]> git.ipfire.org Git - thirdparty/kea.git/commitdiff
[1452] impose upper limit on the data length for SocketSessionForwarder::push,
authorJINMEI Tatuya <jinmei@isc.org>
Tue, 13 Dec 2011 23:06:29 +0000 (15:06 -0800)
committerJINMEI Tatuya <jinmei@isc.org>
Tue, 13 Dec 2011 23:06:29 +0000 (15:06 -0800)
too.

src/lib/util/io/socketsession.cc
src/lib/util/tests/socketsession_unittest.cc

index af871c750ed1cb695f31e98fb623a6872205858a..8dbdf78e1556b89b4d6580dd18f274bc32472404 100644 (file)
@@ -179,6 +179,10 @@ SocketSessionForwarder::push(int sock, int family, int sock_type, int protocol,
         isc_throw(SocketSessionError,
                   "Data for a socket session must not be empty");
     }
+    if (data_len > MAX_DATASIZE) {
+        isc_throw(SocketSessionError, "Invalid socket session data size: " <<
+                  data_len << ", must not exceed " << MAX_DATASIZE);
+    }
 
     if (send_fd(impl_->fd_, sock) != 0) {
         isc_throw(SocketSessionError, "FD passing failed: " <<
@@ -198,8 +202,10 @@ SocketSessionForwarder::push(int sock, int family, int sock_type, int protocol,
     // Remote endpoint
     impl_->buf_.writeUint32(static_cast<uint32_t>(getSALength(remote_end)));
     impl_->buf_.writeData(&remote_end, getSALength(remote_end));
-    // Data length
-    impl_->buf_.writeUint32(static_cast<uint32_t>(data_len));
+    // Data length.  Must be fit uint32 due to the range check above.
+    const uint32_t data_len32 = static_cast<uint32_t>(data_len);
+    assert(data_len == data_len32); // shouldn't cause overflow.
+    impl_->buf_.writeUint32(data_len32);
     // Write the resulting header length at the beginning of the buffer
     impl_->buf_.writeUint16At(impl_->buf_.getLength() - sizeof(uint16_t), 0);
 
index e5380bf0a00672550cd3d1968825feda8c81ed62..717b0cdd223038dbf31b068d4649b01b9bf808b3 100644 (file)
@@ -626,6 +626,13 @@ TEST_F(ForwarderTest, badPush) {
                                  NULL, sizeof(TEST_DATA)),
                  SocketSessionError);
 
+    // Too big data: we reject them at least for now
+    EXPECT_THROW(forwarder_.push(1, AF_INET, SOCK_DGRAM, IPPROTO_UDP,
+                                 *getSockAddr("192.0.2.1", "53").first,
+                                 *getSockAddr("192.0.2.2", "53").first,
+                                 string(65536, 'd').c_str(), 65536),
+                 SocketSessionError);
+
     // Close the receptor before push.  It will result in SIGPIPE (should be
     // ignored) and EPIPE, which will be converted to SocketSessionError.
     const int receptor_fd = acceptForwarder();