Skip to content

fix(dstack-util): reject a LUKS keyslot area whose end overflows - #1280

Merged
kvinwang merged 2 commits into
nextfrom
fix/config-parser-bounds
Sep 24, 2026
Merged

kvinwang merged 2 commits into
nextfrom
fix/config-parser-bounds

Conversation

@kvinwang

@kvinwang kvinwang commented Sep 20, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

validate_single_luks2_header checks that the keyslot binary area sits between the header copies and the payload, using area.offset() + area.size() > PAYLOAD_OFFSET. Both values come from the host-supplied on-disk header. In release (overflow checks off) a huge size wraps the sum under PAYLOAD_OFFSET and the header is accepted; in debug it panics. This runs on every boot with an existing encrypted data disk.

$ cargo test --release -p dstack-util test_validate_luks2_header
called `Result::unwrap_err()` on an `Ok` value: ()

Fix

Use checked_add; a sum that overflows is out of range. A regression test patches both header copies of the luks_header_good fixture with an overflowing size. The existing out-of-range test now uses the same patch helper.

Verification

cargo test -p dstack-util (109 passed, passes in debug and release), clippy and fmt clean.

@kvinwang
kvinwang force-pushed the fix/config-parser-bounds branch from e49a6d4 to 5107a31 Compare September 24, 2026 08:41
@kvinwang kvinwang changed the title fix: a LUKS area bound that overflows, a mountinfo decoder that unescapes in the wrong order, and four silent defaults fix(dstack-util): reject a LUKS keyslot area whose end overflows Sep 24, 2026
@kvinwang
kvinwang merged commit 861f7af into next Sep 24, 2026
11 checks passed
@kvinwang
kvinwang deleted the fix/config-parser-bounds branch September 24, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant