Copilot commented on code in PR #3575:
URL: https://github.com/apache/brpc/pull/3575#discussion_r4151537077
##########
src/brpc/policy/mysql/mysql_reply.cpp:
##########
@@ -555,12 +599,14 @@ ParseError
MysqlReply::ResultSetHeader::Parse(butil::IOBuf& buf) {
return PARSE_OK;
}
MysqlHeader header;
- if (!parse_header(buf, &header)) {
+ butil::IOBuf payload;
+ if (!parse_header(buf, &header, &payload)) {
return PARSE_ERROR_NOT_ENOUGH_DATA;
}
- uint64_t old_size, new_size;
- old_size = buf.size();
- _column_count = parse_encode_length(buf);
+ if (!parse_encode_length(payload, &_column_count)) {
+ LOG(ERROR) << "MysqlReply::ResultSetHeader::Parse: truncated column
count";
+ return PARSE_ERROR_ABSOLUTELY_WRONG;
Review Comment:
Multi-byte column counts never reach this validation. On a fresh
normal-statement reply, the dispatcher treats wire `0xFC` as the synthetic
`MYSQL_RSP_PREPARE_OK` type, so a valid 251–4096-column result is misclassified
and a truncated `0xFC` reaches unchecked prepare-header reads. It also treats
every `0xFE` payload as EOF, even though EOF is distinguishable by a payload
shorter than 9 bytes, bypassing the new count cap. Dispatch prepare replies
from `stmt_type`/an already-selected `_type`, and use the packet length to
distinguish EOF before parsing the result-set count; add direct
complete/truncated column-count tests.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]