Copilot commented on code in PR #3576:
URL: https://github.com/apache/brpc/pull/3576#discussion_r4151512856
##########
src/mcpack2pb/parser.cpp:
##########
@@ -299,24 +306,24 @@ int64_t UnparsedValue::as_int64(const char* var) {
if (value <= (uint64_t)std::numeric_limits<int64_t>::max()) {
return (int64_t)value;
}
- CHECK(false) << "uint64=" << value << " to " << var << " overflows";
+ LOG(ERROR) << "uint64=" << value << " to " << var << " overflows";
_stream->set_bad();
return std::numeric_limits<int64_t>::max();
}
case PRIMITIVE_FIELD_BOOL:
return _stream->cut_packed_pod<bool>();
case PRIMITIVE_FIELD_FLOAT:
- CHECK(false) << "Can't set float=" << _stream->cut_packed_pod<float>()
+ LOG(ERROR) << "Can't set float=" << _stream->cut_packed_pod<float>()
<< " to " << var;
_stream->set_bad();
return 0;
case PRIMITIVE_FIELD_DOUBLE:
- CHECK(false) << "Can't set double=" <<
_stream->cut_packed_pod<double>()
+ LOG(ERROR) << "Can't set double=" << _stream->cut_packed_pod<double>()
<< " to " << var;
_stream->set_bad();
Review Comment:
This still evaluates an indeterminate value for truncated input before
marking the stream bad. The value-returning `cut_packed_pod<T>()` leaves its
local uninitialized when `cutn()` returns fewer than `sizeof(T)`, which is
reachable when the enclosing object declares enough bytes but the actual input
ends before this float/double payload. Logging that value is undefined
behavior, so malformed input is not guaranteed to be rejected safely. Make the
primitive read initialize its result and mark the stream bad on a short read
before any caller uses or logs it.
This issue also appears in the following locations of the same file:
- line 380
- line 441
- line 513
- line 549
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]