Skip to content

Validate note accessor bounds - #173

Open
sstamenk wants to merge 2 commits into
serge1:mainfrom
sstamenk:fix/note-accessor-bounds
Open

sstamenk wants to merge 2 commits into
serge1:mainfrom
sstamenk:fix/note-accessor-bounds

Conversation

@sstamenk

@sstamenk sstamenk commented Aug 31, 2026 •

Copy link
Copy Markdown

Fix note indexing and record validation in the section and segment accessors. The index check used the section's byte size instead of the number of parsed notes.

Changes

  • Share record decoding between scanning and retrieval, and revalidate cached offsets against the current data.
  • Use memcpy, byte-order conversion, and widened padding calculations to validate the complete record.
  • Require terminated owner names while preserving nameless notes. Leave output parameters unchanged when validation fails.

The public API is unchanged.

Tests

Eight scenarios run across ELF32/ELF64 and both byte orders. Coverage includes invalid indices, truncated and oversized records, owner names, data mutation, serialized sections/segments, and unaligned headers.

  • Full suite: 105/105 passed with MSVC ASan.
  • Focused note tests: 32/32 passed with GCC ASan/UBSan.

Prepared with AI assistance.

Centralize record validation and check owner string termination. Cover both ELF classes, byte orders, section and segment access, and data mutation. Keep test registration compatible with the hash lookup changes.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant