This commit fixes an issue in which the following sequence of operations leads to use of uninitialized memory: 1. Caller invokes GrpcBufferWriter::Next(), and then makes use of 8191 bytes in the returned buffer (which is 8192 bytes in size). 2. Caller then returns the unused single byte via GrpcBufferWriter::BackUp(). This method invokes g_core_codegen_interface->grpc_slice_split_tail(), which causes backup_slice_ to be a grpc_slice with one byte. 3. At the next invocation of GrpcBufferWriter::Next(), a reference to the single byte grpc_slice is returned to the caller. The problem here is that the returned reference is to the inlined buffer in the grpc_slice, which is resident in slice_, not the location of the buffer inside slice_buffer_ after g_core_codegen_interface->grpc_slice_buffer_add() in GrpcBufferWriter::Next(). As a result, any data the caller writes to the returned void* data is lost. The solution is to avoid inlined backup slices. |
||
|---|---|---|
| .. | ||
| codegen | ||
| README.md | ||
| call.h | ||
| client_unary_call.h | ||
| grpc_library.h | ||
| method_handler_impl.h | ||
| rpc_method.h | ||
| rpc_service_method.h | ||
| serialization_traits.h | ||
| server_builder_option.h | ||
| server_builder_plugin.h | ||
| server_initializer.h | ||
| service_type.h | ||
| sync_cxx11.h | ||
| sync_no_cxx11.h | ||
README.md
The APIs in this directory are not stable!
This directory contains header files that need to be installed but are not part of the public API. Users should not use these headers directly.