Validate FatArch alignment and reject truncated Fat architecture records - #1030
Merged
Merged
Conversation
Signed-off-by: Caleb Xu <calebcenter@live.com> Assisted-by: OpenCode (Nemotron 3 Ultra)
Reject alignment values exceeding MAX_FAT_ARCH_ALIGN (15) in populate_fat_archs to prevent excessive padding allocation during Fat file reconstruction and signing. Signed-off-by: Caleb Xu <calebcenter@live.com> Assisted-by: OpenCode (Nemotron 3 Ultra)
There was a problem hiding this comment.
馃煛 Changes recommended
Unused test assignments will fail the repository鈥檚 default RuboCop check.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Hardens Fat Mach-O parsing against unsafe alignments and truncated architecture records.
Changes:
- Rejects alignment exponents above 15.
- Detects truncated 32-bit and 64-bit records.
- Adds parsing and code-signing regression tests.
File summaries
| File | Reviewed changes and findings |
|---|---|
test/test_fat.rb |
Adds malformed-record tests. Critical: Remove unused assignments on lines 69 and 90; RuboCop will fail. |
test/test_code_signing.rb |
Tests safe signing failure. No issues found. |
lib/macho/headers.rb |
Defines the maximum alignment exponent. No issues found. |
lib/macho/fat_file.rb |
Validates record lengths and alignments. Nit: Document the new FatArchAlignmentError raise. |
lib/macho/exceptions.rb |
Adds the alignment error type. No issues found. |
Review details
Suppressed comments (2)
lib/macho/fat_file.rb:374
- The updated raise documentation covers truncation but omits the new
FatArchAlignmentErrorraised directly by this method. Add it so callers of this public-but-private-API parser method can see both newly enforced failure modes.
# @raise [TruncatedFileError] if the file is too small to contain all fat architectures
test/test_fat.rb:90
- This local is also never read and will be reported by the RuboCop check as
Lint/UselessAssignment. Remove it so the repository check can pass.
fat_arch64_size = MachO::Headers::FatArch64.bytesize
- Files reviewed: 5/5 changed files
- Comments generated: 1
- Review effort level: Balanced
馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- test_invalid_fat_arch_alignment_32: reject FAT_MAGIC with align > 15 - test_invalid_fat_arch_alignment_64: reject FAT_MAGIC_64 with align > 15 - test_max_valid_fat_arch_alignment_accepted: accept align == 15 - test_rejects_invalid_fat_alignment_before_signing: end-to-end test verifying file is not modified when alignment is invalid Signed-off-by: Caleb Xu <calebcenter@live.com> Assisted-by: OpenCode (Nemotron 3 Ultra)
alebcay
force-pushed
the
fat-arch-alignment
branch
from
September 7, 2026 04:12
bb19694 to
899b5e2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
populate_fat_archsto check record length before unpacking; truncated FatArch/FatArch64 records now raiseTruncatedFileErrorinstead ofNoMethodError