darion-yaphet opened a new pull request, #3570:
URL: https://github.com/apache/brpc/pull/3570

   ### What problem does this PR solve?
   
   Problem Summary:
   
   RedisCommandFormatV formats arguments into a fixed 40-byte stack buffer. 
vsnprintf returns the full output length, but the code used that length even 
when the output exceeded the buffer, causing an out-of-bounds stack read for 
wide or high-precision format specifiers.
   
   The PR also makes the existing component-based Redis command API easier to 
use with std::vector.
   
   ### What is changed and the side effects?
   
   Changed:
   
   Keep the stack-buffer path for short formatted values; retry longer values 
using a dynamically sized buffer.
   Add a RedisRequest::AddCommandByComponents overload for 
std::vector<butil::StringPiece>.
   Use the component API for Redis authentication and cluster command 
construction.
   Document the vector overload and add regression tests for wide formatting, 
binary parameters, and credential encoding.
   
   Side effects:
   
   Performance effects: Short formatted values keep the stack-buffer path. 
Values exceeding its capacity allocate a larger buffer.
   Breaking backward compatibility: None intended. Existing formatting and 
pointer/count APIs remain available.
   
   ### Check List:
   
   [x] Changes compile: brpc_redis_unittest target built successfully.
   [x] Added and passed focused regression tests, including the cluster routing 
test.
   [x] Followed the Contributor Covenant Code of Conduct.
   
   Note: The existing RedisTest.by_components and RedisTest.auth integration 
tests could not connect because the local Redis server exited during startup 
with a locale configuration error.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to