mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-26 01:44:48 +00:00
* fix(volume): reject negative sizes in ReadNeedleBlob and WriteNeedleBlob A ReadNeedleBlob RPC with a size of -44 or below (-36 on v2 volumes) panics in makeslice inside needle.ReadNeedleBlob. The volume gRPC server has no recovery interceptor, so one request kills the process. Smaller negative sizes return bytes that are not a record. WriteNeedleBlob accepted a negative size whenever the blob header carried the same value: it appended the blob to .dat and indexed the needle with that size, which reads as deleted. Reject size < 0 in both Volume methods. Size 0 still passes, since delete records carry it. The Rust volume server got the same storage guards in #11345. * fix(volume): reject needle blobs whose length does not match their size WriteNeedleBlob appends the blob as is. A blob that is not the length its size implies leaves .dat off the 8-byte grid, and every later ordinary write to the volume is indexed at a truncated offset and reads back as EOF. A blob off by 8 bytes keeps the grid but leaves bytes that a .dat scan reads as the next record. The in-tree callers already send exact lengths. The one case this newly refuses is a copy between volumes of different needle versions, and that case already writes a broken record: a v3 record lands on a v2 volume with 8 extra bytes, and a v2 record on a v3 volume either fails the timestamp check or lands 8 bytes short. This is separate from the negative-size guards, whose Rust counterpart is #11345. The Rust server does not check the length yet. * fix(volume): guard the blob buffer allocation in needle.ReadNeedleBlob Volume.ReadNeedleBlob rejected negative sizes, but needle.ReadNeedleBlob still sized its buffer from the size and is called directly by vacuum and other paths. Reject a deletion marker before make() there too, and use size.IsDeleted() in the volume-level checks. * fix(volume): mirror the blob length check in the rust volume server write_needle_blob_and_index checked the size against the blob header but appended the blob verbatim, so a blob that is not the length its size implies still leaves .dat off the record grid. Match the Go check. --------- Co-authored-by: Chris Lu <chris.lu@gmail.com>
304 lines
9.5 KiB
Go
304 lines
9.5 KiB
Go
package needle
|
|
|
|
import (
|
|
"errors"
|
|
"fmt"
|
|
"io"
|
|
|
|
"github.com/seaweedfs/seaweedfs/weed/glog"
|
|
"github.com/seaweedfs/seaweedfs/weed/stats"
|
|
"github.com/seaweedfs/seaweedfs/weed/storage/backend"
|
|
. "github.com/seaweedfs/seaweedfs/weed/storage/types"
|
|
"github.com/seaweedfs/seaweedfs/weed/util"
|
|
)
|
|
|
|
const (
|
|
FlagIsCompressed = 0x01
|
|
FlagHasName = 0x02
|
|
FlagHasMime = 0x04
|
|
FlagHasLastModifiedDate = 0x08
|
|
FlagHasTtl = 0x10
|
|
FlagHasPairs = 0x20
|
|
FlagIsChunkManifest = 0x80
|
|
LastModifiedBytesLength = 5
|
|
TtlBytesLength = 2
|
|
)
|
|
|
|
var ErrorSizeMismatch = errors.New("size mismatch")
|
|
var ErrorSizeInvalid = errors.New("size invalid")
|
|
|
|
// ErrorCorrupted marks a needle whose on-disk bytes cannot be parsed because
|
|
// of data corruption: bad CRC, malformed v2/v3/v4 headers, or out-of-range
|
|
// fields. Wrap errors with %w so callers (e.g. vacuum compaction) can
|
|
// distinguish "the bytes are bad" from a genuine I/O fault.
|
|
var ErrorCorrupted = errors.New("needle data corrupted")
|
|
|
|
func (n *Needle) DiskSize(version Version) int64 {
|
|
return GetActualSize(n.Size, version)
|
|
}
|
|
|
|
func ReadNeedleBlob(r backend.BackendStorageFile, offset int64, size Size, version Version) (dataSlice []byte, err error) {
|
|
|
|
if size.IsDeleted() {
|
|
return nil, fmt.Errorf("invalid needle size %d: %w", size, ErrorSizeInvalid)
|
|
}
|
|
dataSize := GetActualSize(size, version)
|
|
dataSlice = make([]byte, int(dataSize))
|
|
|
|
var n int
|
|
n, err = r.ReadAt(dataSlice, offset)
|
|
if err != nil && int64(n) == dataSize {
|
|
err = nil
|
|
}
|
|
if err != nil {
|
|
fileSize, _, _ := r.GetStat()
|
|
glog.Errorf("%s read %d dataSize %d offset %d fileSize %d: %v", r.Name(), n, dataSize, offset, fileSize, err)
|
|
}
|
|
return dataSlice, err
|
|
|
|
}
|
|
|
|
// ReadBytes hydrates the needle from the bytes buffer, with only n.Id is set.
|
|
func (n *Needle) ReadBytes(bytes []byte, offset int64, size Size, version Version) (err error) {
|
|
n.ParseNeedleHeader(bytes)
|
|
if n.Size != size {
|
|
if OffsetSize == 4 && offset < int64(MaxPossibleVolumeSize) {
|
|
stats.VolumeServerHandlerCounter.WithLabelValues(stats.ErrorSizeMismatchOffsetSize).Inc()
|
|
return ErrorSizeMismatch
|
|
}
|
|
stats.VolumeServerHandlerCounter.WithLabelValues(stats.ErrorSizeMismatch).Inc()
|
|
return fmt.Errorf("%w: entry not found: offset %d found id %x size %d, expected size %d", ErrorSizeMismatch, offset, n.Id, n.Size, size)
|
|
}
|
|
if version == Version1 {
|
|
n.Data = bytes[NeedleHeaderSize : NeedleHeaderSize+size]
|
|
} else {
|
|
err := n.readNeedleDataVersion2(bytes[NeedleHeaderSize : NeedleHeaderSize+int(size)])
|
|
if err != nil && err != io.EOF {
|
|
return err
|
|
}
|
|
}
|
|
err = n.readNeedleTail(bytes[NeedleHeaderSize+size:], version)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// ReadData hydrates the needle from the file, with only n.Id is set.
|
|
func (n *Needle) ReadData(r backend.BackendStorageFile, offset int64, size Size, version Version) (err error) {
|
|
bytes, err := ReadNeedleBlob(r, offset, size, version)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
err = n.ReadBytes(bytes, offset, size, version)
|
|
if err == ErrorSizeMismatch && OffsetSize == 4 {
|
|
offset = offset + int64(MaxPossibleVolumeSize)
|
|
bytes, err = ReadNeedleBlob(r, offset, size, version)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
err = n.ReadBytes(bytes, offset, size, version)
|
|
}
|
|
return err
|
|
}
|
|
|
|
func (n *Needle) ParseNeedleHeader(bytes []byte) {
|
|
n.Cookie = BytesToCookie(bytes[0:CookieSize])
|
|
n.Id = BytesToNeedleId(bytes[CookieSize : CookieSize+NeedleIdSize])
|
|
n.Size = BytesToSize(bytes[CookieSize+NeedleIdSize : NeedleHeaderSize])
|
|
}
|
|
|
|
func (n *Needle) readNeedleDataVersion2(bytes []byte) (err error) {
|
|
index, lenBytes := 0, len(bytes)
|
|
if index < lenBytes {
|
|
n.DataSize = util.BytesToUint32(bytes[index : index+4])
|
|
index = index + 4
|
|
if int(n.DataSize)+index > lenBytes {
|
|
stats.VolumeServerHandlerCounter.WithLabelValues(stats.ErrorIndexOutOfRange).Inc()
|
|
return fmt.Errorf("index out of range %d: %w", 1, ErrorCorrupted)
|
|
}
|
|
n.Data = bytes[index : index+int(n.DataSize)]
|
|
index = index + int(n.DataSize)
|
|
}
|
|
_, err = n.readNeedleDataVersion2NonData(bytes[index:])
|
|
return
|
|
}
|
|
func (n *Needle) readNeedleDataVersion2NonData(bytes []byte) (index int, err error) {
|
|
lenBytes := len(bytes)
|
|
if index < lenBytes {
|
|
n.Flags = bytes[index]
|
|
index = index + 1
|
|
}
|
|
if index < lenBytes && n.HasName() {
|
|
n.NameSize = uint8(bytes[index])
|
|
index = index + 1
|
|
if int(n.NameSize)+index > lenBytes {
|
|
stats.VolumeServerHandlerCounter.WithLabelValues(stats.ErrorIndexOutOfRange).Inc()
|
|
return index, fmt.Errorf("index out of range %d: %w", 2, ErrorCorrupted)
|
|
}
|
|
n.Name = bytes[index : index+int(n.NameSize)]
|
|
index = index + int(n.NameSize)
|
|
}
|
|
if index < lenBytes && n.HasMime() {
|
|
n.MimeSize = uint8(bytes[index])
|
|
index = index + 1
|
|
if int(n.MimeSize)+index > lenBytes {
|
|
stats.VolumeServerHandlerCounter.WithLabelValues(stats.ErrorIndexOutOfRange).Inc()
|
|
return index, fmt.Errorf("index out of range %d: %w", 3, ErrorCorrupted)
|
|
}
|
|
n.Mime = bytes[index : index+int(n.MimeSize)]
|
|
index = index + int(n.MimeSize)
|
|
}
|
|
if index < lenBytes && n.HasLastModifiedDate() {
|
|
if LastModifiedBytesLength+index > lenBytes {
|
|
stats.VolumeServerHandlerCounter.WithLabelValues(stats.ErrorIndexOutOfRange).Inc()
|
|
return index, fmt.Errorf("index out of range %d: %w", 4, ErrorCorrupted)
|
|
}
|
|
n.LastModified = util.BytesToUint64(bytes[index : index+LastModifiedBytesLength])
|
|
index = index + LastModifiedBytesLength
|
|
}
|
|
if index < lenBytes && n.HasTtl() {
|
|
if TtlBytesLength+index > lenBytes {
|
|
stats.VolumeServerHandlerCounter.WithLabelValues(stats.ErrorIndexOutOfRange).Inc()
|
|
return index, fmt.Errorf("index out of range %d: %w", 5, ErrorCorrupted)
|
|
}
|
|
n.Ttl = LoadTTLFromBytes(bytes[index : index+TtlBytesLength])
|
|
index = index + TtlBytesLength
|
|
}
|
|
if index < lenBytes && n.HasPairs() {
|
|
if 2+index > lenBytes {
|
|
stats.VolumeServerHandlerCounter.WithLabelValues(stats.ErrorIndexOutOfRange).Inc()
|
|
return index, fmt.Errorf("index out of range %d: %w", 6, ErrorCorrupted)
|
|
}
|
|
n.PairsSize = util.BytesToUint16(bytes[index : index+2])
|
|
index += 2
|
|
if int(n.PairsSize)+index > lenBytes {
|
|
stats.VolumeServerHandlerCounter.WithLabelValues(stats.ErrorIndexOutOfRange).Inc()
|
|
return index, fmt.Errorf("index out of range %d: %w", 7, ErrorCorrupted)
|
|
}
|
|
end := index + int(n.PairsSize)
|
|
n.Pairs = bytes[index:end]
|
|
index = end
|
|
}
|
|
return index, nil
|
|
}
|
|
|
|
func ReadNeedleHeader(r backend.BackendStorageFile, version Version, offset int64) (n *Needle, bytes []byte, bodyLength int64, err error) {
|
|
n = new(Needle)
|
|
|
|
bytes = make([]byte, NeedleHeaderSize)
|
|
|
|
var count int
|
|
count, err = r.ReadAt(bytes, offset)
|
|
if err == io.EOF && count == NeedleHeaderSize {
|
|
err = nil
|
|
}
|
|
if count <= 0 || err != nil {
|
|
return nil, bytes, 0, err
|
|
}
|
|
|
|
n.ParseNeedleHeader(bytes)
|
|
bodyLength = NeedleBodyLength(n.Size, version)
|
|
|
|
return
|
|
}
|
|
|
|
// n should be a needle already read the header
|
|
// the input stream will read until next file entry
|
|
func (n *Needle) ReadNeedleBody(r backend.BackendStorageFile, version Version, offset int64, bodyLength int64) (bytes []byte, err error) {
|
|
|
|
if bodyLength <= 0 {
|
|
return nil, nil
|
|
}
|
|
bytes = make([]byte, bodyLength)
|
|
readCount, err := r.ReadAt(bytes, offset)
|
|
if err == io.EOF && int64(readCount) == bodyLength {
|
|
err = nil
|
|
}
|
|
if err != nil {
|
|
glog.Errorf("%s read %d bodyLength %d offset %d: %v", r.Name(), readCount, bodyLength, offset, err)
|
|
return
|
|
}
|
|
|
|
err = n.ReadNeedleBodyBytes(bytes, version)
|
|
|
|
return
|
|
}
|
|
|
|
func (n *Needle) ReadNeedleBodyBytes(needleBody []byte, version Version) (err error) {
|
|
|
|
// n.Size comes from the on-disk header, so a corrupted header can carry a
|
|
// negative size or one the body cannot hold along with its tail. Deriving
|
|
// the tail from the version's own layout keeps the bound exact for every
|
|
// on-disk format.
