Jens Geyer created THRIFT-6367:
----------------------------------

             Summary: Erlang: cap the message name length in the binary and 
compact protocols
                 Key: THRIFT-6367
                 URL: https://issues.apache.org/jira/browse/THRIFT-6367
             Project: Thrift
          Issue Type: Bug
          Components: Erlang - Library
            Reporter: Jens Geyer


{{thrift_binary_protocol}} and {{thrift_compact_protocol}} turn a message name 
into a list with {{binary_to_list}} before {{thrift_processor}} looks it up. 
The name may be as long as the rest of the message allows 
({{max_message_size}}, 100 MB by default, THRIFT-6366). A name the processor 
can dispatch is much shorter: the function name is an atom of at most 255 
characters, after a service name and a ':' for a multiplexed service.

h2. Change

* Both protocols read the declared length of the name first. A name longer than 
{{?MAX_MESSAGE_NAME_SIZE}} (4096 bytes, {{thrift_constants.hrl}}) is refused 
before it is read.
* The refusal is {{\{error, \{message_name_exceeds_maximum, 4096\}\}}}. 
{{message_begin}} returns it, and the server closes that connection.

_Drafted with AI assistance (Claude Opus 5.5)._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to