21:25:25 +12:00

About MeshCore

MeshCore is a lightweight, portable C++ library that enables multi-hop packet routing for embedded projects using LoRa and other packet radios. It is designed for developers who want to create resilient, decentralized communication networks that work without the internet.

🔍 What is MeshCore?

MeshCore now supports a range of LoRa devices, allowing for easy flashing without the need to compile firmware manually. Users can flash a pre-built binary using tools like Adafruit ESPTool and interact with the network through a serial console. MeshCore provides the ability to create wireless mesh networks, similar to Meshtastic and Reticulum but with a focus on lightweight multi-hop packet routing for embedded projects. Unlike Meshtastic, which is tailored for casual LoRa communication, or Reticulum, which offers advanced networking, MeshCore balances simplicity with scalability, making it ideal for custom embedded solutions, where devices (nodes) can communicate over long distances by relaying messages through intermediate nodes. This is especially useful in off-grid, emergency, or tactical situations where traditional communication infrastructure is unavailable.

MQTT Observer Setup — Prebuilt observer firmware, docs, and a changelog are at observer.gessaman.com. See the MQTT Implementation Guide for configuration, CLI commands, and troubleshooting.

Key Features

  • Multi-Hop Packet Routing
    • Devices can forward messages across multiple nodes, extending range beyond a single radio's reach.
    • Supports up to a configurable number of hops to balance network efficiency and prevent excessive traffic.
    • Nodes use fixed roles where "Companion" nodes are not repeating messages at all to prevent adverse routing paths from being used.
  • Supports LoRa Radios Works with Heltec, RAK Wireless, and other LoRa-based hardware.
  • Decentralized & Resilient No central server or internet required; the network is self-healing.
  • Low Power Consumption Ideal for battery-powered or solar-powered devices.
  • Simple to Deploy Pre-built example applications make it easy to get started.

🎯 What Can You Use MeshCore For?

  • Off-Grid Communication: Stay connected even in remote areas.
  • Emergency Response & Disaster Recovery: Set up instant networks where infrastructure is down.
  • Outdoor Activities: Hiking, camping, and adventure racing communication.
  • Tactical & Security Applications: Military, law enforcement, and private security use cases.
  • IoT & Sensor Networks: Collect data from remote sensors and relay it back to a central location.

🚀 How to Get Started

For developers:

The Simple Secure Chat example can be interacted with through the Serial Monitor in Visual Studio Code, or with a Serial USB Terminal on Android.

MeshCore Flasher

We have prebuilt firmware ready to flash on supported devices.

  • Launch https://meshcore.io/flasher
  • Select a supported device
  • Flash one of the firmware types:
    • Companion, Repeater or Room Server
  • Once flashing is complete, you can connect with one of the MeshCore clients below.

📱 MeshCore Clients

Companion Firmware

The companion firmware can be connected to via BLE, USB or Wi-Fi depending on the firmware type you flashed.

Repeater and Room Server Firmware

The repeater and room server firmware can be set up via USB in the web config tool.

They can also be managed via LoRa in the mobile app by using the Remote Management feature.

🛠 Hardware Compatibility

MeshCore is designed for devices listed in the MeshCore Flasher

📜 License

MeshCore is open-source software released under the MIT License. You are free to use, modify, and distribute it for personal and commercial projects.

Contributing

Please submit PR's using 'dev' as the base branch! For minor changes just submit your PR and we'll try to review it, but for anything more 'impactful' please open an Issue first and start a discussion. It is better to sound out what it is you want to achieve first, and try to come to a consensus on what the best approach is, especially when it impacts the structure or architecture of this codebase.

Here are some general principles you should try to adhere to:

  • Keep it simple. Please, don't think like a high-level lang programmer. Think embedded, and keep code concise, without any unnecessary layers.
  • No dynamic memory allocation, except during setup/begin functions.
  • Use the same brace and indenting style that's in the core source modules. (A .clang-format is probably going to be added soon, but please do NOT retroactively re-format existing code. This just creates unnecessary diffs that make finding problems harder)

Help us prioritize! Please react with thumbs-up to issues/PRs you care about most. We look at reaction counts when planning work.

Running unit tests

To run unit tests, run the following command:

pio test --environment native --verbose

Road-Map / To-Do

There are a number of fairly major features in the pipeline, with no particular time-frames attached yet. In very rough chronological order:

  • Companion radio: UI redesign
  • Repeater + Room Server: add ACL's (like Sensor Node has)
  • Standardise Bridge mode for repeaters
  • Repeater/Bridge: Standardise the Transport Codes for zoning/filtering
  • Core + Repeater: enhanced zero-hop neighbour discovery
  • Core: round-trip manual path support
  • Companion + Apps: support for multiple sub-meshes (and 'off-grid' client repeat mode)
  • Core + Apps: support for LZW message compression
  • Core: dynamic CR (Coding Rate) for weak vs strong hops
  • Core: new framework for hosting multiple virtual nodes on one physical device
  • V2 protocol spec: discussion and consensus around V2 packet protocol, including path hashes, new encryption specs, etc

📞 Get Support

  • Report bugs and request features on the GitHub Issues page.
  • Find additional guides and components on my site.
  • Join MeshCore Discord to chat with the developers and get help from the community.
S
Description
No description provided
Readme
38 MiB
Languages
C 57.9%
C++ 41.1%
Python 0.6%
Shell 0.3%
Linker Script 0.1%