Jens Geyer created THRIFT-6365:
----------------------------------

             Summary: Lua: add a container-size limit to the protocols
                 Key: THRIFT-6365
                 URL: https://issues.apache.org/jira/browse/THRIFT-6365
             Project: Thrift
          Issue Type: Sub-task
          Components: Lua - Library
            Reporter: Jens Geyer


Sub-task of THRIFT-6291. The Lua library has no limit on the number of elements 
a list, set or map may declare. {{readListBegin}}, {{readSetBegin}} and 
{{readMapBegin}} of the binary, compact and JSON protocols refuse only a 
negative size, and the generated code then reads one element per declared 
element.

Unlike the bindings in the THRIFT-6291 table, Lua has no MaxMessageSize either, 
so nothing else bounds the declared count. That is why the limit gets a finite 
default here, not the "no limit of its own" default the specification gives 
MaxContainerSize.

h2. Suggested

* Add {{maxContainerSize}} to the protocol object, next to {{maxStringSize}}, 
and {{DEFAULT_MAX_CONTAINER_SIZE = 16384000}} to {{TProtocol.lua}}, the value 
of the string and frame size limits. A value less than or equal to zero 
switches the limit off, as THRIFT-6291 settles.
* Add {{TProtocolBase:checkContainerSize(size)}}. Call it in {{readListBegin}}, 
{{readSetBegin}} and {{readMapBegin}} of {{TBinaryProtocol}}, 
{{TCompactProtocol}} and {{TJSONProtocol}}, after the negative-size check and 
before any element is read. It raises {{TProtocolException}} with 
{{SIZE_LIMIT}}.
* Every element takes at least one byte on the wire, so the default does not 
refuse any message that fits into one frame of the default size. A container of 
more than 16384000 elements, which only an unframed transport can carry, needs 
{{maxContainerSize}} raised.
* Record the finite default and the reason in 
{{doc/specs/thrift-tconfiguration.md}}.

h2. Test

Write a complete and well-formed container of {{limit + 1}} single-byte 
elements. The unfixed code must be seen to read it; the fixed code answers 
{{SIZE_LIMIT}} after reading only the container header. Cover binary, compact 
and JSON, each for list, set and map, at {{limit}} and {{limit + 1}}, plus the 
default, the off value and {{skip}}.

Reported by Sylwester Lachiewicz.

_Drafted with AI assistance (Claude Opus 5.5)._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to