thrift-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From GitBox <>
Subject [GitHub] [thrift] fishy opened a new pull request #2258: THRIFT-5294: Fix panic in go TSimpleJSONProtocol
Date Sun, 11 Oct 2020 01:43:54 GMT

fishy opened a new pull request #2258:

   Client: go
   In go library's TSimpleJSONProtocol and TJSONProtocol implementations,
   we use slices as stacks for context info, but didn't do proper boundary
   check when peeking/popping, result in it might panic with using -1 as
   slice index in certain cases of calling Write*End without matching
   Write*Begin before.
   Refactor the code to properly implement the stack, and return a
   TProtocolException instead on those cases.
   Also add unit tests for them.
   <!-- Explain the changes in the pull request below: -->
   <!-- We recommend you review the checklist/tips before submitting a pull request. -->
   - [x] Did you create an [Apache Jira](
ticket?  (not required for trivial changes)
   - [x] If a ticket exists: Does your pull request title follow the pattern "THRIFT-NNNN:
describe my issue"?
   - [x] Did you squash your changes to a single commit?  (not required, but preferred)
   - [x] Did you do your best to avoid breaking changes?  If one was needed, did you label
the Jira ticket with "Breaking-Change"?
   - [ ] If your change does not involve any code, include `[skip ci]` anywhere in the commit
message to free up build resources.
     The Contributing Guide at:
     has more details and tips for committing properly.

This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:

View raw message