Jens-G opened a new pull request, #3951:
URL: https://github.com/apache/thrift/pull/3951

   [THRIFT-6367](https://issues.apache.org/jira/browse/THRIFT-6367)
   
   `thrift_binary_protocol` and `thrift_compact_protocol` turn a message name 
into a list with `binary_to_list` before `thrift_processor` looks it up. The 
name could be as long as the rest of the message allows (`max_message_size`, 
100 MB by default, THRIFT-6366). A name the processor can dispatch is much 
shorter: the function name is an atom of at most 255 characters, after a 
service name and a `:` for a multiplexed service.
   
   **Change**
   - Both protocols now read the name's declared length first and refuse a name 
longer than `?MAX_MESSAGE_NAME_SIZE` (4096 bytes, `thrift_constants.hrl`) 
before reading it, with `{error, {message_name_exceeds_maximum, 4096}}`.
   - `message_begin` returns that error, and the server closes the connection.
   - A small `read_name/2` in each protocol does the check. The binary 
protocol's negative-length check for the name is unchanged.
   
   **Tests:** `name_length_test_` in 
`lib/erl/test/test_thrift_max_message_size.erl` covers binary (with and without 
the version header) and compact.
   - A name of exactly 4096 bytes is read.
   - A name one byte longer is refused by `message_begin` after at most the 8 
header bytes.
   
   On the base commit the three cases fail; with the change the full suite (455 
tests) passes on OTP 25 (rebar3 3.18), 27 and 28. `rebar3 fmt -c` passes on the 
changed files except `thrift_binary_protocol.erl`, which already fails it on 
master with older `if` one-liners. Those lines are left as they are.
   
   - [x] Did you create an [Apache 
Jira](https://issues.apache.org/jira/projects/THRIFT/issues/) ticket? 
THRIFT-6367
   - [x] If a ticket exists: Does your pull request title follow the pattern 
"THRIFT-NNNN: describe my issue"?
   - [x] Did you squash your changes to a single commit?
   - [x] Did you do your best to avoid breaking changes? If one was needed, did 
you label the Jira ticket with "Breaking-Change"? Not needed: a name over 4096 
bytes could not be dispatched anyway.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to