Copilot commented on code in PR #3575:
URL: https://github.com/apache/brpc/pull/3575#discussion_r4151537077


##########
src/brpc/policy/mysql/mysql_reply.cpp:
##########
@@ -555,12 +599,14 @@ ParseError 
MysqlReply::ResultSetHeader::Parse(butil::IOBuf& buf) {
         return PARSE_OK;
     }
     MysqlHeader header;
-    if (!parse_header(buf, &header)) {
+    butil::IOBuf payload;
+    if (!parse_header(buf, &header, &payload)) {
         return PARSE_ERROR_NOT_ENOUGH_DATA;
     }
-    uint64_t old_size, new_size;
-    old_size = buf.size();
-    _column_count = parse_encode_length(buf);
+    if (!parse_encode_length(payload, &_column_count)) {
+        LOG(ERROR) << "MysqlReply::ResultSetHeader::Parse: truncated column 
count";
+        return PARSE_ERROR_ABSOLUTELY_WRONG;

Review Comment:
   Multi-byte column counts never reach this validation. On a fresh 
normal-statement reply, the dispatcher treats wire `0xFC` as the synthetic 
`MYSQL_RSP_PREPARE_OK` type, so a valid 251–4096-column result is misclassified 
and a truncated `0xFC` reaches unchecked prepare-header reads. It also treats 
every `0xFE` payload as EOF, even though EOF is distinguishable by a payload 
shorter than 9 bytes, bypassing the new count cap. Dispatch prepare replies 
from `stmt_type`/an already-selected `_type`, and use the packet length to 
distinguish EOF before parsing the result-set count; add direct 
complete/truncated column-count tests.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to