<feed xmlns='http://www.w3.org/2005/Atom'>
<title>mobius/hotline/decode.go, branch main</title>
<subtitle>Friendship Quest remix of mobius, a hotline server in go #cli</subtitle>
<id>https://git.r.bdr.sh/mobius/atom/hotline/decode.go?h=main</id>
<link rel='self' href='https://git.r.bdr.sh/mobius/atom/hotline/decode.go?h=main'/>
<link rel='alternate' type='text/html' href='https://git.r.bdr.sh/mobius/'/>
<updated>2026-05-31T21:48:31Z</updated>
<entry>
<title>Validate client input to prevent panics from malformed transactions</title>
<updated>2026-05-31T21:48:31Z</updated>
<author>
<name>Jeff Halter</name>
<email>868228+jhalter@users.noreply.github.com</email>
</author>
<published>2026-05-31T21:48:31Z</published>
<link rel='alternate' type='text/html' href='https://git.r.bdr.sh/mobius/commit/?id=123d1a305bc68474034f5989362148508bdbf7f5'/>
<id>urn:sha1:123d1a305bc68474034f5989362148508bdbf7f5</id>
<content type='text'>
A malicious or buggy client could send transaction fields with the wrong
length and trigger runtime panics (slice/index out of range, slice-to-array
conversion, nil deref) in the parsing and handler code. These were caught by
the connection-level recover, so they dropped the client connection and dumped
a stack trace to stdout rather than crashing the process, but they are still
incorrect behavior, a log-flood vector, and a latent crash if the recover
scope ever changes.

Fix at the source and harden the safety net:

- Add ClientIDFromBytes / ChatIDFromBytes helpers that return ok=false on a
  length mismatch, and use them in the transaction handlers instead of direct
  [2]byte(...) / [4]byte(...) conversions on field data. Nil-check ClientMgr.Get
  results, and length-guard FieldOptions and the HandleUpdateUser sub-field
  header. Malformed input now yields an error reply (or a clean no-op for
  reply-less handlers) instead of panicking.
- Bounds-check FileResumeData.UnmarshalBinary (header length and fork count)
  and guard the ForkInfoList[0] accesses against an empty list.
- Bounds-check FlatFileInformationFork parsing (reachable on upload): validate
  the fixed header, name, and comment lengths, and fix a latent 72+nameSize
  uint16 overflow. Route Write through UnmarshalBinary.
- panic.go: stop printing stack traces to stdout (keep structured logging) so a
  client cannot flood stdout by repeatedly triggering a panic.
- handleTransaction: recover per-transaction so one malformed request no longer
  tears down the whole client connection.

Adds tests for the new helpers, the hardened resume-data and flat-file-object
decoders, and handler-level malformed-ID handling.
</content>
</entry>
</feed>
