Add bounds check in Remember to prevent potential bof panic #256
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hi, I found the function
Remember
in the filesample/user.go
does not check the lengths of the parameterskeys
andvalues
. If the number of keys is greater than the one of values, the buffer access at line 103 would cause bof panic. This patch adds a length check in the Remember function to avoid this bof panic.Although current test cases use matching lengths, adding this check improves robustness and makes the assumption explicit, which can help avoid unexpected panics if the function is reused elsewhere.
Let me know if you'd prefer returning an error instead of logging a fatal error—happy to adjust.