Skip to content

Reject a truncated iNES header instead of parsing past its end - #3607

Open
arpitjain099 wants to merge 1 commit into
trailofbits:masterfrom
arpitjain099:fix/truncated-ines-header
Open

arpitjain099 wants to merge 1 commit into
trailofbits:masterfrom
arpitjain099:fix/truncated-ines-header

Conversation

@arpitjain099

Copy link
Copy Markdown

parse_ines_header checks the magic and then reads header[4] through header[10] and slices header[11:], but parse_ines gets the header from file_stream.read(16), which returns short on a truncated file. Only the magic is validated, so a 4 byte file gets through.

On a ROM cut to 4 bytes, polyfile --format json logs Parser parse_ines ... raised an exception while parsing: index out of range, exits 0, and still emits an iNESHeader element with "size": 16 for a 4 byte file, with everything after the magic missing. A consumer of that JSON sees a partial structure and a length that cannot be right.

Lengths 11 to 15 are worse in a way, since nothing raises at all: header[11:] just returns short, so the output carries a 16 byte iNESHeader and an undersized UnusedPadding with no warning anywhere.

Raising InvalidMatch matches how the bad-magic case is already handled, and the dispatcher treats it as a clean non-match rather than an internal error. A well-formed ROM is unaffected, and I confirmed the full structure still comes out for one.

The new tests cover lengths 4 to 15; all twelve fail on master. tests/unit is 81 passing.

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Arpit Jain <arpitjain099@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant