Skip to content

Harden against invalid cache peer digests - #2485

Open
kinkie wants to merge 1 commit into
squid-cache:masterfrom
kinkie:fix-cachedigest-calcmasksize
Open

Harden against invalid cache peer digests#2485
kinkie wants to merge 1 commit into
squid-cache:masterfrom
kinkie:fix-cachedigest-calcmasksize

Conversation

@kinkie

@kinkie kinkie commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

An assert() call was improperly used to validate
a received cache digest from a cache_peer.
Switch to returning an invalid value, so that
the improper digest is rejected instead.

An assert() call was improperly used to validate
a received cache digest from a cache_peer.
Switch to using an invalid value, so that
the improper digest is rejected instead.
@squid-anubis squid-anubis added the M-failed-description https://github.com/measurement-factory/anubis#pull-request-labels label Aug 27, 2026
@squid-anubis

This comment was marked as resolved.

@kinkie

kinkie commented Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

The relevant call is in peerDigestSetCBlock():783, which calls CalcMaskSize() with a peer-supplied cblock.capacity, triggering the assert.

The new code will cause mismatch between cblock.mask_size and the calculated capacity (we may also add an explicit non-zero check as an additional precaution), causing the rejection of the digest.

No other call to CalcMaskSize( ) uses user input

@kinkie kinkie added the backport-to-v7 maintainer has approved these changes for v7 backporting label Aug 27, 2026
@squid-anubis squid-anubis removed the M-failed-description https://github.com/measurement-factory/anubis#pull-request-labels label Aug 27, 2026

@rousskov rousskov left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The proposed solution has several conceptual and implementation problems. I will find the time to disclose and fix them. The ball is in my court.

@rousskov rousskov added the S-waiting-for-reviewer ready for review: Set this when requesting a (re)review using GitHub PR Reviewers box label Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-to-v7 maintainer has approved these changes for v7 backporting S-waiting-for-reviewer ready for review: Set this when requesting a (re)review using GitHub PR Reviewers box

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants