Truncate RPC error text on a UTF-8 boundary - #1018
RaphaelFakhri wants to merge 2 commits into
Conversation
| for end > 0 && !utf8.RuneStart(str[end]) { | ||
| end-- | ||
| } | ||
| return str[:end] |
There was a problem hiding this comment.
🟡 Truncated errors retain discarded payloads
When NewRpcError receives an oversized string, truncateBytes keeps its entire backing allocation through the returned substring. Retained errors therefore keep discarded message or data bytes in memory.
| return str[:end] | |
| return strings.Clone(str[:end]) |
Was this helpful? React with 👍 or 👎 to provide feedback.
Truncated errors retain discarded payloadsValid finding, fixed in the new commit. Malformed error text still blocks responsesValid finding, fixed in the same commit. notify-devs checkThe failure is unrelated to the change. The job fails in the |
Fixes #1017
Summary
truncateBytescuts strings at a byte offset. When the offset falls inside a multi-byte UTF-8 character,NewRpcErrorproduces an invalid string, andproto.Marshalfails withstring field contains invalid UTF-8when the error is sent.This change backs the cut point up to the start of the character, so the result is valid UTF-8 and never exceeds the byte limit.
Testing
TestTruncateBytescovering ASCII, exact-fit, and cuts inside 2-, 3-, and 4-byte characters.TestNewRpcErrorTruncatesToValidUTF8, which marshals the truncated error.mainand pass with this change.