Copilot commented on code in PR #13768:
URL: https://github.com/apache/trafficserver/pull/13768#discussion_r4153113647
##########
src/iocore/cache/CacheVC.cc:
##########
@@ -403,6 +403,15 @@ CacheVC::handleReadDone(int event, Event * /* e ATS_UNUSED
*/)
goto Ldone;
}
+ // Everything below trusts len and hlen, and STORE_COLLISION lets a doc
that is not ours get this far.
+ if (doc->magic == DOC_MAGIC &&
+ (doc->len < sizeof(Doc) || doc->len > io.aiocb.aio_nbytes || doc->hlen
> doc->len - sizeof(Doc))) {
Review Comment:
The new `doc->len < sizeof(Doc)` rejection path is not exercised: every
`boundary_cases` row uses a length of at least 3584. This guard also prevents
underflow in the following `hlen` bound, so please add a case such as `len =
sizeof(Doc) - 1` that expects `DOC_CORRUPT`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]