[ 
https://issues.apache.org/jira/browse/THRIFT-6367?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jens Geyer resolved THRIFT-6367.
--------------------------------
    Fix Version/s: 0.25.0
         Assignee: Jens Geyer
       Resolution: Fixed

> Erlang: cap the message name length in the binary and compact protocols
> -----------------------------------------------------------------------
>
>                 Key: THRIFT-6367
>                 URL: https://issues.apache.org/jira/browse/THRIFT-6367
>             Project: Thrift
>          Issue Type: Bug
>          Components: Erlang - Library
>            Reporter: Jens Geyer
>            Assignee: Jens Geyer
>            Priority: Minor
>             Fix For: 0.25.0
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> {{thrift_binary_protocol}} and {{thrift_compact_protocol}} turn a message 
> name into a list with {{binary_to_list}} before {{thrift_processor}} looks it 
> up. The name may be as long as the rest of the message allows 
> ({{max_message_size}}, 100 MB by default, THRIFT-6366). A name the processor 
> can dispatch is much shorter: the function name is an atom of at most 255 
> characters, after a service name and a ':' for a multiplexed service.
> h2. Change
> * Both protocols read the declared length of the name first. A name longer 
> than {{?MAX_MESSAGE_NAME_SIZE}} (4096 bytes, {{thrift_constants.hrl}}) is 
> refused before it is read.
> * The refusal is {{\{error, \{message_name_exceeds_maximum, 4096\}\}}}. 
> {{message_begin}} returns it, and the server closes that connection.
> _Drafted with AI assistance (Claude Opus 5.5)._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to