The downloaded snapshot database is untrusted input: #154, #155 and #156 made restore check it. A few sites still slice or dereference values read from it without checking them (traced on next at 0700901, not run):
Unchecked [:16] slices of chunk hashes at internal/vaultik/restore_plan.go:78, internal/vaultik/restore.go:1176 and :1193. A file_chunks row whose hash is shorter than 16 characters, with no matching blob_chunks row, panics.
Under --verify, a missing chunk row is dereferenced, and a size taken from the database is allocated without a bound (restore.go:1388-1395).
Definition of done
These sites use the existing shortHash helper, check for a missing chunk row, and stream or bound the verify read instead of allocating a size taken from the database.
A test with a crafted database (a short hash, a missing chunk row) gets an error, not a panic.
make check passes.
Model: fable-5-1 (audit); opus-5-5 (issue)
The downloaded snapshot database is untrusted input: https://git.eeqj.de/sneak/vaultik/issues/154, https://git.eeqj.de/sneak/vaultik/issues/155 and https://git.eeqj.de/sneak/vaultik/issues/156 made restore check it. A few sites still slice or dereference values read from it without checking them (traced on `next` at `0700901`, not run):
- Unchecked `[:16]` slices of chunk hashes at `internal/vaultik/restore_plan.go:78`, `internal/vaultik/restore.go:1176` and `:1193`. A `file_chunks` row whose hash is shorter than 16 characters, with no matching `blob_chunks` row, panics.
- Under `--verify`, a missing chunk row is dereferenced, and a size taken from the database is allocated without a bound (`restore.go:1388-1395`).
## Definition of done
1. These sites use the existing `shortHash` helper, check for a missing chunk row, and stream or bound the verify read instead of allocating a size taken from the database.
2. A test with a crafted database (a short hash, a missing chunk row) gets an error, not a panic.
3. `make check` passes.
Model: fable-5-1 (audit); opus-5-5 (issue)
clawbot
self-assigned this 2026-10-06 01:49:47 +02:00
Still present on next at 5aa5ba5. Fixed in #249: the chunk-hash messages use shortHash, and --verify reports a missing chunks row as an error, rejects a negative size, and streams each chunk instead of allocating its stored size.
Model: opus-5-5
Still present on `next` at `5aa5ba5`. Fixed in https://git.eeqj.de/sneak/vaultik/pulls/249: the chunk-hash messages use `shortHash`, and `--verify` reports a missing `chunks` row as an error, rejects a negative size, and streams each chunk instead of allocating its stored size.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The downloaded snapshot database is untrusted input: #154, #155 and #156 made restore check it. A few sites still slice or dereference values read from it without checking them (traced on
nextat0700901, not run):[:16]slices of chunk hashes atinternal/vaultik/restore_plan.go:78,internal/vaultik/restore.go:1176and:1193. Afile_chunksrow whose hash is shorter than 16 characters, with no matchingblob_chunksrow, panics.--verify, a missing chunk row is dereferenced, and a size taken from the database is allocated without a bound (restore.go:1388-1395).Definition of done
shortHashhelper, check for a missing chunk row, and stream or bound the verify read instead of allocating a size taken from the database.make checkpasses.Model: fable-5-1 (audit); opus-5-5 (issue)
Still present on
nextat5aa5ba5. Fixed in #249: the chunk-hash messages useshortHash, and--verifyreports a missingchunksrow as an error, rejects a negative size, and streams each chunk instead of allocating its stored size.Model: opus-5-5