|
|
tailSize := NeedleBodyLength(n.Size, version) - int64(n.Size) - int64(PaddingLength(n.Size, version))
|
|
if n.Size < 0 || int64(n.Size)+tailSize > int64(len(needleBody)) {
|
|
stats.VolumeServerHandlerCounter.WithLabelValues(stats.ErrorIndexOutOfRange).Inc()
|
|
return fmt.Errorf("needle %v size %d out of range for body length %d: %w", n.Id, n.Size, len(needleBody), ErrorCorrupted)
|
|
}
|
|
switch version {
|
|
case Version1:
|
|
n.Data = needleBody[:n.Size]
|
|
err = n.readNeedleTail(needleBody[n.Size:], version)
|
|
case Version2, Version3:
|
|
err = n.readNeedleDataVersion2(needleBody[0:n.Size])
|
|
if err == nil {
|
|
err = n.readNeedleTail(needleBody[n.Size:], version)
|
|
}
|
|
default:
|
|
err = fmt.Errorf("unsupported version %d!", version)
|
|
}
|
|
return
|
|
}
|
|
|
|
func (n *Needle) IsCompressed() bool {
|
|
return n.Flags&FlagIsCompressed > 0
|
|
}
|
|
func (n *Needle) SetIsCompressed() {
|
|
n.Flags = n.Flags | FlagIsCompressed
|
|
}
|
|
func (n *Needle) HasName() bool {
|
|
return n.Flags&FlagHasName > 0
|
|
}
|
|
func (n *Needle) SetHasName() {
|
|
n.Flags = n.Flags | FlagHasName
|
|
}
|
|
func (n *Needle) HasMime() bool {
|
|
return n.Flags&FlagHasMime > 0
|
|
}
|
|
func (n *Needle) SetHasMime() {
|
|
n.Flags = n.Flags | FlagHasMime
|
|
}
|
|
func (n *Needle) HasLastModifiedDate() bool {
|
|
return n.Flags&FlagHasLastModifiedDate > 0
|
|
}
|
|
func (n *Needle) SetHasLastModifiedDate() {
|
|
n.Flags = n.Flags | FlagHasLastModifiedDate
|
|
}
|
|
func (n *Needle) HasTtl() bool {
|
|
return n.Flags&FlagHasTtl > 0
|
|
}
|
|
func (n *Needle) SetHasTtl() {
|
|
n.Flags = n.Flags | FlagHasTtl
|
|
}
|
|
|
|
func (n *Needle) IsChunkedManifest() bool {
|
|
return n.Flags&FlagIsChunkManifest > 0
|
|
}
|
|
|
|
func (n *Needle) SetIsChunkManifest() {
|
|
n.Flags = n.Flags | FlagIsChunkManifest
|
|
}
|
|
|
|
func (n *Needle) HasPairs() bool {
|
|
return n.Flags&FlagHasPairs != 0
|
|
}
|
|
|
|
func (n *Needle) SetHasPairs() {
|
|
n.Flags = n.Flags | FlagHasPairs
|
|
}
|
|
|
|
func GetActualSize(size Size, version Version) int64 {
|
|
return NeedleHeaderSize + NeedleBodyLength(size, version)
|
|
}
|