[
https://issues.apache.org/jira/browse/THRIFT-6367?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jens Geyer resolved THRIFT-6367.
--------------------------------
Fix Version/s: 0.25.0
Assignee: Jens Geyer
Resolution: Fixed
> Erlang: cap the message name length in the binary and compact protocols
> -----------------------------------------------------------------------
>
> Key: THRIFT-6367
> URL: https://issues.apache.org/jira/browse/THRIFT-6367
> Project: Thrift
> Issue Type: Bug
> Components: Erlang - Library
> Reporter: Jens Geyer
> Assignee: Jens Geyer
> Priority: Minor
> Fix For: 0.25.0
>
> Time Spent: 20m
> Remaining Estimate: 0h
>
> {{thrift_binary_protocol}} and {{thrift_compact_protocol}} turn a message
> name into a list with {{binary_to_list}} before {{thrift_processor}} looks it
> up. The name may be as long as the rest of the message allows
> ({{max_message_size}}, 100 MB by default, THRIFT-6366). A name the processor
> can dispatch is much shorter: the function name is an atom of at most 255
> characters, after a service name and a ':' for a multiplexed service.
> h2. Change
> * Both protocols read the declared length of the name first. A name longer
> than {{?MAX_MESSAGE_NAME_SIZE}} (4096 bytes, {{thrift_constants.hrl}}) is
> refused before it is read.
> * The refusal is {{\{error, \{message_name_exceeds_maximum, 4096\}\}}}.
> {{message_begin}} returns it, and the server closes that connection.
> _Drafted with AI assistance (Claude Opus 5.5)._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)