New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

src: detect nul bytes in InternalModuleReadFile() #14854

Closed
wants to merge 1 commit into
base: master
from

Conversation

Projects
None yet
8 participants
@bnoordhuis
Member

bnoordhuis commented Aug 16, 2017

Throw an exception when the path contains nul bytes, don't abort.

Fixes: #13787
CI: https://ci.nodejs.org/job/node-test-pull-request/9683/

src: detect nul bytes in InternalModuleReadFile()
Throw an exception when the path contains nul bytes, don't abort.

Fixes: #13787
@bnoordhuis

This comment has been minimized.

Show comment
Hide comment
@bnoordhuis

bnoordhuis Aug 16, 2017

Member

I didn't add a check to InternalModuleStat() because:

  1. Performance. It's called much more often.
  2. It seems unnecessary. Worst case you stat the wrong file but InternalModuleReadFile() will still catch it.
Member

bnoordhuis commented Aug 16, 2017

I didn't add a check to InternalModuleStat() because:

  1. Performance. It's called much more often.
  2. It seems unnecessary. Worst case you stat the wrong file but InternalModuleReadFile() will still catch it.
@addaleax

This comment has been minimized.

Show comment
Hide comment
@addaleax

addaleax Aug 21, 2017

Member

Landed in ffed7b6

Member

addaleax commented Aug 21, 2017

Landed in ffed7b6

@addaleax addaleax closed this Aug 21, 2017

addaleax added a commit that referenced this pull request Aug 21, 2017

src: detect nul bytes in InternalModuleReadFile()
Throw an exception when the path contains nul bytes, don't abort.

Fixes: #13787
PR-URL: #14854
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Tobias Nießen <tniessen@tnie.de>
Reviewed-By: Timothy Gu <timothygu99@gmail.com>
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>

MylesBorins added a commit that referenced this pull request Sep 10, 2017

src: detect nul bytes in InternalModuleReadFile()
Throw an exception when the path contains nul bytes, don't abort.

Fixes: #13787
PR-URL: #14854
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Tobias Nießen <tniessen@tnie.de>
Reviewed-By: Timothy Gu <timothygu99@gmail.com>
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>

@MylesBorins MylesBorins referenced this pull request Sep 10, 2017

Merged

v8.5.0 proposal #15308

MylesBorins added a commit that referenced this pull request Sep 12, 2017

src: detect nul bytes in InternalModuleReadFile()
Throw an exception when the path contains nul bytes, don't abort.

Fixes: #13787
PR-URL: #14854
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Tobias Nießen <tniessen@tnie.de>
Reviewed-By: Timothy Gu <timothygu99@gmail.com>
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
@MylesBorins

This comment has been minimized.

Show comment
Hide comment
@MylesBorins

MylesBorins Sep 20, 2017

Member

I've backported this to v6.x. please let me know if it should be backed out

Member

MylesBorins commented Sep 20, 2017

I've backported this to v6.x. please let me know if it should be backed out

MylesBorins added a commit that referenced this pull request Sep 20, 2017

src: detect nul bytes in InternalModuleReadFile()
Throw an exception when the path contains nul bytes, don't abort.

Fixes: #13787
PR-URL: #14854
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Tobias Nießen <tniessen@tnie.de>
Reviewed-By: Timothy Gu <timothygu99@gmail.com>
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>

@MylesBorins MylesBorins referenced this pull request Sep 20, 2017

Merged

v6.11.4 proposal #15506

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment