[ 
https://issues.apache.org/jira/browse/THRIFT-6136?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Dmytro Shteflyuk resolved THRIFT-6136.
--------------------------------------
    Fix Version/s: 0.25.0
       Resolution: Fixed

> Stop suppressing Ruby integer conversion errors in fuzzing
> ----------------------------------------------------------
>
>                 Key: THRIFT-6136
>                 URL: https://issues.apache.org/jira/browse/THRIFT-6136
>             Project: Thrift
>          Issue Type: Bug
>          Components: Ruby - Library
>            Reporter: Dmytro Shteflyuk
>            Assignee: Dmytro Shteflyuk
>            Priority: Major
>             Fix For: 0.25.0
>
>          Time Spent: 40m
>  Remaining Estimate: 0h
>
> h3. Problem
> The Ruby fuzz harness ignores selected integer-conversion errors by matching 
> their message text. This lets integer-boundary errors from the native 
> extension remain hidden, while the result also depends on MRI's wording: Ruby 
> 3.3 uses the backtick form {{too big to convert to `int'}}, but the filter 
> recognizes only the single-quote form.
> The supplied minimized Compact roundtrip input declares a map size of 
> 2684354528. The native {{Thrift::Struct#read}} path narrows that unsigned 
> 32-bit value to a signed C {{int}} before reading the map contents.
> h3. Client impact
> Malformed or truncated Compact input can raise an implementation-specific 
> {{RangeError}} when the native extension is loaded, while the pure-Ruby 
> implementation raises {{EOFError}} for the same bytes. Message-based 
> suppression also prevents fuzzing from reliably exposing similar 
> integer-conversion leaks so they can be corrected at their source.
> h3. Reproduction
> From {{lib/rb}}:
> {code:bash}
> bundle exec rake gen-rb:fuzz build_ext
> ruby -Ilib -Iext -Itest/fuzz/gen-rb -e 'require "thrift"; require 
> "fuzz_test_constants"; data = ["9be0ffffff092c0c"].pack("H*"); protocol = 
> Thrift::CompactProtocolFactory.new.get_protocol(Thrift::MemoryBufferTransport.new(data));
>  Fuzz::FuzzTest.new.read(protocol)'
> {code}
> Testing on master commit {{831306e501cbcd261cdbd8c2a3b8c44232704ceb}} 
> produces:
> {code}
> -e:1:in 'Thrift::Struct#read': integer 2684354528 too big to convert to 'int' 
> (RangeError)
> {code}
> Running the same command without {{-Iext}} uses the pure-Ruby implementation 
> and produces:
> {code}
> Not enough bytes remain in buffer (EOFError)
> {code}
> The same signed narrowing is present when the native struct reader processes 
> map, list, and set sizes above {{2147483647}}.
> h3. Expected behavior
> The fuzz harness should suppress only intentional malformed-input outcomes 
> such as {{Thrift::ProtocolException}} and {{EOFError}}, not 
> integer-conversion errors selected by message text. Native and pure-Ruby 
> readers should apply consistent container-size semantics, and oversized or 
> truncated input should produce a Thrift protocol/data exception or 
> {{EOFError}} rather than an implementation-specific {{RangeError}}.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to