Skip to content

Return errors instead of panicking on short lines in meminfo, ipvs and cpufreq parsers - #880

Open
LemonCondor wants to merge 1 commit into
prometheus:masterfrom
LemonCondor:fix-short-line-panics
Open

LemonCondor wants to merge 1 commit into
prometheus:masterfrom
LemonCondor:fix-short-line-panics

Conversation

@LemonCondor

Copy link
Copy Markdown

Three parsers index into strings.Fields results before checking how many fields there are, so malformed input panics with index out of range instead of returning an error (or skipping the line, where that is what the surrounding code already does):

  • parseMemInfo reads fields[1] before the switch len(fields) that returns Malformed line; an empty or single-field line panics. The field count is now checked first, returning the same error.
  • parseIPVSBackendStatus evaluates fields[1] == "RemoteAddress:Port" for any line whose first field is not IP/Prot; a single-field line panics. The comparison is now guarded by len(fields) > 1; the other cases already skip short lines.
  • The cpufreq trans_table parser indexes fields[0] on a line made only of whitespace (it passes the line == "" check). Such lines are now skipped.

Tests: added TestParseMemInfoMalformedLine, TestParseIPVSBackendStatusShortLine and TestParseCpufreqTransTableBlankLine; each panics before this change and passes after. go test ./... passes with the unpacked fixtures; gofmt and go vet are clean.

parseMemInfo read fields[1] before checking the field count, so an empty
or single-field line panicked instead of returning the existing
"Malformed line" error. parseIPVSBackendStatus evaluated fields[1] for
any line whose first field is not IP or Prot, panicking on single-field
lines. The cpufreq trans_table parser indexed fields[0] on lines made only
of whitespace.

Check the field count before indexing in all three places.

Signed-off-by: Guillaume Marty <yomgui12@outlook.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant