A malformed snapshot database crashes restore with a Go panic instead of an error #231

Closed
opened 2026-10-06 01:49:47 +02:00 by clawbot · 1 comment
Collaborator

The downloaded snapshot database is untrusted input: #154, #155 and #156 made restore check it. A few sites still slice or dereference values read from it without checking them (traced on next at 0700901, not run):

  • Unchecked [:16] slices of chunk hashes at internal/vaultik/restore_plan.go:78, internal/vaultik/restore.go:1176 and :1193. A file_chunks row whose hash is shorter than 16 characters, with no matching blob_chunks row, panics.
  • Under --verify, a missing chunk row is dereferenced, and a size taken from the database is allocated without a bound (restore.go:1388-1395).

Definition of done

  1. These sites use the existing shortHash helper, check for a missing chunk row, and stream or bound the verify read instead of allocating a size taken from the database.
  2. A test with a crafted database (a short hash, a missing chunk row) gets an error, not a panic.
  3. make check passes.

Model: fable-5-1 (audit); opus-5-5 (issue)

The downloaded snapshot database is untrusted input: https://git.eeqj.de/sneak/vaultik/issues/154, https://git.eeqj.de/sneak/vaultik/issues/155 and https://git.eeqj.de/sneak/vaultik/issues/156 made restore check it. A few sites still slice or dereference values read from it without checking them (traced on `next` at `0700901`, not run): - Unchecked `[:16]` slices of chunk hashes at `internal/vaultik/restore_plan.go:78`, `internal/vaultik/restore.go:1176` and `:1193`. A `file_chunks` row whose hash is shorter than 16 characters, with no matching `blob_chunks` row, panics. - Under `--verify`, a missing chunk row is dereferenced, and a size taken from the database is allocated without a bound (`restore.go:1388-1395`). ## Definition of done 1. These sites use the existing `shortHash` helper, check for a missing chunk row, and stream or bound the verify read instead of allocating a size taken from the database. 2. A test with a crafted database (a short hash, a missing chunk row) gets an error, not a panic. 3. `make check` passes. Model: fable-5-1 (audit); opus-5-5 (issue)
clawbot self-assigned this 2026-10-06 01:49:47 +02:00
Author
Collaborator

Still present on next at 5aa5ba5. Fixed in #249: the chunk-hash messages use shortHash, and --verify reports a missing chunks row as an error, rejects a negative size, and streams each chunk instead of allocating its stored size.

Model: opus-5-5

Still present on `next` at `5aa5ba5`. Fixed in https://git.eeqj.de/sneak/vaultik/pulls/249: the chunk-hash messages use `shortHash`, and `--verify` reports a missing `chunks` row as an error, rejects a negative size, and streams each chunk instead of allocating its stored size. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/vaultik#231