wwbmmm commented on code in PR #3558:
URL: https://github.com/apache/brpc/pull/3558#discussion_r4092179612
##########
CMakeLists.txt:
##########
@@ -82,6 +83,17 @@ if(WITH_GLOG)
set(BRPC_WITH_GLOG 1)
endif()
+set(WITH_FLATBUFFERS_VAL "0")
+if(WITH_FLATBUFFERS)
+ find_path(FLATBUFFERS_INCLUDE_DIR NAMES flatbuffers/flatbuffers.h)
Review Comment:
[replied by brpc-oncall robot] `WITH_FLATBUFFERS` is validated only by the
existence of `flatbuffers/flatbuffers.h`, but the runtime does not use
FlatBuffers purely through its public API: `src/brpc/flatbuffers/message.cpp`
reaches into builder internals (`buf_`, `buf_.swap_allocator()`,
`scratch_push_small()`, `string_pool`, `minalign_`), and `SlabAllocator`
asserts on the exact `allocate()`/`reallocate_downward()` size bookkeeping
(only one live allocation, `old_size == _capacity`). Bazel pins 25.2.10 while
CMake and `config_brpc.sh` accept any installed version, so with a different
FlatBuffers an unsupported version fails deep in compilation or aborts inside
the allocator. Please add a compile-time guard in
`src/brpc/flatbuffers/message.h` (e.g. `#if !defined(FLATBUFFERS_VERSION_MAJOR)
|| FLATBUFFERS_VERSION_MAJOR < X` -> `#error`) and document the supported
range, so users get a clear diagnostic instead of an obscure failure.
##########
src/brpc/flatbuffers/message.h:
##########
@@ -0,0 +1,166 @@
+// Licensed to the Apache Software Foundation (ASF) under one
+// or more contributor license agreements. See the NOTICE file
+// distributed with this work for additional information
+// regarding copyright ownership. The ASF licenses this file
+// to you under the Apache License, Version 2.0 (the
+// "License"); you may not use this file except in compliance
+// with the License. You may obtain a copy of the License at
+//
+// http://www.apache.org/licenses/LICENSE-2.0
+//
+// Unless required by applicable law or agreed to in writing,
+// software distributed under the License is distributed on an
+// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+// KIND, either express or implied. See the License for the
+// specific language governing permissions and limitations
+// under the License.
+
+#ifndef BRPC_FLATBUFFERS_MESSAGE_H
+#define BRPC_FLATBUFFERS_MESSAGE_H
+
+#include "butil/config.h"
+
+#if BRPC_WITH_FLATBUFFERS
+#include <cstddef>
+#include <cstdint>
+#include <utility>
+#include <flatbuffers/flatbuffers.h>
+#include "butil/single_iobuf.h"
+#include "brpc/nonreflectable_message.h"
+
+namespace brpc {
+namespace flatbuffers {
+
+// Space preceding a payload, available to a future RPC transport.
+constexpr uint32_t kDefaultMetaSize = 64;
+// IOBuf slices need not start at an aligned address. The allocator corrects
it.
+constexpr size_t kBufferAlignment = 64;
+
+class MessageBuilder;
+
+// FlatBufferBuilder cannot recover from a null allocation. Allocation failure
+// and sizes outside FlatBuffers' offset range are fatal, even in release
builds.
+class SlabAllocator : public ::flatbuffers::Allocator {
+public:
+ SlabAllocator() : _data(nullptr), _capacity(0) {}
+ SlabAllocator(const SlabAllocator&) = delete;
+ SlabAllocator& operator=(const SlabAllocator&) = delete;
+ SlabAllocator(SlabAllocator&& other) noexcept : SlabAllocator() {
+ swap(other);
+ }
+ SlabAllocator& operator=(SlabAllocator&& other) noexcept;
+
+ uint8_t* allocate(size_t size) override;
+ void deallocate(uint8_t* p, size_t size) override;
+ uint8_t* reallocate_downward(uint8_t* old_p, size_t old_size,
+ size_t new_size, size_t in_use_back,
+ size_t in_use_front) override;
+ void swap(SlabAllocator& other) noexcept;
+
+private:
+ butil::SingleIOBuf _iobuf;
+ uint8_t* _data;
+ size_t _capacity;
+ friend class MessageBuilder;
+};
+
+// Construct the allocator before the FlatBufferBuilder base uses it, and
+// destroy it after that base has returned its buffer.
+struct SlabAllocatorMember {
+ SlabAllocator slab_allocator_;
+};
+
+// A move-only message. Parsing checks framing, not the schema: Verify<T>()
+// must succeed before reading data received from an untrusted peer.
+class Message : public NonreflectableMessage<Message> {
+public:
+ Message() : _meta_size(0), _msg_size(0) {}
+ Message(const Message&) = delete;
+ Message& operator=(const Message&) = delete;
+ Message(Message&& other) noexcept : Message() { Swap(other); }
+ Message& operator=(Message&& other) noexcept;
+
+ void MergeFrom(const Message&) override;
+ void Clear() override;
+ void Swap(Message& other) noexcept;
+
+ const uint8_t* data() const;
+ void* mutable_data() { return const_cast<uint8_t*>(data()); }
+ void* mutable_buf_begin() {
+ return const_cast<void*>(_iobuf.get_begin());
+ }
+ void* reduce_meta_size_and_get_buf(uint32_t new_size);
+ uint32_t get_meta_size() const { return _meta_size; }
+ size_t size() const { return _msg_size; }
+
+ template <typename T>
+ bool Verify() const {
+ if (!data() || size() < sizeof(::flatbuffers::uoffset_t) ||
+ size() >= FLATBUFFERS_MAX_BUFFER_SIZE) {
+ return false;
+ }
+ ::flatbuffers::Verifier verifier(data(), size());
+ return verifier.VerifyBuffer<T>(nullptr);
+ }
+
+ // These accessors require a schema-verified buffer.
+ template <typename T> const T* GetRoot() const {
+ return data() ? ::flatbuffers::GetRoot<T>(data()) : nullptr;
+ }
+ template <typename T> T* GetMutableRoot() {
+ return data() ? ::flatbuffers::GetMutableRoot<T>(mutable_data()) :
nullptr;
+ }
+
+ // Failure leaves the old message unchanged. A fragmented or unaligned
+ // payload is copied into aligned storage; aligned contiguous input is
shared.
+ bool parse_msg_from_iobuf(const butil::IOBuf& buf, size_t msg_size,
Review Comment:
[replied by brpc-oncall robot] `parse_msg_from_iobuf` (and therefore
`ParseFbFromIOBUF`) accepts any `msg_size` below `FLATBUFFERS_MAX_BUFFER_SIZE`
and, for fragmented or insufficiently aligned input, copies that many bytes
into a fresh allocation before anything is verified. Once the RPC transport
lands this length comes from an untrusted peer. Please state the caller
contract here (and in `docs/en/flatbuffers.md`): the caller must bound
`msg_size` with its own max-message-size setting and must call `Verify<T>()`
before reading, so the receive-side limit is not left implicit.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]