Skip to content

fix(security): bound response slicing, guard guess count underflow, validate thresholds, and cap HTTP bodies - #26

Open
mertcano wants to merge 1 commit into
phantom:mainfrom
mertcano:mertcano-patch-1
Open

mertcano wants to merge 1 commit into
phantom:mainfrom
mertcano:mertcano-patch-1

Conversation

@mertcano

Copy link
Copy Markdown

Description

Remediates memory safety, arithmetic underflow, configuration assertion, and resource exhaustion vulnerabilities across juicebox-sdk.

Previously, untrusted realm lengths sliced fixed buffers without bounds checks, guess counter calculations lacked underflow protection, register_threshold assertions duplicated recover_threshold logic, and HTTP responses were read into memory without size boundaries.

Key Changes & Remediations

  • Unpadded Length Bounds Clamping (rust/realm/api/src/requests.rs):

    • Clamped unpadded_length against the underlying buffer length (min(padded_bytes.len())) prior to slicing.
    • Prevents panic and denial-of-service on malicious or corrupted realm responses.
  • Saturating Guess Arithmetic (rust/sdk/src/recover.rs):

    • Replaced subtraction with num_guesses.saturating_sub(guess_count).
    • Guarantees u16 underflow safety if a realm reports an unexpected guess_count.
  • Configuration Threshold Validation (rust/sdk/src/configuration.rs):

    • Corrected duplicate assertions in CheckedConfiguration::from.
    • Explicitly enforces 1 <= register_threshold <= recover_threshold <= realm_count.
  • Streaming HTTP Body Size Cap (rust/networking/src/reqwest.rs):

    • Implemented read_body_capped() with MAX_RESPONSE_BODY_BYTES = 16 * 1024 * 1024 (16 MiB).
    • Streams incoming response chunks and aborts immediately if the payload limit is exceeded.

Verification

  • Verified clamping logic in SecretsResponse::try_from.
  • Confirmed threshold ordering in CheckedConfiguration::from.
  • Validated streaming cap handling in reqwest::Client::to_response.

…alidate thresholds, and cap HTTP bodies

## Description
Remediates memory safety, arithmetic underflow, configuration assertion, and resource exhaustion vulnerabilities across `juicebox-sdk`.

Previously, untrusted realm lengths sliced fixed buffers without bounds checks, guess counter calculations lacked underflow protection, `register_threshold` assertions duplicated `recover_threshold` logic, and HTTP responses were read into memory without size boundaries.

## Key Changes & Remediations

* **Unpadded Length Bounds Clamping (`rust/realm/api/src/requests.rs`)**:
  - Clamped `unpadded_length` against the underlying buffer length (`min(padded_bytes.len())`) prior to slicing.
  - Prevents panic and denial-of-service on malicious or corrupted realm responses.

* **Saturating Guess Arithmetic (`rust/sdk/src/recover.rs`)**:
  - Replaced subtraction with `num_guesses.saturating_sub(guess_count)`.
  - Guarantees `u16` underflow safety if a realm reports an unexpected `guess_count`.

* **Configuration Threshold Validation (`rust/sdk/src/configuration.rs`)**:
  - Corrected duplicate assertions in `CheckedConfiguration::from`.
  - Explicitly enforces `1 <= register_threshold <= recover_threshold <= realm_count`.

* **Streaming HTTP Body Size Cap (`rust/networking/src/reqwest.rs`)**:
  - Implemented `read_body_capped()` with `MAX_RESPONSE_BODY_BYTES = 16 * 1024 * 1024` (16 MiB).
  - Streams incoming response chunks and aborts immediately if the payload limit is exceeded.

## Verification
- Verified clamping logic in `SecretsResponse::try_from`.
- Confirmed threshold ordering in `CheckedConfiguration::from`.
- Validated streaming cap handling in `reqwest::Client::to_response`.
@coderabbitai

coderabbitai Bot commented Sep 19, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 8a79622b-b8ef-4e34-8c9d-b50f4c63ebff


Comment @coderabbitai help to get the list of available commands.

@mertcano

Copy link
Copy Markdown
Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 20, 2026

Copy link
Copy Markdown

CodeRabbit chat interactions are restricted to organization members for this repository. Ask an organization member to interact with CodeRabbit, or set chat.allow_non_org_members: true in your configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant