Summary
prost_build::compile_fds has the signature fn(FileDescriptorSet) -> std::io::Result<()>, but it can panic when the supplied FileDescriptorSet is structurally malformed.
On current master / prost-build 0.14.3, Config::compile_fds forwards the caller-provided FileDescriptorSet into self.generate(requests)?, and generate() immediately builds a MessageGraph. MessageGraph::add_message() then unconditionally unwraps descriptor fields that may be absent in malformed descriptor data:
msg.name.as_ref().unwrap()
field.type_name.clone().unwrap() for message-typed, non-repeated fields
That means malformed descriptor contents cause a panic before compile_fds can return an Err.
Reproduction
use prost_types::{DescriptorProto, FileDescriptorProto, FileDescriptorSet};
fn main() {
let out = std::env::temp_dir().join("prost_build_compile_fds_panic");
std::fs::create_dir_all(&out).unwrap();
std::env::set_var("OUT_DIR", &out);
let fds = FileDescriptorSet {
file: vec![FileDescriptorProto {
name: Some("broken.proto".into()),
message_type: vec![DescriptorProto::default()],
..Default::default()
}],
};
let res = std::panic::catch_unwind(|| prost_build::compile_fds(fds));
println!("{res:?}");
}
With prost-build = "0.14.3", this panics in prost-build/src/message_graph.rs because the top-level message has no name:
thread 'main' panicked at .../prost-build/src/message_graph.rs:57:68:
called `Option::unwrap()` on a `None` value
Impacts
This is a panic-on-invalid-input bug, even if most real-world callers only pass valid protoc output.
Summary
prost_build::compile_fdshas the signaturefn(FileDescriptorSet) -> std::io::Result<()>, but it can panic when the suppliedFileDescriptorSetis structurally malformed.On current
master/prost-build0.14.3,Config::compile_fdsforwards the caller-providedFileDescriptorSetintoself.generate(requests)?, andgenerate()immediately builds aMessageGraph.MessageGraph::add_message()then unconditionally unwraps descriptor fields that may be absent in malformed descriptor data:msg.name.as_ref().unwrap()field.type_name.clone().unwrap()for message-typed, non-repeated fieldsThat means malformed descriptor contents cause a panic before
compile_fdscan return anErr.Reproduction
With
prost-build = "0.14.3", this panics inprost-build/src/message_graph.rsbecause the top-level message has noname:Impacts
This is a panic-on-invalid-input bug, even if most real-world callers only pass valid
protocoutput.