Copilot commented on code in PR #3576:
URL: https://github.com/apache/brpc/pull/3576#discussion_r4151512856


##########
src/mcpack2pb/parser.cpp:
##########
@@ -299,24 +306,24 @@ int64_t UnparsedValue::as_int64(const char* var) {
         if (value <= (uint64_t)std::numeric_limits<int64_t>::max()) {
             return (int64_t)value;
         }
-        CHECK(false) << "uint64=" << value << " to " << var << " overflows";
+        LOG(ERROR) << "uint64=" << value << " to " << var << " overflows";
         _stream->set_bad();
         return std::numeric_limits<int64_t>::max();
     }
     case PRIMITIVE_FIELD_BOOL:
         return _stream->cut_packed_pod<bool>();
     case PRIMITIVE_FIELD_FLOAT:
-        CHECK(false) << "Can't set float=" << _stream->cut_packed_pod<float>()
+        LOG(ERROR) << "Can't set float=" << _stream->cut_packed_pod<float>()
                      << " to " << var;
         _stream->set_bad();
         return 0;
     case PRIMITIVE_FIELD_DOUBLE:
-        CHECK(false) << "Can't set double=" << 
_stream->cut_packed_pod<double>()
+        LOG(ERROR) << "Can't set double=" << _stream->cut_packed_pod<double>()
                      << " to " << var;
         _stream->set_bad();

Review Comment:
   This still evaluates an indeterminate value for truncated input before 
marking the stream bad. The value-returning `cut_packed_pod<T>()` leaves its 
local uninitialized when `cutn()` returns fewer than `sizeof(T)`, which is 
reachable when the enclosing object declares enough bytes but the actual input 
ends before this float/double payload. Logging that value is undefined 
behavior, so malformed input is not guaranteed to be rejected safely. Make the 
primitive read initialize its result and mark the stream bad on a short read 
before any caller uses or logs it.
   
   This issue also appears in the following locations of the same file:
   - line 380
   - line 441
   - line 513
   - line 549



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to