Skip to content

Validation pass #874

Description

@philipc

If we wanted to enable object to be used with untrusted inputs, the simplest approach I can think of is to add an optional validation pass. This would use the low level API to traverse the data structures in the file (similar to what the readobj example does) and do two things:

  • inspect fields for invalid values
  • measure the work done, and exit when it is out of proportion with the size of the file. Ideally the limit on work would be at most O(n log n). This would require some care to ensure we are not neglecting to measure some work (e.g. cost of reading a null terminated string or performing a lookup in a collection).

For this to be useful, the validation pass must be exhaustive, which is hard.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions