Respect padded base64 output buffer capacity - #205
Open
rupayon123 wants to merge 2 commits into
Open
rupayon123 wants to merge 2 commits into
rupayon123 wants to merge 2 commits into
Conversation
|
|
|
Memory usage change @ 55f1471
Click for full report table
Click for full report CSV |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The base64 encoder checks
(inputLength * 8) / 6bytes of output space, but a final partial group still writes four bytes with padding. A one-byte input can therefore write four output bytes when the caller supplied capacity one.Calculate the complete padded length before writing and return that length unchanged for insufficient capacity. Reject negative input lengths and lengths whose encoded result cannot fit the int return type. Document that output is not NUL-terminated.
A standalone host regression covers the standard empty-through-six-byte vectors, every undersized capacity for those vectors, output canaries, negative lengths and INT_MAX. It fails before the fix and passes afterward with Clang C++11,
-Wall -Wextra -Werror, AddressSanitizer and UndefinedBehaviorSanitizer. The production HTTP authentication path already supplies five-byte scratch space; this patch protects the encoding helper's stated capacity argument and does not claim a demonstrated network exploit.Prepared with AI assistance; the bounds calculation, callers and regression results were checked.