[
https://issues.apache.org/jira/browse/THRIFT-6137?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dmytro Shteflyuk resolved THRIFT-6137.
--------------------------------------
Fix Version/s: 0.25.0
Resolution: Fixed
> Ruby HeaderTransport should reject incomplete framed protocol headers
> ---------------------------------------------------------------------
>
> Key: THRIFT-6137
> URL: https://issues.apache.org/jira/browse/THRIFT-6137
> Project: Thrift
> Issue Type: Bug
> Components: Ruby - Library
> Reporter: Dmytro Shteflyuk
> Assignee: Dmytro Shteflyuk
> Priority: Major
> Fix For: 0.25.0
>
> Time Spent: 50m
> Remaining Estimate: 0h
>
> h3. Problem
> Ruby HeaderTransport identifies framed Binary, Compact, and Header clients
> from a four-byte protocol signature at the start of each declared frame
> payload. A frame whose declared payload size is less than four bytes cannot
> contain that signature, but the parser currently proceeds into fixed-width
> decoding.
> A zero-length frame consequently reaches an internal unpack operation with no
> data and raises a raw Ruby exception. A frame that ends before its declared
> payload is complete can likewise expose the underlying EOF exception instead
> of reporting a typed Thrift transport failure.
> h3. Client impact
> Applications using HeaderProtocol can receive NoMethodError or EOFError from
> malformed or desynchronized input instead of Thrift::TransportException.
> These implementation exceptions can bypass normal connection-level protocol
> and transport error handling; the resulting behavior depends on the selected
> server or client execution model.
> Conforming frames are unaffected.
> h3. Reproduction
> {code:ruby}
> require "thrift"
> {
> "zero-length frame" => [0].pack("N"),
> "truncated four-byte signature" => [4].pack("N") + "\x80\x01\x00".b
> }.each do |label, bytes|
> transport = Thrift::HeaderTransport.new(
> Thrift::MemoryBufferTransport.new(bytes)
> )
> begin
> transport.read(1)
> rescue Exception => error
> puts "#{label}: #{error.class}: #{error.message}"
> end
> end
> {code}
> Testing on master commit {{e4473c9e296b79003ca04128612e7b6a846a6552}}
> produces:
> {noformat}
> zero-length frame: NoMethodError: undefined method 'unpack' for nil
> truncated four-byte signature: EOFError: Not enough bytes remain in memory
> buffer
> {noformat}
> h3. Expected behavior
> HeaderTransport should reject declared frame payload sizes below the
> four-byte protocol-signature minimum before attempting fixed-width decoding.
> Complete but undersized frames should raise a typed
> Thrift::TransportException describing the malformed size, while an incomplete
> frame-size prefix or prematurely ended declared payload should raise
> Thrift::TransportException with the END_OF_FILE type.
> A four-byte framed protocol signature and all larger valid frames should
> continue to be accepted normally.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)