Skip to content

Validate NumStates and negative Start state in VectorFstImpl::Read. - #346

Merged
copybara-service[bot] merged 1 commit into
mainfrom
copybara/995035133
Oct 7, 2026
Merged

copybara-service[bot] merged 1 commit into
mainfrom
copybara/995035133

Conversation

@copybara-service

Copy link
Copy Markdown

Validate NumStates and negative Start state in VectorFstImpl::Read.

VectorFstImpl::Read previously passed hdr.NumStates() directly to ReserveStates(size_t) whenever hdr.NumStates() != kNoStateId, and only checked impl->Start() >= state after reading states. As a result:

  • A negative hdr.NumStates() other than kNoStateId (e.g., -2) converted to a huge size_t in ReserveStates and aborted, and a huge positive hdr.NumStates() in a corrupt or truncated header attempted an unbounded upfront allocation before reading the first state.
  • A negative start state < kNoStateId (e.g., -2) passed the impl->Start() != kNoStateId && impl->Start() >= state check.

Reject hdr.NumStates() < 0 || hdr.NumStates() > kMaxStates (when != kNoStateId), cap the upfront ReserveStates call to kMaxReserveStates, and reject impl->Start() < 0 in the start-state range check (matching ConstFstImpl::Read and CompactArcStore::Read). Add unit tests in fst_limits_test.cc.

@copybara-service
copybara-service Bot force-pushed the copybara/995035133 branch 3 times, most recently from 5a29e1e to 39c97f6 Compare October 7, 2026 15:20
…ad`.

`VectorFstImpl::Read` previously passed `hdr.NumStates()` directly to `ReserveStates(size_t)` whenever `hdr.NumStates() != kNoStateId`, and only checked `impl->Start() >= state` after reading states. As a result:
- A negative `hdr.NumStates()` other than `kNoStateId` (e.g., `-2`) converted to a huge `size_t` in `ReserveStates` and aborted, and a huge positive `hdr.NumStates()` in a corrupt or truncated header attempted an unbounded upfront allocation before reading the first state.
- A negative start state `< kNoStateId` (e.g., `-2`) passed the `impl->Start() != kNoStateId && impl->Start() >= state` check.

Reject `hdr.NumStates() < 0 || hdr.NumStates() > kMaxStates` (when `!= kNoStateId`), cap the upfront `ReserveStates` call to `kMaxReserveStates`, and reject `impl->Start() < 0` in the start-state range check (matching `ConstFstImpl::Read` and `CompactArcStore::Read`). Add unit tests in `fst_limits_test.cc`.

PiperOrigin-RevId: 995131897
@copybara-service
copybara-service Bot merged commit d3b4480 into main Oct 7, 2026
1 check passed
@copybara-service
copybara-service Bot deleted the copybara/995035133 branch October 7, 2026 15:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant