Reject an in-addr.arpa name longer than 32 characters before splitting it - #228
Merged
Merged
Conversation
…g it Address4.fromArpa() split, reversed and joined its whole argument before handing the result to the constructor, so the constructor's 15-character limit ran only after work proportional to the input: about 8 ms per MB (node 24.19.0), against under 0.01 ms for the same string in Address6.fromArpa(), whose nibble grammar rejects it first. The longest name the constructor accepts is a 15-character address, a "/32" prefix length on its last octet (the RFC 2317 classless form) and ".in-addr.arpa.": 32 characters. Anything longer is rejected on entry. Every name that parsed before still parses; a longer one throws AddressError as it did, with a message naming the 32-character limit.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Address4.fromArpa()split, reversed and joined its whole argument before handing the result to the constructor, so the constructor's 15-character limit ran only after work proportional to the input. On node 24.19.0 that is about 8 ms per MB: 33 ms for 4 MB, 259 ms for 32 MB.Address6.fromArpa()rejects the same strings in under 0.01 ms, because its nibble grammar is checked first.The fix
Address4.fromArpa()checks the length of its argument on entry and throwsAddressErrorabove 32 characters. That is the longest name the constructor accepts: a 15-character address, a/32prefix length on its last octet (the RFC 2317 classless form, as in0/25.2.0.192.in-addr.arpa.) and.in-addr.arpa..Every name that parsed before still parses. A longer one threw
AddressErrorbefore and throws it now, with a message naming the 32-character limit.Tests
A new
input lengthblock underfromArpacovers the longest name, the RFC 2317 form, and rejection of names one character over the limit, a 34-character run of labels, and 1 MiB of dots. The rejection test fails before the fix.Reported by @manus-pi via GHSA-24hj-7547-x7wc, declined as an advisory and fixed as hardening: the cost is linear in the input and up to about 8 times its size in memory, which is what splitting any string costs, and it takes megabytes in a field that holds at most 32 characters to notice.