Conversation
A single Read call may return fewer bytes than requested with a nil error (bufio.Reader at a buffer boundary, pipes, network streams). The rest of the challenge was then left as zeros, the returned byte count was wrong and no error was reported. A truncated stream wasn't reported either. Use io.ReadFull, which reads the whole slice or returns io.ErrUnexpectedEOF.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
io.ReadBytesShortreads the payload with a singlereader.Readcall.io.ReaderallowsReadto return fewer bytes than requested with a nil error, so with a reader that does short reads the rest of the slice stays zero and no error is returned:This happens in practice with
bufio.Readerat a buffer boundary, pipes or network streams. A stream that ends in the middle of the payload isn't reported either. The function is used by the groth16mpcsetupPhase1/Phase2ReadFromon all curves to read the contribution challenge, so a contribution read that way would carry a wrong challenge.The fix uses
io.ReadFull, which keeps reading until the slice is full and returnsio.ErrUnexpectedEOFon a truncated stream.Tests:
TestReadBytesShortPartialReads(one byte perRead) andTestReadBytesShortTruncatedboth fail on master and pass with the change.