wwbmmm opened a new pull request, #3575:
URL: https://github.com/apache/brpc/pull/3575

   ### What problem does this PR solve?
   
   Issue Number: resolve #N/A
   
   Problem Summary:
   
   `parse_encode_length` in `src/brpc/policy/mysql/mysql_reply.cpp` declared an 
uninitialized `uint8_t tmp[N]` (N=2/3/8) and called `IOBuf::cutn` without 
checking the return value. When a MySQL server sends a packet in which a 
length-encoded integer's 0xFC/0xFD/0xFE prefix is followed by fewer value bytes 
than promised, `cutn` only partially fills `tmp` and `mysql_uint*korr` then 
reads the uninitialized stack bytes as the value. The garbage value propagates 
into column counts, field lengths and loop bounds, producing unpredictable 
parse behavior (bogus lengths, stream desync, oversized allocations). By 
contrast, `parse_header` in the same file already validates its `cutn` result — 
this closes the protection gap.
   
   ### What is changed and the side effects?
   
   Changed:
   - `parse_encode_length` now returns `int64_t` and returns `-1` when the 
prefix byte or its 2/3/8 value bytes are not fully present, or when the prefix 
is the invalid 0xFF marker. `cut1`/`cutn` return values are checked, so no 
uninitialized memory is ever interpreted.
   - All call sites fail fast with `PARSE_ERROR_ABSOLUTELY_WRONG` on a 
truncated value: `ResultSetHeader::Parse` (column count / extra message), 
`Column::Parse` (all six length-encoded strings), `Ok::Parse` (affected rows / 
last insert id), text and binary `Field::Parse`, and the binary TIME/DATETIME 
parsers.
   - The six duplicated length-encoded-string blocks in `Column::Parse` are 
folded into one `parse_column_string` helper (same checks and log messages as 
before).
   
   Side effects:
   - Performance effects: none — the fix adds one branch per length-encoded 
integer on a non-hot parse path.
   - Breaking backward compatibility: no API changes. Packets that were 
previously parsed with garbage values (truncated length prefixes) are now 
rejected as malformed, which is the intended behavior; well-formed packets are 
unaffected.
   
   ### Check List:
   - Tests: added 4 cases to `test/brpc_mysql_reply_parse_unittest.cpp` — 
truncated 0xFC/0xFD/0xFE prefixes in column definitions (the reported 
scenario), truncated prefixes in row fields, truncated OK packets, plus a 
positive multi-byte (0xFC) length test. All 9 cases in 
`brpc_mysql_reply_parse_unittest` pass, and the auth/handshake/scramble mysql 
unit tests still pass.
   - Compilable: verified with cmake (`BUILD_UNIT_TESTS=ON`) full build.
   
   ---
   🤖 This PR was automatically created by brpc-oncall


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to