Copilot commented on code in PR #3576:
URL: https://github.com/apache/brpc/pull/3576#discussion_r4151373903
##########
src/mcpack2pb/parser.cpp:
##########
@@ -588,7 +595,8 @@ void UnparsedValue::as_string(std::string* out, const char*
var) {
}
out->resize(_size - 1);
if (_stream->cutn(&(*out)[0], _size - 1) != _size - 1) {
- CHECK(false) << "Not enough data for " << var;
+ LOG(ERROR) << "Not enough data for " << var;
+ _stream->set_bad();
Review Comment:
A truncated field can still terminate the process before this new error path
runs: `_size` is wire-controlled (up to `UINT32_MAX`), and `resize(_size - 1)`
eagerly allocates that amount even when the request contains only a few bytes.
An uncaught `std::bad_alloc`/`std::length_error` defeats the malformed-input
hardening. Consume into a bounded buffer and grow `out` only for bytes actually
present, then mark the stream bad on a short read.
This issue also appears on line 614 of the same file.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]