Skip to content

Validate NUL-termination of flexible-array Buffer in interop messages - #40402

Merged
Ben Hillis (benhillis) merged 2 commits into
masterfrom
user/benhill/message_buffer_access
May 4, 2026
Merged

Ben Hillis (benhillis) merged 2 commits into
masterfrom
user/benhill/message_buffer_access

Conversation

@benhillis

Copy link
Copy Markdown
Member

Use string::FromMessageBuffer<T>() instead of directly accessing the Buffer[] flexible-array member in interop message structs. FromMessageBuffer validates that a NUL terminator exists within the span bounds, preventing out-of-bounds reads when a malformed message contains no Buffer data or lacks NUL termination.

Affected message handlers:

  • LxInitMessageQueryEnvironmentVariable (config.cpp)
  • LxInitMessageCreateLoginSession (config.cpp)
  • LxMiniInitMessageUnmount (main.cpp)
  • WSLC_UNMOUNT (WSLCInit.cpp)

Use string::FromMessageBuffer<T>() instead of directly accessing the
Buffer[] flexible-array member in interop message structs. FromMessageBuffer
validates that a NUL terminator exists within the span bounds, preventing
out-of-bounds reads when a malformed message contains no Buffer data or
lacks NUL termination.

Affected message handlers:
- LxInitMessageQueryEnvironmentVariable (config.cpp)
- LxInitMessageCreateLoginSession (config.cpp)
- LxMiniInitMessageUnmount (main.cpp)

Co-authored-by: Copilot <[email protected]>
@benhillis
Ben Hillis (benhillis) requested a review from a team as a code owner May 4, 2026 16:07
Copilot AI review requested due to automatic review settings May 4, 2026 16:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens Linux-side interop message handling by switching flexible-array Buffer[] string access over to wsl::shared::string::FromMessageBuffer<T>(), which validates that a NUL terminator exists within the received span and avoids potential out-of-bounds reads on malformed messages.

Changes:

  • Use FromMessageBuffer<T>(...) for LX_INIT_QUERY_ENVIRONMENT_VARIABLE and LX_INIT_CREATE_LOGIN_SESSION buffer parsing in config.cpp.
  • Use FromMessageBuffer<T>(...) for LX_MINI_INIT_UNMOUNT_MESSAGE mount target parsing in main.cpp.
  • Use FromMessageBuffer<T>(...) for WSLC_UNMOUNT path parsing in WSLCInit.cpp.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
src/linux/init/WSLCInit.cpp Use FromMessageBuffer for WSLC_UNMOUNT path to ensure bounded, NUL-terminated parsing.
src/linux/init/main.cpp Use FromMessageBuffer for unmount target name parsing in mini_init unmount flow.
src/linux/init/config.cpp Use FromMessageBuffer for environment-variable query and login-session username parsing.

Comment thread src/linux/init/WSLCInit.cpp Outdated
Copilot AI review requested due to automatic review settings May 4, 2026 17:54
@benhillis
Ben Hillis (benhillis) force-pushed the user/benhill/message_buffer_access branch from 965ea52 to 31b15d6 Compare May 4, 2026 17:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

Comment thread src/linux/init/config.cpp
Comment thread src/linux/init/config.cpp
After switching to FromMessageBuffer, the Message parameter is no longer
referenced directly. Remove the name to avoid -Wunused-parameter.

Co-authored-by: Copilot <[email protected]>
@benhillis
Ben Hillis (benhillis) merged commit 909d5eb into master May 4, 2026
10 checks passed
@benhillis
Ben Hillis (benhillis) deleted the user/benhill/message_buffer_access branch May 4, 2026 20:02
Ben Hillis (benhillis) added a commit that referenced this pull request Sep 10, 2026
* Validate NUL-termination of flexible-array Buffer in interop messages (#40402)

* Validate NUL-termination of flexible-array Buffer in interop messages

Use string::FromMessageBuffer<T>() instead of directly accessing the
Buffer[] flexible-array member in interop message structs. FromMessageBuffer
validates that a NUL terminator exists within the span bounds, preventing
out-of-bounds reads when a malformed message contains no Buffer data or
lacks NUL termination.

Affected message handlers:
- LxInitMessageQueryEnvironmentVariable (config.cpp)
- LxInitMessageCreateLoginSession (config.cpp)
- LxMiniInitMessageUnmount (main.cpp)

Co-authored-by: Copilot <[email protected]>

* Remove unused Message parameter name in WSLC_UNMOUNT handler

After switching to FromMessageBuffer, the Message parameter is no longer
referenced directly. Remove the name to avoid -Wunused-parameter.

Co-authored-by: Copilot <[email protected]>

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
(cherry picked from commit 909d5eb)

* Bind KdRelay to loopback (#41260)

Restrict the KdRelay listener to local connections.

Co-authored-by: Copilot <[email protected]>

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a
(cherry picked from commit 5eb2138)

* Update Microsoft.NETCore.App.Runtime to 10.0.11 (#41332)

(cherry picked from commit 8edd976)

* Fix unvalidated TerminalProfileSize during distribution import (#41495)

* Fix unvalidated TerminalProfileSize when importing a distribution

_ProcessImportResultMessage constructed the terminal profile string_view
using the message-supplied TerminalProfileSize without validating it
against the received buffer length. Use the bounds-checked two-argument
span::subspan() overload (matching the existing ShortcutIconSize handling
a few lines above) so an inconsistent size value throws instead of
producing a string_view that runs past the end of the buffer.

Co-authored-by: Copilot <[email protected]>
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5

* format source

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5
(cherry picked from commit f2d87e0)

* Avoid stop service race window during uninstall (#40625)

Disable service before stopping service during uninstall.

(cherry picked from commit c28bd15)

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Co-authored-by: Blue <[email protected]>
Co-authored-by: Feng Wang <[email protected]>
Copilot-Session: d9d1a097-a7bc-4c1b-806b-d3778adfd23a
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants