From: Roman Khabibov <roman.habibov@tarantool.org> To: tarantool-patches@dev.tarantool.org Subject: [Tarantool-patches] [PATCH] serilaizer: check for recursive serialization Date: Fri, 10 Jul 2020 15:01:09 +0300 [thread overview] Message-ID: <20200710120109.91675-1-roman.habibov@tarantool.org> (raw) Add a limit to the number of calls to the __serialize function. Throw error in case of very deep (most likely endless) recursion. Closes #3228 --- Branch: https://github.com/tarantool/tarantool/tree/romanhabibov/gh-3228-serialize Issue: https://github.com/tarantool/tarantool/issues/3228 @ChangeLog - Fix bug with bus error when __serialize function generates infinite recursion. src/lua/utils.c | 8 ++++++++ ...-3228-serializer-look-for-recursion.result | 19 +++++++++++++++++++ ...228-serializer-look-for-recursion.test.lua | 8 ++++++++ 3 files changed, 35 insertions(+) create mode 100644 test/app/gh-3228-serializer-look-for-recursion.result create mode 100644 test/app/gh-3228-serializer-look-for-recursion.test.lua diff --git a/src/lua/utils.c b/src/lua/utils.c index 0b05d7257..7e55d43f1 100644 --- a/src/lua/utils.c +++ b/src/lua/utils.c @@ -50,6 +50,9 @@ static uint32_t CTID_CONST_CHAR_PTR; static uint32_t CTID_UUID; uint32_t CTID_DECIMAL; +enum { + SERIALIZER_CRITICAL_RECURSION_DEPTH = 256 +}; void * luaL_pushcdata(struct lua_State *L, uint32_t ctypeid) @@ -490,6 +493,11 @@ static int lua_field_try_serialize(struct lua_State *L, struct luaL_serializer *cfg, int idx, struct luaL_field *field) { + if (idx > SERIALIZER_CRITICAL_RECURSION_DEPTH) { + diag_set(LuajitError, LUAL_SERIALIZE " generates too deep " + "recursion"); + return -1; + } if (luaL_getmetafield(L, idx, LUAL_SERIALIZE) == 0) return 1; if (lua_isfunction(L, -1)) { diff --git a/test/app/gh-3228-serializer-look-for-recursion.result b/test/app/gh-3228-serializer-look-for-recursion.result new file mode 100644 index 000000000..f105bfae9 --- /dev/null +++ b/test/app/gh-3228-serializer-look-for-recursion.result @@ -0,0 +1,19 @@ +-- test-run result file version 2 +test_run = require('test_run').new() + | --- + | ... + +-- +-- gh-3228: Check the error message in the case of a __serialize +-- function generating infinite recursion. +-- +setmetatable({}, {__serialize = function(a) return a end}) + | --- + | - error: 'console: an exception occurred when formatting the output: __serialize generates + | too deep recursion' + | ... +setmetatable({}, {__serialize = function(a, b, c) return a, b, c end}) + | --- + | - error: 'console: an exception occurred when formatting the output: __serialize generates + | too deep recursion' + | ... diff --git a/test/app/gh-3228-serializer-look-for-recursion.test.lua b/test/app/gh-3228-serializer-look-for-recursion.test.lua new file mode 100644 index 000000000..d3c76ef0c --- /dev/null +++ b/test/app/gh-3228-serializer-look-for-recursion.test.lua @@ -0,0 +1,8 @@ +test_run = require('test_run').new() + +-- +-- gh-3228: Check the error message in the case of a __serialize +-- function generating infinite recursion. +-- +setmetatable({}, {__serialize = function(a) return a end}) +setmetatable({}, {__serialize = function(a, b, c) return a, b, c end}) -- 2.21.0 (Apple Git-122)
next reply other threads:[~2020-07-10 12:01 UTC|newest] Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top 2020-07-10 12:01 Roman Khabibov [this message] 2020-07-10 12:29 ` Cyrill Gorcunov 2020-07-14 9:45 ` Igor Munkin 2020-07-14 10:40 ` Cyrill Gorcunov 2020-09-14 14:43 ` Roman Khabibov 2020-09-14 16:06 ` Cyrill Gorcunov 2020-09-16 7:29 ` Igor Munkin 2020-09-30 21:49 ` Roman Khabibov 2020-10-01 14:40 ` Igor Munkin
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=20200710120109.91675-1-roman.habibov@tarantool.org \ --to=roman.habibov@tarantool.org \ --cc=tarantool-patches@dev.tarantool.org \ --subject='Re: [Tarantool-patches] [PATCH] serilaizer: check for recursive serialization' \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: link
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox