Repository navigation
fix: neutralize control characters in lcov report fields - #2226
Conversation
|
gentle ping |
|
TBH, this seems like a very unlikely scenario, and isn't a security concern. A file name with a newline will likely cause havoc in many places. A broken .lcov file seems like the least of their worries, and will only cause troubles for themselves. Unless you have a more compelling argument, I am inclined to close this. |
|
No argument on the security framing, and newline filenames are certainly rare. The case I'd make is the one devdanzin raised: after dd80635 and e06eb34, lcov is the only writer left that can produce output its own format can't represent, and the failure can be silent since the spilled name reads back as extra SF/LH records with bogus totals rather than a parse error. The guard is a few lines at the write sites and leaves all valid output byte-identical. If that still doesn't clear the bar, no objection to closing it. |
|
OK, rebase onto main, and we can get it merged. |
930fb65 to
45eb03d
Compare
|
Rebased onto main. Only fixup needed was re-placing the changelog entry in the current Unreleased section, since the old one has since shipped. Code and test are unchanged, and the lcov tests pass locally. |
|
This is now released as part of coverage 7.15.4. |
The lcov writer drops file names and the function and branch fields straight into its newline-delimited records with no escaping, unlike the html, markdown, xml, and json reports which each neutralize untrusted values. A source file whose name contains a newline (legal on POSIX, and reachable whenever coverage measures a tree you don't fully control) spills past the
SF:line and forges its ownSF/DA/LHrecords, so a downstream reader like genhtml or a CI coverage gate sees fabricated files and inflated hit counts.lcov_fieldreplaces control characters in each field right before it's written, keeping the value on one line while leaving normal names (printable, including non-ASCII) untouched. Keeping the guard at the write sites covers every field the format treats as free text in one spot, with no change to valid output. The added test measures a file whose name embeds a fake record and checks the report stays a singleSFrecord.