fix: enforce max alloc in delta deserialization
CI / lint (pull_request) Successful in 11s
CI / sanitizers (address) (pull_request) Successful in 38s
CI / sanitizers (undefined) (pull_request) Successful in 37s
CI / fuzz-build (pull_request) Successful in 15s
CI / coverage (pull_request) Successful in 32s
CI / build-and-test (pull_request) Successful in 1m15s
CI / valgrind (pull_request) Successful in 33s
CI / lint (pull_request) Successful in 11s
CI / sanitizers (address) (pull_request) Successful in 38s
CI / sanitizers (undefined) (pull_request) Successful in 37s
CI / fuzz-build (pull_request) Successful in 15s
CI / coverage (pull_request) Successful in 32s
CI / build-and-test (pull_request) Successful in 1m15s
CI / valgrind (pull_request) Successful in 33s
This commit is contained in:
+1
-1
@@ -396,7 +396,7 @@ Delta* delta_deserialize(const Data* data) {
|
|||||||
const uint8_t* buf = (const uint8_t*)data->data;
|
const uint8_t* buf = (const uint8_t*)data->data;
|
||||||
size_t pos = 0;
|
size_t pos = 0;
|
||||||
|
|
||||||
Delta* delta = malloc(sizeof(Delta));
|
Delta* delta = protocol_alloc(sizeof(Delta));
|
||||||
if (!delta)
|
if (!delta)
|
||||||
return NULL;
|
return NULL;
|
||||||
|
|
||||||
|
|||||||
@@ -109,6 +109,20 @@ static void test_delta_deserialize_garbage() {
|
|||||||
data_destroy(d);
|
data_destroy(d);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static void test_delta_deserialize_respects_max_alloc() {
|
||||||
|
unsigned char serialized[sizeof(uint64_t) + sizeof(uint32_t)] = {0};
|
||||||
|
Data data = {.data = serialized, .size = sizeof(serialized)};
|
||||||
|
ProtocolSession session;
|
||||||
|
protocol_session_init(&session, -1, -1);
|
||||||
|
protocol_session_set_max_alloc(&session, sizeof(Delta) - 1);
|
||||||
|
protocol_session_bind(&session);
|
||||||
|
|
||||||
|
const Delta* result = delta_deserialize(&data);
|
||||||
|
EXPECT_NULL(result);
|
||||||
|
|
||||||
|
protocol_session_unbind();
|
||||||
|
}
|
||||||
|
|
||||||
static void test_delta_signature_deserialize_truncated() {
|
static void test_delta_signature_deserialize_truncated() {
|
||||||
char old_data[4096];
|
char old_data[4096];
|
||||||
for (int i = 0; i < 4096; i++)
|
for (int i = 0; i < 4096; i++)
|
||||||
@@ -206,6 +220,7 @@ void test_robustness() {
|
|||||||
test_delta_deserialize_truncated();
|
test_delta_deserialize_truncated();
|
||||||
test_delta_deserialize_empty();
|
test_delta_deserialize_empty();
|
||||||
test_delta_deserialize_garbage();
|
test_delta_deserialize_garbage();
|
||||||
|
test_delta_deserialize_respects_max_alloc();
|
||||||
test_delta_deserialize_truncated_instructions();
|
test_delta_deserialize_truncated_instructions();
|
||||||
test_delta_signature_deserialize_truncated();
|
test_delta_signature_deserialize_truncated();
|
||||||
test_delta_apply_null();
|
test_delta_apply_null();
|
||||||
|
|||||||
Reference in New Issue
Block a user