ubeddulla opened a new pull request, #3577: URL: https://github.com/apache/brpc/pull/3577
ConvertGrpcTimeoutToUS parses the grpc-timeout header from any gRPC client but only checks that a single unit char trails the digits, so a value with many digits (or a negative one) flows into timeout_value * <unit> and overflows int64, which is undefined and then lands a bogus deadline in gettimeofday_us() on the request path. The gRPC-over-HTTP2 spec caps TimeoutValue at an 8-digit positive integer, so reject anything outside 0..99999999 before the multiply. The added regression test decodes a 999999999999999999H timeout, which returns a wrapped value today and -1 after the change. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
