Repository navigation
Conversation
…alidate thresholds, and cap HTTP bodies ## Description Remediates memory safety, arithmetic underflow, configuration assertion, and resource exhaustion vulnerabilities across `juicebox-sdk`. Previously, untrusted realm lengths sliced fixed buffers without bounds checks, guess counter calculations lacked underflow protection, `register_threshold` assertions duplicated `recover_threshold` logic, and HTTP responses were read into memory without size boundaries. ## Key Changes & Remediations * **Unpadded Length Bounds Clamping (`rust/realm/api/src/requests.rs`)**: - Clamped `unpadded_length` against the underlying buffer length (`min(padded_bytes.len())`) prior to slicing. - Prevents panic and denial-of-service on malicious or corrupted realm responses. * **Saturating Guess Arithmetic (`rust/sdk/src/recover.rs`)**: - Replaced subtraction with `num_guesses.saturating_sub(guess_count)`. - Guarantees `u16` underflow safety if a realm reports an unexpected `guess_count`. * **Configuration Threshold Validation (`rust/sdk/src/configuration.rs`)**: - Corrected duplicate assertions in `CheckedConfiguration::from`. - Explicitly enforces `1 <= register_threshold <= recover_threshold <= realm_count`. * **Streaming HTTP Body Size Cap (`rust/networking/src/reqwest.rs`)**: - Implemented `read_body_capped()` with `MAX_RESPONSE_BODY_BYTES = 16 * 1024 * 1024` (16 MiB). - Streams incoming response chunks and aborts immediately if the payload limit is exceeded. ## Verification - Verified clamping logic in `SecretsResponse::try_from`. - Confirmed threshold ordering in `CheckedConfiguration::from`. - Validated streaming cap handling in `reqwest::Client::to_response`.
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: Comment |
Author
|
@coderabbitai full review |
|
CodeRabbit chat interactions are restricted to organization members for this repository. Ask an organization member to interact with CodeRabbit, or set |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Remediates memory safety, arithmetic underflow, configuration assertion, and resource exhaustion vulnerabilities across
juicebox-sdk.Previously, untrusted realm lengths sliced fixed buffers without bounds checks, guess counter calculations lacked underflow protection,
register_thresholdassertions duplicatedrecover_thresholdlogic, and HTTP responses were read into memory without size boundaries.Key Changes & Remediations
Unpadded Length Bounds Clamping (
rust/realm/api/src/requests.rs):unpadded_lengthagainst the underlying buffer length (min(padded_bytes.len())) prior to slicing.Saturating Guess Arithmetic (
rust/sdk/src/recover.rs):num_guesses.saturating_sub(guess_count).u16underflow safety if a realm reports an unexpectedguess_count.Configuration Threshold Validation (
rust/sdk/src/configuration.rs):CheckedConfiguration::from.1 <= register_threshold <= recover_threshold <= realm_count.Streaming HTTP Body Size Cap (
rust/networking/src/reqwest.rs):read_body_capped()withMAX_RESPONSE_BODY_BYTES = 16 * 1024 * 1024(16 MiB).Verification
SecretsResponse::try_from.CheckedConfiguration::from.reqwest::Client::to_response.