Skip to content

fix(h3 ffi): validate raw slice pointer metadata - #2794

Open
codeandsolder wants to merge 1 commit into
cloudflare:masterfrom
codeandsolder:upstream-pr/h3-ffi-slice-metadata-20261004
Open

codeandsolder wants to merge 1 commit into
cloudflare:masterfrom
codeandsolder:upstream-pr/h3-ffi-slice-metadata-20261004

Conversation

@codeandsolder

Copy link
Copy Markdown

Summary

Validate HTTP/3 C-FFI raw buffer/header pointer metadata before constructing Rust slices.

This is the HTTP/3 counterpart to #2790, kept separate so the transport and H3 surfaces remain independently reviewable.

Problems addressed

The H3 FFI currently constructs slices directly from caller-provided pointers and lengths. Invalid C metadata can therefore violate Rust slice preconditions before quiche gets a chance to return an error. Oversized body lengths also panic instead of using the FFI error channel.

Change

  • add QUICHE_H3_ERR_INVALID_ARGUMENT = -21;
  • validate null/alignment/size metadata before slice::from_raw_parts(_mut);
  • preserve the valid C convention NULL + len == 0 by constructing an aligned empty slice;
  • return the H3 invalid-argument code instead of panicking for oversized body buffers;
  • validate the outer header array and each header name/value pair before creating HeaderRefs;
  • propagate invalid header metadata through request/response/additional-header calls;
  • apply the same checks to body recv/send and extensible-priority parsing.

Validation

Rebased directly onto current upstream master (3fc9bc1c). On Rust 1.98.1 with --features ffi:

  • h3_header_slices_accept_null_zero_and_reject_bad_parts: pass
  • oversized_h3_ffi_length_returns_invalid_argument: pass

Formatting with the repository's nightly rustfmt configuration and git diff --check are clean.

@codeandsolder
codeandsolder requested a review from a team as a code owner October 4, 2026 18:42
@ghedo ghedo added type: bugfix Corrects defective behavior. area: ffi Changes related to ffi. area: h3 Changes related to h3. labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ffi Changes related to ffi. area: h3 Changes related to h3. type: bugfix Corrects defective behavior.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants