Harden image loader size arithmetic - #340
Conversation
|
Thanks for this! I'd make one change before merging: The image size checking function should probably live in chicle-util.c. It's too tiny to warrant its own code unit. |
|
Thanks for the suggestion. I moved the image buffer size helper into I also updated the loader arithmetic test to link Verified with:
|
|
Thanks! It looks good now. I may refine the build mechanics later on, since this introduces unit tests for libchicle too, and we may want to use a more general approach (one for libchafa, one for libchicle). Also I think we need to be able to read() even if the fstat() fails, but your patch is better than what we had, since it fixes a bug that was there currently. |
Fixes #339.
Summary
This PR hardens decoded image buffer size calculations for loader paths that consume dimensions from untrusted image files.
The change introduces a shared checked-size helper and applies it before allocation, copying, or passing output buffers to decoder APIs.
Changes
chicle_checked_image_buffer_size()for checked 64-bit image buffer sizing.JxlDecoderSetImageOutBuffer().fstat()sizes before mapping files.loader-arithmetic-testcoverage for oversized dimension rejection, zero dimensions/channels, exactmax_sizeboundaries,G_MAXSIZE / n_channelsboundaries, and valid size acceptance.Verification
Confirmed the previous unsafe arithmetic pattern can overflow under clang integer sanitizer with a minimal reproducer:
Ran the new regression test:
Ran CI-like sanitizer build and C unit tests:
Ran a clean normal build and full test suite:
Notes
The sanitizer run still reports existing unrelated UBSan recover-mode findings in areas such as
chafa-symbol-map,smolscale, andchafa-string-util. Those reports are not introduced by this PR. The clean normal build and full test suite pass.