mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-08-29 07:27:16 +00:00
test: reject truncated and oversized sticker wire refs
Addresses review feedback on #1544: pin that wire refs cut at field boundaries or mid-hash, and refs with 64KiB oversized fields, all parse to nil so a bad packet cannot inflate the decoder.
This commit is contained in:
parent
8eeb9cce99
commit
cc63c0c9a7
@ -128,6 +128,28 @@ struct StickerRefCodecTests {
|
||||
#expect(StickerRefCodec.parse("\u{1F}sticker\u{1F}30031:\(pubkey):pack\u{1F}\u{1F}\(sha256)") == nil) // empty shortcode field
|
||||
}
|
||||
|
||||
// MARK: - Truncated / oversized wire input
|
||||
|
||||
@Test func rejectsTruncatedAndOversizedWireRefs() {
|
||||
let wire = "\u{1F}sticker\u{1F}30031:\(pubkey):pack\u{1F}wave\u{1F}\(sha256)"
|
||||
|
||||
// Truncated at a field boundary, mid-hash, and mid-tag: a cut
|
||||
// packet must never parse as a valid ref.
|
||||
for cut in [wire.count - 1, wire.count - 32, wire.count / 2, 9, 1] {
|
||||
#expect(StickerRefCodec.parse(String(wire.prefix(cut))) == nil)
|
||||
}
|
||||
// Valid framing with a hash truncated to 63 chars.
|
||||
#expect(StickerRefCodec.parse("\u{1F}sticker\u{1F}30031:\(pubkey):pack\u{1F}wave\u{1F}\(String(sha256.dropLast()))") == nil)
|
||||
|
||||
// Oversized fields (64KiB) must be rejected by the length guards
|
||||
// before any field is trusted, so a bad packet cannot make the
|
||||
// decoder retain an inflated buffer.
|
||||
let huge = String(repeating: "a", count: 65_536)
|
||||
#expect(StickerRefCodec.parse("\u{1F}sticker\u{1F}30031:\(pubkey):\(huge)\u{1F}wave\u{1F}\(sha256)") == nil)
|
||||
#expect(StickerRefCodec.parse("\u{1F}sticker\u{1F}30031:\(pubkey):pack\u{1F}\(huge)\u{1F}\(sha256)") == nil)
|
||||
#expect(StickerRefCodec.parse("\u{1F}sticker\u{1F}30031:\(pubkey):pack\u{1F}wave\u{1F}\(huge)") == nil)
|
||||
}
|
||||
|
||||
// MARK: - Never-crash fuzz-ish
|
||||
|
||||
@Test func pathologicalInputsNeverCrashAndNeverParse() {
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user