Skip to content

fix(cursor): bound protobuf map entries - #739

Open
outlier27-cell wants to merge 1 commit into
openpi-dev:mainfrom
outlier27-cell:fix/issue-735-protobuf-map-boundary
Open

outlier27-cell wants to merge 1 commit into
openpi-dev:mainfrom
outlier27-cell:fix/issue-735-protobuf-map-boundary

Conversation

@outlier27-cell

Copy link
Copy Markdown
Contributor

Problem

Cursor protobuf map decoding kept reading from the outer message after a map entry's declared length. A malformed entry could therefore consume later bytes as its value.

Closes #735

Value

Malformed catalog protobuf input now fails at the entry boundary instead of silently producing a map value from unrelated bytes.

Approach

  • Decode each length-delimited map entry through its own bounded Reader.
  • Add a regression test using the issue's truncated-entry shape and a valid control message.

Validation

  • node --test --experimental-strip-types tests/extensions/ai-providers/cursor-protobuf.test.ts tests/extensions/ai-providers/cursor.test.ts (38 passing)
  • bun run check
  • bun run test was started; the unmodified full suite reproduced existing renderer-chain failures before it was stopped. Exact-head GitHub CI is tracked for the final cross-platform result.

Impact

No configuration or user-visible workflow changes. The Cursor protobuf decoder rejects malformed map entries more accurately.

@outlier27-cell

Copy link
Copy Markdown
Contributor Author

@tt-a1i 请审核此 PR。#735 的 protobuf map entry 边界读取已在 07d5f23 修复;专项 38 项、�un run check 与 exact-head GitHub CI(Node、Windows、UI、Web E2E)均通过。当前仅等待审核。

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(cursor): protobuf map entries can read beyond their declared length

1 participant