fix(bpv7): the extension editor refuses what the parser rejects - #753
Open
ricktaylor wants to merge 1 commit into
Open
ricktaylor wants to merge 1 commit into
ricktaylor wants to merge 1 commit into
Conversation
`ExtensionEditor::insert` passed flags, CRC type and block bodies through unchecked, so an edit could be accepted at call time and then fail at `finish()` or produce bytes the parser rejects: a `report_on_failure` flag on an administrative-record or null-source bundle (RFC 9171 §4.2.3-4/-5), an unrecognised CRC type, or a Previous Node / Bundle Age / Hop Count body that does not decode. Each is now refused at call time as `Error::Invalid`, carrying the error the parser raises for it (`InvalidFlags`, `InvalidCrc`, or the body's own decode error); `replace` validates well-known bodies too. The RFC rule gets one statement, `PrimaryBlock::forbids_report_on_failure`, which the parser's block check now consults. `Builder::build` emitted bundles its own parser rejects: `with_hop_count` sets `report_on_failure`, so any null-source or admin-record bundle with a hop limit was unparseable. `build()` now clears the flag on every block of such a bundle, normalised like the fragment flag. Found by the external review of #712 (CRIT-1, HIGH-2, MED-3): the BPA's filter editor mirrors this one, and a Rewriter tripping the gap aborts the node. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Rick Taylor <rtaylor@aalyria.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ExtensionEditorcould accept an edit at call time that then failed atfinish(), or that produced bytes the bpv7 parser rejects. This PR makes the editor refuse those edits up front, with the parser's own error. It also fixesBuilder::build, which could produce bundles its own parser rejects.The gaps came out of the external review of #712. The BPA's filter editor mirrors
ExtensionEditor, and a Rewriter that hits one of these gaps aborts the node under the Rewriter fail-stop rule, so they need closing in bpv7 first. #712 and the rest of the train are rebased onto this branch.Changes
ExtensionEditorrefusals.insertnow refuses, asextension_editor::Error::Invalidcarrying the error the parser raises for the same input:report_on_failureflag on an administrative-record or null-source bundle (RFC 9171 §4.2.3-4/-5):InvalidFlags;InvalidCrc;replacealso checks well-known bodies. There's one new variant wrappingcrate::Error, rather than duplicates of errors the crate already has.One statement of the RFC rule.
PrimaryBlock::forbids_report_on_failure()is the single place RFC 9171 §4.2.3-4/-5 is written. The parser's block check and the editor's refusal both use it.Builder::buildfix.with_hop_countsetsreport_on_failure, so any null-source or admin-record bundle with a hop limit failed to parse.build()now clears the flag on every block of such a bundle, the same way it normalises the fragment flag.Docs. The CHANGELOG has entries under Added (the refusals, the predicate) and Fixed (the builder). The TODO has a new entry for a fuzz target that pins the invariant: for every parseable bundle and every
ExtensionEditoroperation sequence, iffinish()succeeds, the flattened result parses. The refusal list is kept in step with the parser by hand, so a future parser rule could reopen the gap.API impact
ExtensionEditoris unreleased (listed under Unreleased → Added), so the newError::Invalidvariant breaks no released API.PrimaryBlock::forbids_report_on_failure()is a new public method. Callers ofBuilderthat relied on the forbidden flag being emitted were producing bundles the parser rejects.Tests
New tests in
bpv7/tests/editor.rsandbpv7/tests/parse.rs:insertand onreplace;report_on_failureand round-trips throughparse.Each refusal test asserts the specific wrapped parser error, not just
is_err().Verification
Run locally:
cargo fmt --check, workspacecargo clippy --all-targets --all-features -- -D warnings, andcargo test --workspace --all-features. The only failures are environment-only: the storage-harness Postgres/S3 suites (no services here) and tcpclv4[::1](no IPv6). The no-std thumb build pair runs in CI only, and this PR needs it green.Merge order
This merges first, then #712, #717, #718, #719 and #752. Until it merges, #712's diff also shows this commit.
🤖 Generated with Claude Code