forked from denisenkom/go-mssqldb
-
Notifications
You must be signed in to change notification settings - Fork 106
fix: bound TDS response parser allocations against malformed streams #421
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
Saurabh Singh (saurabh500)
wants to merge
64
commits into
main
from
saurabh500-bound-tds-response-allocations
+1,564
−94
Open
Changes from all commits
Commits
Show all changes
64 commits
Select commit
Hold shift + click to select a range
3dc3f4b
test: add TDS response fuzz harness and end-to-end target
8a474c6
fix: bound TDS response allocations to prevent OOM from malformed str…
062a009
test: remove ineffectual assignment in bufFromBytes helper
bea21c1
test: address review feedback on TDS fuzz harness
153bd96
fix: panic StreamError for bounded TDS allocation guards
a2b636e
Merge remote-tracking branch 'origin/saurabh500-fuzz-tds-response-har…
8ccfd10
fix: bound sql_variant length to 8 KB instead of the LOB ceiling
a34ab7a
Merge remote-tracking branch 'origin/main' into saurabh500-fuzz-tds-r…
abb9475
test: assert malformed seeds error and valid seeds parse cleanly
6f66037
test: frame TDS fuzz packets by payload size for arbitrary seams
520380d
Merge remote-tracking branch 'origin/main' into saurabh500-fuzz-tds-r…
7484a27
Merge remote-tracking branch 'origin/saurabh500-fuzz-tds-response-har…
d559b62
fix: clarify TEXT/NTEXT/IMAGE invalid-length error message
a3e1f83
test: compare parsed token values across packet boundaries
ff9fd02
test: compare decoded ERROR contents across packet boundaries
18e8c32
fix: fail malformed FEDAUTHINFO/typeid streams as StreamError, guard …
320dbc2
test: correct trailing-bytes seed's documented intent
fc28416
Merge remote-tracking branch 'origin/saurabh500-fuzz-tds-response-har…
a2cb70c
test: harden alloc regression helpers per review feedback
199d3fb
test: verify INFO/ERROR message values across packet boundaries
dfee301
fix: say 'token' not 'packet' in FEDAUTHINFO stream errors; correct t…
6ce1f09
test: drain return-message queue concurrently to avoid harness hang
ff1bd98
fix: report FEDAUTHINFO opt offset and length separately in stream error
fd5f0a8
test: drop trailing-bytes seed from the valid boundary corpus
d7e2253
fix: stream TEXT/NTEXT/IMAGE reads to avoid preallocating from length…
6817aef
test: seed non-zero ERROR/INFO fields and non-empty browse tokens
e39b471
test: make TABNAME seed a spec-faithful TDS 7.2 name
70274e4
test: add non-final DONE + trailing garbage malformed seed
5932862
test: strengthen valid seeds with non-zero DONE/RETURNSTATUS and real…
26e16f2
Merge remote-tracking branch 'origin/main' into saurabh500-fuzz-tds-r…
79c012b
ci: retrigger AppVeyor after account-level build cancellation
e3164a6
Merge remote-tracking branch 'origin/saurabh500-fuzz-tds-response-har…
a56568b
Merge remote-tracking branch 'origin/main' into saurabh500-fuzz-tds-r…
1886f5a
Merge remote-tracking branch 'origin/saurabh500-fuzz-tds-response-har…
2bc5c60
Merge remote-tracking branch 'origin/main' into saurabh500-fuzz-tds-r…
326d4a8
test: widen fuzz fragmentation arg to uint16 for full seam coverage
95a2a46
Merge remote-tracking branch 'origin/saurabh500-fuzz-tds-response-har…
d2b7237
fix: bound COLMETADATA column count to prevent OOM from malformed str…
a8d58be
docs: explain why the COLMETADATA and FEDAUTHINFO allocation caps are…
ca438b0
Merge remote-tracking branch 'origin/main' into saurabh500-bound-tds-…
3b04116
refactor: grow COLMETADATA columns incrementally instead of capping c…
cf0ee5d
Merge remote-tracking branch 'origin/main' into saurabh500-bound-tds-…
cfa1c87
Merge remote-tracking branch 'origin/main' into saurabh500-bound-tds-…
82a076c
docs: clarify COLMETADATA growth and sql_variant bound comments
8223999
Merge remote-tracking branch 'origin/main' into saurabh500-bound-tds-…
977eae3
test: measure allocation in COLMETADATA bogus-count regression test
5ad6a3f
test: loosen COLMETADATA alloc ceiling to avoid parallel-test flakiness
8640697
test: cover FEDAUTHINFO dataOffset+dataLength uint32 overflow guard
0194132
Merge remote-tracking branch 'origin/main' into saurabh500-bound-tds-…
7b20dcc
Merge remote-tracking branch 'origin/main' into saurabh500-bound-tds-…
d0f5dec
fix: bound CEK table allocations and validate key value counts
30488dc
fix: defer value buffers and bound cumulative PLP payloads
b8067c0
chore: merge main with CI password generation fix
0f46c75
chore: merge main query-response draining fix
3d421ef
chore: merge main response-cleanup revert
42b08b2
chore: merge main v1.11.1 release update
22e913d
fix: validate sql_variant widths before reading values
2e0b392
refactor: use tagged switches for variant widths
c1af349
fix: reject odd Unicode variant lengths as stream errors
ca7e443
chore: merge main boolean connection option update
8b202f0
chore: merge main v1.11.2 release update
9afac4e
chore: merge main authentication connection aliases
bfee5b4
chore: merge main review compatibility guidance
70125bc
chore: merge main Codecov action update
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.