Skip to content

decode_opentelemetry: bound wire decoding and attribute nesting - #97

Merged
edsiper merged 4 commits into
masterfrom
fix/decoder-validation
Sep 19, 2026
Merged

edsiper merged 4 commits into
masterfrom
fix/decoder-validation

Conversation

@edsiper

@edsiper edsiper commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

Reject excessively nested OTLP attributes and wire messages before they can exhaust decoder resources or produce contexts beyond the MessagePack nesting budget.

A schema-aware wire preflight now runs before recursive protobuf-c unpacking, so the protection also covers allocation and recursive cleanup before CFL conversion. It uses an explicit stack with a 100-message budget and treats strings, bytes, packed scalars and unknown fields as opaque. Attribute conversion separately retains the 32-container limit, with the outer attribute map at depth zero. Public helper signatures remain unchanged.

Validation: all 6 CTest targets pass. The protobuf boundary and OTLP tests pass Valgrind with zero errors and no leaks. Downstream Fluent Bit Forward/OTLP regression tests pass normally and under strict Valgrind. Tests cover 99/100/101 schema-message boundaries, malformed wire lengths/varints, and existing 8/31/32/400 attribute-depth cases across maps, arrays and mixed nesting.

Compatibility: excessive nesting is rejected. The protobuf budget counts intermediate protocol wrappers as well as AnyValue messages; existing supported attribute-depth tests still pass. No public ABI changes.

Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
@edsiper
edsiper marked this pull request as ready for review September 19, 2026 13:27
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
Signed-off-by: Eduardo Silva <eduardo@chronosphere.io>
@edsiper edsiper changed the title decode_opentelemetry: enforce attribute nesting limits decode_opentelemetry: bound wire decoding and attribute nesting Sep 19, 2026
@edsiper
edsiper merged commit 5427970 into master Sep 19, 2026
22 checks passed
@edsiper
edsiper deleted the fix/decoder-validation branch September 19, 2026 15:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant