AnDiXL commented on code in PR #3558:
URL: https://github.com/apache/brpc/pull/3558#discussion_r4111002078
##########
CMakeLists.txt:
##########
@@ -82,6 +83,17 @@ if(WITH_GLOG)
set(BRPC_WITH_GLOG 1)
endif()
+set(WITH_FLATBUFFERS_VAL "0")
+if(WITH_FLATBUFFERS)
+ find_path(FLATBUFFERS_INCLUDE_DIR NAMES flatbuffers/flatbuffers.h)
Review Comment:
Thanks, this makes sense. The implementation depends on FlatBuffers builder
internals, so accepting an arbitrary installed FlatBuffers version is too
loose. I will add an explicit compile-time version guard in the public
FlatBuffers message header and document the supported/tested version range in
both docs. The goal is to fail early with a clear diagnostic instead of relying
on an internal-layout compile error or allocator abort.
##########
src/brpc/flatbuffers/message.h:
##########
@@ -0,0 +1,166 @@
+// Licensed to the Apache Software Foundation (ASF) under one
+// or more contributor license agreements. See the NOTICE file
+// distributed with this work for additional information
+// regarding copyright ownership. The ASF licenses this file
+// to you under the Apache License, Version 2.0 (the
+// "License"); you may not use this file except in compliance
+// with the License. You may obtain a copy of the License at
+//
+// http://www.apache.org/licenses/LICENSE-2.0
+//
+// Unless required by applicable law or agreed to in writing,
+// software distributed under the License is distributed on an
+// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+// KIND, either express or implied. See the License for the
+// specific language governing permissions and limitations
+// under the License.
+
+#ifndef BRPC_FLATBUFFERS_MESSAGE_H
+#define BRPC_FLATBUFFERS_MESSAGE_H
+
+#include "butil/config.h"
+
+#if BRPC_WITH_FLATBUFFERS
+#include <cstddef>
+#include <cstdint>
+#include <utility>
+#include <flatbuffers/flatbuffers.h>
+#include "butil/single_iobuf.h"
+#include "brpc/nonreflectable_message.h"
+
+namespace brpc {
+namespace flatbuffers {
+
+// Space preceding a payload, available to a future RPC transport.
+constexpr uint32_t kDefaultMetaSize = 64;
+// IOBuf slices need not start at an aligned address. The allocator corrects
it.
+constexpr size_t kBufferAlignment = 64;
+
+class MessageBuilder;
+
+// FlatBufferBuilder cannot recover from a null allocation. Allocation failure
+// and sizes outside FlatBuffers' offset range are fatal, even in release
builds.
+class SlabAllocator : public ::flatbuffers::Allocator {
+public:
+ SlabAllocator() : _data(nullptr), _capacity(0) {}
+ SlabAllocator(const SlabAllocator&) = delete;
+ SlabAllocator& operator=(const SlabAllocator&) = delete;
+ SlabAllocator(SlabAllocator&& other) noexcept : SlabAllocator() {
+ swap(other);
+ }
+ SlabAllocator& operator=(SlabAllocator&& other) noexcept;
+
+ uint8_t* allocate(size_t size) override;
+ void deallocate(uint8_t* p, size_t size) override;
+ uint8_t* reallocate_downward(uint8_t* old_p, size_t old_size,
+ size_t new_size, size_t in_use_back,
+ size_t in_use_front) override;
+ void swap(SlabAllocator& other) noexcept;
+
+private:
+ butil::SingleIOBuf _iobuf;
+ uint8_t* _data;
+ size_t _capacity;
+ friend class MessageBuilder;
+};
+
+// Construct the allocator before the FlatBufferBuilder base uses it, and
+// destroy it after that base has returned its buffer.
+struct SlabAllocatorMember {
+ SlabAllocator slab_allocator_;
+};
+
+// A move-only message. Parsing checks framing, not the schema: Verify<T>()
+// must succeed before reading data received from an untrusted peer.
+class Message : public NonreflectableMessage<Message> {
+public:
+ Message() : _meta_size(0), _msg_size(0) {}
+ Message(const Message&) = delete;
+ Message& operator=(const Message&) = delete;
+ Message(Message&& other) noexcept : Message() { Swap(other); }
+ Message& operator=(Message&& other) noexcept;
+
+ void MergeFrom(const Message&) override;
+ void Clear() override;
+ void Swap(Message& other) noexcept;
+
+ const uint8_t* data() const;
+ void* mutable_data() { return const_cast<uint8_t*>(data()); }
+ void* mutable_buf_begin() {
+ return const_cast<void*>(_iobuf.get_begin());
+ }
+ void* reduce_meta_size_and_get_buf(uint32_t new_size);
+ uint32_t get_meta_size() const { return _meta_size; }
+ size_t size() const { return _msg_size; }
+
+ template <typename T>
+ bool Verify() const {
+ if (!data() || size() < sizeof(::flatbuffers::uoffset_t) ||
+ size() >= FLATBUFFERS_MAX_BUFFER_SIZE) {
+ return false;
+ }
+ ::flatbuffers::Verifier verifier(data(), size());
+ return verifier.VerifyBuffer<T>(nullptr);
+ }
+
+ // These accessors require a schema-verified buffer.
+ template <typename T> const T* GetRoot() const {
+ return data() ? ::flatbuffers::GetRoot<T>(data()) : nullptr;
+ }
+ template <typename T> T* GetMutableRoot() {
+ return data() ? ::flatbuffers::GetMutableRoot<T>(mutable_data()) :
nullptr;
+ }
+
+ // Failure leaves the old message unchanged. A fragmented or unaligned
+ // payload is copied into aligned storage; aligned contiguous input is
shared.
+ bool parse_msg_from_iobuf(const butil::IOBuf& buf, size_t msg_size,
Review Comment:
Agreed. `parse_msg_from_iobuf` only owns framing/alignment/storage
conversion; it should not be read as a receive-side admission limit or schema
validator. I will make the caller contract explicit in `message.h` and the
docs: callers must bound `msg_size` with their own max-message-size policy
before parsing untrusted input, and must call `Verify<T>()` before reading the
root.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]