Files
filament/libs/uberz/tests/test_ReadableArchive.cpp
Mathias Agopian e6e7c0325e uberz: Fix vulnerabilities in convertOffsetsToPointers without aborts
- Implement fixes inspired by PR #9853 to make convertOffsetsToPointers
  size-aware and prevent OOB reads and writes.
- Change function signature to return bool instead of void, allowing graceful
  error propagation instead of runtime aborts.
- Replace FILAMENT_CHECK_PRECONDITION with explicit checks that log errors
  and return false.
- Update ArchiveCache in gltfio and main in tools/uberz to handle failure.
- Add unit tests to verify rejection of invalid offsets.
2026-04-16 09:10:08 -07:00

71 lines
2.2 KiB
C++

/*
* Copyright (C) 2026 The Android Open Source Project
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
#include <uberz/ReadableArchive.h>
#include <gtest/gtest.h>
#include <array>
#include <string>
using filament::uberz::ArchiveFeature;
using filament::uberz::ArchiveFlag;
using filament::uberz::ArchiveSpec;
using filament::uberz::ReadableArchive;
using filament::uberz::convertOffsetsToPointers;
namespace {
TEST(ReadableArchiveTest, RejectsSpecsOffsetOutsideBuffer) {
alignas(8) std::array<uint8_t, 64> storage {};
auto* archive = reinterpret_cast<ReadableArchive*>(storage.data());
archive->magic = 'UBER';
archive->version = 0;
archive->specsCount = 1;
archive->specsOffset = storage.size();
EXPECT_FALSE(convertOffsetsToPointers(archive, storage.size()));
}
TEST(ReadableArchiveTest, RejectsFlagNamesOutsideBuffer) {
alignas(8) std::array<uint8_t, 96> storage {};
auto* archive = reinterpret_cast<ReadableArchive*>(storage.data());
archive->magic = 'UBER';
archive->version = 0;
archive->specsCount = 1;
archive->specsOffset = sizeof(ReadableArchive);
auto* spec = reinterpret_cast<ArchiveSpec*>(storage.data() + archive->specsOffset);
*spec = {};
spec->flagsCount = 1;
spec->flagsOffset = archive->specsOffset + sizeof(ArchiveSpec);
spec->packageOffset = storage.size() - 1;
auto* flag = reinterpret_cast<ArchiveFlag*>(storage.data() + spec->flagsOffset);
flag->nameOffset = storage.size();
flag->value = ArchiveFeature::OPTIONAL;
EXPECT_FALSE(convertOffsetsToPointers(archive, storage.size()));
}
} // namespace
int main(int argc, char** argv) {
::testing::InitGoogleTest(&argc, argv);
return RUN_ALL_TESTS();
}