Bug fixes: composite PK, nl_to_sql sandbox, FK check, SQL injection, storage correctness
Critical fixes: - Composite PK: execInsert + validateConstraints use all PK columns - nl_to_sql: non-SELECT SQL no longer executed directly during validation - FK check: removed O(N) scanMemTable fallback, uses db.get() with SSTables - exprToSql: nkIdent wrapped in quotes to prevent SQL injection - restoreSchema: try/except around tokenize/parse for crash resilience - recovery.nim: lastTxnId tracking + putUnsafe/deleteUnsafe without WAL - SCRAM: verifyClientProof length check + DefaultIterationCount restored Storage fixes: - lsm.nim: SSTable sort order fixed (ascending), close() flushes all memtables - compaction.nim: tombstones preserved during compaction - wal.nim: header written for empty existing files, readEntries checks magic - btree.nim: B+ tree leaf split keeps boundary key - bloom.nim: deserialize raises on short data - mmap.nim: bounds checks for adviseWillNeed/DontNeed + posix.close() Protocol fixes: - zerocopy.nim: readString bounds check - wire.nim: deserializeValue 32-bit underflow check - auth.nim: JWT JSON escaping for claims - server.nim: readUint32BE bounds check + specific exception handling - raft.nim: readData checks + specific exception handling Tests: - Added Composite Primary Key test suite (4 tests) Build: 0 warnings, 0 errors
This commit is contained in:
@@ -124,9 +124,10 @@ proc loadState(node: RaftNode) =
|
||||
let dataLen = int(s.readUint32())
|
||||
var data = newSeq[byte](dataLen)
|
||||
if dataLen > 0:
|
||||
discard s.readData(addr data[0], dataLen)
|
||||
if s.readData(addr data[0], dataLen) != dataLen:
|
||||
raise newException(IOError, "Incomplete Raft log data read")
|
||||
node.log[i] = LogEntry(term: term, index: index, command: cmd, data: data)
|
||||
except:
|
||||
except IOError, OSError:
|
||||
discard
|
||||
s.close()
|
||||
|
||||
@@ -431,7 +432,8 @@ proc readString(s: Stream): string =
|
||||
let len = int(s.readUint32())
|
||||
if len > 0:
|
||||
result = newString(len)
|
||||
discard s.readData(result[0].addr, len)
|
||||
if s.readData(result[0].addr, len) != len:
|
||||
raise newException(IOError, "Incomplete string read from stream")
|
||||
else:
|
||||
result = ""
|
||||
|
||||
|
||||
Reference in New Issue
Block a user