Commit 70dc6bf
authored
fix(spanner): catch recursion and decode errors in proto parsing to p… (#16561)
This PR fixes a Persistent Stored Denial of Service (DoS) vulnerability
in the google-cloud-spanner Python SDK (Issue 479858035).
**The Problem**
When the SDK attempts to deserialize a Protobuf-encoded row (via
_parse_proto() in _helpers.py) that contains a maliciously crafted
"recursion bomb" (e.g., a ListValue nested 1,000+ times), it triggers a
DecodeError or RecursionError. This unhandled exception crashes the
consumer thread and blocks the entire result set stream ("pipeline
blackhole").
**The Solution**
We modify _parse_proto to wrap the ParseFromString() call in a defensive
try...except block:
Catch RecursionError (triggered if Python hits its stack limit first in
pure Python implementations).
Catch google.protobuf.message.DecodeError (triggered by the C++
extension's internal limits).
If an error is caught: A warning is logged. The original raw bytes_value
is returned as a fallback (consistent with existing behavior when no
prototype is found). This allows the stream iterator to continue
processing subsequent rows.1 parent c5728b2 commit 70dc6bfCopy full SHA for 70dc6bf
2 files changed
+64-5Lines changed: 64 additions & 5 deletions
File tree
Expand file treeCollapse file tree
Open diff view settings
Filter options
- packages/google-cloud-spanner
- google/cloud/spanner_v1
- tests/unit
Expand file treeCollapse file tree
Open diff view settings
Collapse file
packages/google-cloud-spanner/google/cloud/spanner_v1/_helpers.py
Copy file name to clipboardExpand all lines: packages/google-cloud-spanner/google/cloud/spanner_v1/_helpers.py+11-5Lines changed: 11 additions & 5 deletions
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| ||
28 | 28 | |
29 | 29 | |
30 | 30 | |
31 | | - |
| 31 | + |
32 | 32 | |
33 | 33 | |
34 | 34 | |
| ||
76 | 76 | |
77 | 77 | |
78 | 78 | |
79 | | - |
| 79 | + |
80 | 80 | |
81 | 81 | |
82 | 82 | |
| ||
122 | 122 | |
123 | 123 | |
124 | 124 | |
125 | | - |
| 125 | + |
126 | 126 | |
127 | 127 | |
128 | 128 | |
| ||
603 | 603 | |
604 | 604 | |
605 | 605 | |
606 | | - |
607 | | - |
| 606 | + |
| 607 | + |
| 608 | + |
| 609 | + |
| 610 | + |
| 611 | + |
| 612 | + |
| 613 | + |
608 | 614 | |
609 | 615 | |
610 | 616 | |
|
Collapse file
packages/google-cloud-spanner/tests/unit/test__helpers.py
Copy file name to clipboardExpand all lines: packages/google-cloud-spanner/tests/unit/test__helpers.py+53Lines changed: 53 additions & 0 deletions
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| ||
771 | 771 | |
772 | 772 | |
773 | 773 | |
| 774 | + |
| 775 | + |
| 776 | + |
| 777 | + |
| 778 | + |
| 779 | + |
| 780 | + |
| 781 | + |
| 782 | + |
| 783 | + |
| 784 | + |
| 785 | + |
| 786 | + |
| 787 | + |
| 788 | + |
| 789 | + |
| 790 | + |
| 791 | + |
| 792 | + |
| 793 | + |
| 794 | + |
| 795 | + |
| 796 | + |
| 797 | + |
| 798 | + |
| 799 | + |
| 800 | + |
| 801 | + |
| 802 | + |
| 803 | + |
| 804 | + |
| 805 | + |
| 806 | + |
| 807 | + |
| 808 | + |
| 809 | + |
| 810 | + |
| 811 | + |
| 812 | + |
| 813 | + |
| 814 | + |
| 815 | + |
| 816 | + |
| 817 | + |
| 818 | + |
| 819 | + |
| 820 | + |
| 821 | + |
| 822 | + |
| 823 | + |
| 824 | + |
| 825 | + |
| 826 | + |
774 | 827 | |
775 | 828 | |
776 | 829 | |
|
0 commit comments