Overruning write by sccanf
Nobody has claimed this yet.
- Dominant language
- C
- Stars
- 732
- Forks
- 67
- PR merge metrics
- No merged PRs in 30d
Description
In the following sscanf calls, '%64s' requires 65 bytes.
https://github.com/vmware/splinterdb/blob/6a2348c0eb9887cdafee3dad674a96e41edddb28/tests/functional/ycsb_test.c#L584
https://github.com/vmware/splinterdb/blob/6a2348c0eb9887cdafee3dad674a96e41edddb28/tests/functional/ycsb_test.c#L598-L602
But the length of result[i].key is only 24 bytes.
https://github.com/vmware/splinterdb/blob/6a2348c0eb9887cdafee3dad674a96e41edddb28/tests/functional/ycsb_test.c#L244-L246
https://github.com/vmware/splinterdb/blob/6a2348c0eb9887cdafee3dad674a96e41edddb28/tests/functional/ycsb_test.c#L17
Please either modify the sscanf format specifier, or make YCSB_KEY_SIZE larger.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in tests/functional/ycsb_test.c at the sscanf calls around lines 584 and 598-602, then inspect the result[i].key definition around lines 244-246 and the YCSB_KEY_SIZE definition near line 17. Confirm the buffer-size mismatch and update the format or size so the calls cannot overrun the destination; run the relevant functional YCSB tests to verify they still pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c
- Domain
- testing
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 58/100