Skip to content

codecs: bound wire decoding and attribute nesting - #33

Merged
edsiper merged 6 commits into
masterfrom
fix/decoder-validation
Sep 21, 2026
Merged

edsiper merged 6 commits into
masterfrom
fix/decoder-validation

Conversation

@edsiper

@edsiper edsiper commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

Reject excessive nesting before recursive protobuf-C unpacking as well as during MessagePack/OTLP attribute conversion, and free nested attribute values during OTLP encoder cleanup.

The OTLP decoder now performs an explicit-stack, schema-aware wire preflight before calling unpack. This addresses the review finding that a conversion-only limit runs after protobuf-C has already allocated the message tree and leaves recursive unpack/free exposed. The wire preflight bounds the tree to 100 schema messages, rejects malformed lengths/varints, and treats strings, bytes, packed scalars and unknown fields as opaque. Input pointers and offsets are checked before buffer arithmetic.

The separate 32-container attribute budget is retained, with the outer map at depth zero. MessagePack helper signatures remain compatible. Encoder cleanup recursively releases nested AnyValue containers while preserving the protobuf empty-string sentinel.

Validation: all 6 CTest targets pass. The protobuf boundary and OTLP transcoder tests pass Valgrind with zero errors and no leaks. Downstream Fluent Bit tests pass normally and under strict Valgrind. Tests cover 99/100/101 schema-message boundaries, malformed wire fields, and 8/31/32/400 attribute-depth cases for maps, arrays and mixed nesting, including cleanup and continued ingestion.

Compatibility: excessive nesting is rejected. The wire budget includes request and resource/scope wrappers; existing supported attribute-depth tests still pass. No public structure layout or function signature changes.

Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
@edsiper
edsiper marked this pull request as ready for review September 19, 2026 13:28
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-19T13:31:08.219628Z d3e339b Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d3e339b08b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/cprof_opentelemetry_variant_helpers.c
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
@edsiper edsiper changed the title codecs: bound attribute nesting and fix nested value cleanup codecs: bound wire decoding and attribute nesting Sep 19, 2026
@edsiper
edsiper merged commit 6d1e6b5 into master Sep 21, 2026
20 of 21 checks passed
@edsiper
edsiper deleted the fix/decoder-validation branch September 21, 2026 01:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant