[ 
https://issues.apache.org/jira/browse/THRIFT-6137?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Dmytro Shteflyuk resolved THRIFT-6137.
--------------------------------------
    Fix Version/s: 0.25.0
       Resolution: Fixed

> Ruby HeaderTransport should reject incomplete framed protocol headers
> ---------------------------------------------------------------------
>
>                 Key: THRIFT-6137
>                 URL: https://issues.apache.org/jira/browse/THRIFT-6137
>             Project: Thrift
>          Issue Type: Bug
>          Components: Ruby - Library
>            Reporter: Dmytro Shteflyuk
>            Assignee: Dmytro Shteflyuk
>            Priority: Major
>             Fix For: 0.25.0
>
>          Time Spent: 50m
>  Remaining Estimate: 0h
>
> h3. Problem
> Ruby HeaderTransport identifies framed Binary, Compact, and Header clients 
> from a four-byte protocol signature at the start of each declared frame 
> payload. A frame whose declared payload size is less than four bytes cannot 
> contain that signature, but the parser currently proceeds into fixed-width 
> decoding.
> A zero-length frame consequently reaches an internal unpack operation with no 
> data and raises a raw Ruby exception. A frame that ends before its declared 
> payload is complete can likewise expose the underlying EOF exception instead 
> of reporting a typed Thrift transport failure.
> h3. Client impact
> Applications using HeaderProtocol can receive NoMethodError or EOFError from 
> malformed or desynchronized input instead of Thrift::TransportException. 
> These implementation exceptions can bypass normal connection-level protocol 
> and transport error handling; the resulting behavior depends on the selected 
> server or client execution model.
> Conforming frames are unaffected.
> h3. Reproduction
> {code:ruby}
> require "thrift"
> {
>   "zero-length frame" => [0].pack("N"),
>   "truncated four-byte signature" => [4].pack("N") + "\x80\x01\x00".b
> }.each do |label, bytes|
>   transport = Thrift::HeaderTransport.new(
>     Thrift::MemoryBufferTransport.new(bytes)
>   )
>   begin
>     transport.read(1)
>   rescue Exception => error
>     puts "#{label}: #{error.class}: #{error.message}"
>   end
> end
> {code}
> Testing on master commit {{e4473c9e296b79003ca04128612e7b6a846a6552}} 
> produces:
> {noformat}
> zero-length frame: NoMethodError: undefined method 'unpack' for nil
> truncated four-byte signature: EOFError: Not enough bytes remain in memory 
> buffer
> {noformat}
> h3. Expected behavior
> HeaderTransport should reject declared frame payload sizes below the 
> four-byte protocol-signature minimum before attempting fixed-width decoding. 
> Complete but undersized frames should raise a typed 
> Thrift::TransportException describing the malformed size, while an incomplete 
> frame-size prefix or prematurely ended declared payload should raise 
> Thrift::TransportException with the END_OF_FILE type.
> A four-byte framed protocol signature and all larger valid frames should 
> continue to be accepted normally.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to