Skip to content

Validate fat slice ranges against file size - #1041

Merged
MikeMcQuaid merged 1 commit into
Homebrew:mainfrom
alebcay:macho-fat-file-truncated-file
Oct 2, 2026
Merged

MikeMcQuaid merged 1 commit into
Homebrew:mainfrom
alebcay:macho-fat-file-truncated-file

Conversation

@alebcay

@alebcay alebcay commented Oct 2, 2026

Copy link
Copy Markdown
Member

Raise TruncatedFileError in FatFile#populate_machos when a fat_arch offset and size exceed the file.

Previously, this would raise other (generic) errors or no error at all (return a partial read).

Nemotron 3 was used for identifying the original issue and writing a substantial portion of the test cases.

Raise TruncatedFileError in FatFile#populate_machos when a fat_arch offset and
size exceed the file.
Copilot AI balanced review requested due to automatic review settings October 2, 2026 16:56

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

馃煝 Approval recommended

The bounds check is correct, documented, and adequately tested for relevant edge cases.

Review effort: Balanced
Findings: None

What changed in this PR

Validates fat Mach-O slice ranges before parsing to consistently raise TruncatedFileError.

Changes:

  • Rejects slices extending beyond file bounds.
  • Adds 32-bit and 64-bit malformed-slice tests.
File Description
lib/鈥媘acho/鈥媐at_file.rb Adds slice bounds validation.
test/鈥媡est_fat.rb Covers invalid offsets and sizes.

馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@MikeMcQuaid
MikeMcQuaid merged commit e106f77 into Homebrew:main Oct 2, 2026
12 checks passed
@MikeMcQuaid

Copy link
Copy Markdown
Member

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants