wwbmmm opened a new pull request, #3575: URL: https://github.com/apache/brpc/pull/3575
### What problem does this PR solve? Issue Number: resolve #N/A Problem Summary: `parse_encode_length` in `src/brpc/policy/mysql/mysql_reply.cpp` declared an uninitialized `uint8_t tmp[N]` (N=2/3/8) and called `IOBuf::cutn` without checking the return value. When a MySQL server sends a packet in which a length-encoded integer's 0xFC/0xFD/0xFE prefix is followed by fewer value bytes than promised, `cutn` only partially fills `tmp` and `mysql_uint*korr` then reads the uninitialized stack bytes as the value. The garbage value propagates into column counts, field lengths and loop bounds, producing unpredictable parse behavior (bogus lengths, stream desync, oversized allocations). By contrast, `parse_header` in the same file already validates its `cutn` result — this closes the protection gap. ### What is changed and the side effects? Changed: - `parse_encode_length` now returns `int64_t` and returns `-1` when the prefix byte or its 2/3/8 value bytes are not fully present, or when the prefix is the invalid 0xFF marker. `cut1`/`cutn` return values are checked, so no uninitialized memory is ever interpreted. - All call sites fail fast with `PARSE_ERROR_ABSOLUTELY_WRONG` on a truncated value: `ResultSetHeader::Parse` (column count / extra message), `Column::Parse` (all six length-encoded strings), `Ok::Parse` (affected rows / last insert id), text and binary `Field::Parse`, and the binary TIME/DATETIME parsers. - The six duplicated length-encoded-string blocks in `Column::Parse` are folded into one `parse_column_string` helper (same checks and log messages as before). Side effects: - Performance effects: none — the fix adds one branch per length-encoded integer on a non-hot parse path. - Breaking backward compatibility: no API changes. Packets that were previously parsed with garbage values (truncated length prefixes) are now rejected as malformed, which is the intended behavior; well-formed packets are unaffected. ### Check List: - Tests: added 4 cases to `test/brpc_mysql_reply_parse_unittest.cpp` — truncated 0xFC/0xFD/0xFE prefixes in column definitions (the reported scenario), truncated prefixes in row fields, truncated OK packets, plus a positive multi-byte (0xFC) length test. All 9 cases in `brpc_mysql_reply_parse_unittest` pass, and the auth/handshake/scramble mysql unit tests still pass. - Compilable: verified with cmake (`BUILD_UNIT_TESTS=ON`) full build. --- 🤖 This PR was automatically created by brpc-oncall -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
