Repository navigation
Validate NUL-termination of flexible-array Buffer in interop messages - #40402
Merged
Ben Hillis (benhillis) merged 2 commits intoMay 4, 2026
Merged
Conversation
Use string::FromMessageBuffer<T>() instead of directly accessing the Buffer[] flexible-array member in interop message structs. FromMessageBuffer validates that a NUL terminator exists within the span bounds, preventing out-of-bounds reads when a malformed message contains no Buffer data or lacks NUL termination. Affected message handlers: - LxInitMessageQueryEnvironmentVariable (config.cpp) - LxInitMessageCreateLoginSession (config.cpp) - LxMiniInitMessageUnmount (main.cpp) Co-authored-by: Copilot <[email protected]>
Contributor
There was a problem hiding this comment.
Pull request overview
This PR hardens Linux-side interop message handling by switching flexible-array Buffer[] string access over to wsl::shared::string::FromMessageBuffer<T>(), which validates that a NUL terminator exists within the received span and avoids potential out-of-bounds reads on malformed messages.
Changes:
- Use
FromMessageBuffer<T>(...)forLX_INIT_QUERY_ENVIRONMENT_VARIABLEandLX_INIT_CREATE_LOGIN_SESSIONbuffer parsing inconfig.cpp. - Use
FromMessageBuffer<T>(...)forLX_MINI_INIT_UNMOUNT_MESSAGEmount target parsing inmain.cpp. - Use
FromMessageBuffer<T>(...)forWSLC_UNMOUNTpath parsing inWSLCInit.cpp.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| src/linux/init/WSLCInit.cpp | Use FromMessageBuffer for WSLC_UNMOUNT path to ensure bounded, NUL-terminated parsing. |
| src/linux/init/main.cpp | Use FromMessageBuffer for unmount target name parsing in mini_init unmount flow. |
| src/linux/init/config.cpp | Use FromMessageBuffer for environment-variable query and login-session username parsing. |
Ben Hillis (benhillis)
force-pushed
the
user/benhill/message_buffer_access
branch
from
May 4, 2026 17:54
965ea52 to
31b15d6
Compare
After switching to FromMessageBuffer, the Message parameter is no longer referenced directly. Remove the name to avoid -Wunused-parameter. Co-authored-by: Copilot <[email protected]>
Ben Hillis (benhillis)
force-pushed
the
user/benhill/message_buffer_access
branch
from
May 4, 2026 18:05
31b15d6 to
fc16b59
Compare
Blue (OneBlue)
approved these changes
May 4, 2026
Ben Hillis (benhillis)
added a commit
that referenced
this pull request
Sep 10, 2026
* Validate NUL-termination of flexible-array Buffer in interop messages (#40402) * Validate NUL-termination of flexible-array Buffer in interop messages Use string::FromMessageBuffer<T>() instead of directly accessing the Buffer[] flexible-array member in interop message structs. FromMessageBuffer validates that a NUL terminator exists within the span bounds, preventing out-of-bounds reads when a malformed message contains no Buffer data or lacks NUL termination. Affected message handlers: - LxInitMessageQueryEnvironmentVariable (config.cpp) - LxInitMessageCreateLoginSession (config.cpp) - LxMiniInitMessageUnmount (main.cpp) Co-authored-by: Copilot <[email protected]> * Remove unused Message parameter name in WSLC_UNMOUNT handler After switching to FromMessageBuffer, the Message parameter is no longer referenced directly. Remove the name to avoid -Wunused-parameter. Co-authored-by: Copilot <[email protected]> --------- Co-authored-by: Ben Hillis <[email protected]> Co-authored-by: Copilot <[email protected]> (cherry picked from commit 909d5eb) * Bind KdRelay to loopback (#41260) Restrict the KdRelay listener to local connections. Co-authored-by: Copilot <[email protected]> Co-authored-by: Ben Hillis <[email protected]> Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a (cherry picked from commit 5eb2138) * Update Microsoft.NETCore.App.Runtime to 10.0.11 (#41332) (cherry picked from commit 8edd976) * Fix unvalidated TerminalProfileSize during distribution import (#41495) * Fix unvalidated TerminalProfileSize when importing a distribution _ProcessImportResultMessage constructed the terminal profile string_view using the message-supplied TerminalProfileSize without validating it against the received buffer length. Use the bounds-checked two-argument span::subspan() overload (matching the existing ShortcutIconSize handling a few lines above) so an inconsistent size value throws instead of producing a string_view that runs past the end of the buffer. Co-authored-by: Copilot <[email protected]> Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5 * format source --------- Co-authored-by: Ben Hillis <[email protected]> Co-authored-by: Copilot <[email protected]> Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5 (cherry picked from commit f2d87e0) * Avoid stop service race window during uninstall (#40625) Disable service before stopping service during uninstall. (cherry picked from commit c28bd15) --------- Co-authored-by: Ben Hillis <[email protected]> Co-authored-by: Copilot <[email protected]> Co-authored-by: Blue <[email protected]> Co-authored-by: Feng Wang <[email protected]> Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Use
string::FromMessageBuffer<T>()instead of directly accessing theBuffer[]flexible-array member in interop message structs.FromMessageBuffervalidates that a NUL terminator exists within the span bounds, preventing out-of-bounds reads when a malformed message contains no Buffer data or lacks NUL termination.Affected message handlers:
LxInitMessageQueryEnvironmentVariable(config.cpp)LxInitMessageCreateLoginSession(config.cpp)LxMiniInitMessageUnmount(main.cpp)WSLC_UNMOUNT(WSLCInit.cpp)