fix: bounds-check alloc pointer before copy_from_slice
Guest alloc could return a pointer where ptr+len exceeds linear memory size, causing a Rust panic that permanently poisoned the actor. Now validates ptr+len <= memory.len() before writing, dropping the message on OOB (consistent with other allocation failure handling). Authored by Claude, lovingly guided by Zachery Aaron Shores-Chmielewski
This commit is contained in:
parent
22f6860d6d
commit
dfc9e6a392
2 changed files with 6 additions and 4 deletions
|
|
@ -41,9 +41,12 @@ impl ActorInterface for WasmActor {
|
||||||
};
|
};
|
||||||
|
|
||||||
// 2. Write message bytes into guest memory
|
// 2. Write message bytes into guest memory
|
||||||
self.memory.data_mut(&mut self.store)
|
let mem = self.memory.data_mut(&mut self.store);
|
||||||
[ptr as usize..(ptr as usize + bytes.len())]
|
let end = (ptr as usize).saturating_add(bytes.len());
|
||||||
.copy_from_slice(bytes);
|
if end > mem.len() {
|
||||||
|
return; // alloc returned OOB pointer — drop message
|
||||||
|
}
|
||||||
|
mem[ptr as usize..end].copy_from_slice(bytes);
|
||||||
|
|
||||||
// 3. Call guest handle
|
// 3. Call guest handle
|
||||||
if self.handle.call(&mut self.store, (ptr, len)).is_err() {
|
if self.handle.call(&mut self.store, (ptr, len)).is_err() {
|
||||||
|
|
|
||||||
|
|
@ -280,7 +280,6 @@ fn handle_trap_drops_message_actor_survives() {
|
||||||
// ── Bounds safety: alloc pointer near end of linear memory ────────────────────
|
// ── Bounds safety: alloc pointer near end of linear memory ────────────────────
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
#[ignore] // BUG: actor.rs:44-46 has no bounds check — actor gets poisoned instead of surviving
|
|
||||||
fn alloc_near_end_of_memory_drops_message_actor_survives() {
|
fn alloc_near_end_of_memory_drops_message_actor_survives() {
|
||||||
// Guest alloc returns 65500 (near end of 1-page / 65536-byte memory).
|
// Guest alloc returns 65500 (near end of 1-page / 65536-byte memory).
|
||||||
// A 100-byte message means ptr+len = 65600, which exceeds memory bounds.
|
// A 100-byte message means ptr+len = 65600, which exceeds memory bounds.
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue