-
Notifications
You must be signed in to change notification settings - Fork 2.3k
fix(buffers): add nesting depth limit to prevent protobuf decode corruption #25417
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
ganelo
wants to merge
51
commits into
vectordotdev:master
from
ganelo:og/continue-protobuf-nesting-depth-limit
Closed
Changes from 43 commits
Commits
Show all changes
51 commits
Select commit
Hold shift + click to select a range
f469b3f
fix(buffers): add nesting depth limit to prevent protobuf decode corr…
connoryy b05d98a
fix: also check event metadata value for nesting depth
connoryy 87d25cd
docs: replace approximate nesting formula with verified exact derivation
connoryy eff1c70
fix: lower MAX_NESTING_DEPTH from 33 to 32 to cover all proto paths
connoryy 59de3d4
test: add EventWrapper path boundary test for vector sink gRPC
connoryy da1e2eb
docs: simplify MAX_NESTING_DEPTH comment to state only verified facts
connoryy fbd398c
docs: remove proto field names from MAX_NESTING_DEPTH comment
connoryy 2191d9b
docs: simplify test comments to remove proto-specific terminology
connoryy 5046ec5
make error slightly more informative
connoryy 390c30b
move imports
connoryy 3eb9fb4
add test
connoryy 39a9924
fix conditional to new function signature
connoryy d835bc8
style: auto-fix lint/format errors
connoryy 220be47
Merge branch 'master' into connor/protobuf-nesting-depth-limit
connoryy 573dafb
fix metrics case and test failure
connoryy 4d53caf
Merge branch 'connor/protobuf-nesting-depth-limit' of github.com:conn…
connoryy 7936f12
Merge branch 'master' into connor/protobuf-nesting-depth-limit
connoryy 6ff03c5
Add roundtrip tests for depth-32 metadata via prost
connoryy 13bc237
Replace individual nesting tests with exhaustive path coverage
connoryy 79e46b8
Simplify nesting tests: saturate all Value fields instead of enumerat…
connoryy 6800e85
style: auto-fix lint/format errors
connoryy 9ea18cd
Fix clippy doc_markdown lints in nesting depth tests
connoryy 30e6a86
Merge branch 'connor/protobuf-nesting-depth-limit' of github.com:conn…
connoryy 7b42478
Add tests proving metadata_full is the tightest path
connoryy bf5119c
style: auto-fix lint/format errors
connoryy 5ebc616
Test full boundaries for loosest and tightest encoding paths
connoryy 1021e1e
style: auto-fix lint/format errors
connoryy fbd2ad2
Add Trace to flat events test for uniformity
connoryy 8c81391
Use per-path depth limits: 33 for event data, 32 for metadata
connoryy f0fc05a
style: auto-fix lint/format errors
connoryy ef06620
Fix clippy doc_markdown lint
connoryy 2a58740
Fix doc comment arithmetic and add native codec metadata tests
connoryy 5f87a9f
Merge branch 'master' into og/continue-protobuf-nesting-depth-limit
oganel 87038f5
Fix compile
oganel 57c9c91
fix(buffers): drop oversized events gracefully on disk-buffer write
oganel 9d44c36
fix(buffers): account for array vs object cost in nesting check
oganel 2447fda
Merge branch 'master' into og/continue-protobuf-nesting-depth-limit
ganelo 4993bb5
fix(buffers): charge Value::Timestamp for one nesting frame
oganel b5d2e9d
Merge branch 'master' into og/continue-protobuf-nesting-depth-limit
pront 0b639d4
Update changelog.d/protobuf_nesting_depth_limit.fix.md
ganelo eec68b2
refactor(buffers): move pre-encode filtering to Bufferable::filter_un…
oganel 3598122
fix(buffers): account for filter drops in buffer usage instrumentation
oganel 860f40a
fix(console sink): keep per-event encoder failures from terminating t…
oganel f28b2a3
fix(buffers): skip filter_unencodable when disk is already full
oganel 8a22d86
fix(codecs): silent-drop over-budget events from the native encoder
oganel 95ba0d0
test(vector sink): pin PushEventsRequest decode boundary at the same …
oganel 806371d
fix(buffers): report disk-v2 filter drops via the ledger's usage handle
oganel 13999c5
fix(sinks): finalize socket-sink encoder drops with explicit status
oganel e90dd47
fix(codecs): preserve framing for legitimate empty payloads
oganel b172e6c
refactor(codecs): drop native-encoder nesting guard, scope fix to dec…
oganel f57988f
docs(buffers): document over-budget overflow-routing limitation in tr…
oganel File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,3 @@ | ||
| Fixed unrecoverable disk buffer corruption and vector-to-vector retry loops caused by event data or metadata that protobuf could encode but prost could not decode. Vector now rejects only protobuf-unsafe nested payloads before disk buffer, native codec, or `vector` sink gRPC encoding, while preserving nested shapes that prost can safely decode. | ||
|
|
||
| authors: connoryy |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.