A corrupt remote cache entry can crash `vp run`
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
调研方向
Start at the remote cache read path used by vp run, following the context from issue #756, and inspect how the duration's seconds and nanoseconds are decoded. Done means malformed or overflowing duration fields produce a cache miss rather than a panic; run the relevant remote-cache checks if available.
由索引模型根据 Issue 内容生成。
描述
A cache entry stores the task's duration as seconds plus nanoseconds. When decoding an entry, vp run builds the duration without checking those fields, and values that overflow make it panic. Release builds abort on panic, so one corrupt or malicious entry in the remote cache kills the whole run instead of being treated as a miss.
Expected: an entry that doesn't decode is a cache miss, like other corrupt remote entries.
Affects remote cache reads (#756).
- 主要语言
- Rust
- 星标
- 468
- 派生
- 42
- 平均合并
- 1 天 18 小时
- 30 天内合并 PR
- 46
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
voidzero-dev/vite-task 的其他 Issue
-
vp run: output forwarding fails with EAGAIN when an inherited Node child sets stdout non-blocking未关闭
难度 4/5 3-5 天 新手友好度 48/100
voidzero-dev/vite-task#782 · 1 条评论 ·
维护者通常 1 天内回复
-
remote cache
难度 5/5 一周以上 新手友好度 35/100
voidzero-dev/vite-task#781 ·
维护者通常 1 天内回复
-
remote cache
难度 4/5 3-5 天 新手友好度 55/100
voidzero-dev/vite-task#779 ·
维护者通常 1 天内回复
-
remote cache
难度 5/5 一周以上 新手友好度 35/100
voidzero-dev/vite-task#778 ·
维护者通常 1 天内回复
-
fspy misses Bun file reads on Linux (glibc), so cached tasks replay stale output可能已有人在做 @wan9chi 于 2 天前认领。 未关闭fspy
voidzero-dev/vite-task#777 · 1 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
查看 voidzero-dev/vite-task 的全部 Issue
相似的 Issue
-
Change output crossing a compactsize boundary leaves the fee slightly below the requested feerate未关闭bug
难度 2/5 1-3 小时 新手友好度 78/100
bitcoindevkit/bdk_wallet#578 ·
维护者通常 8 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
521xueweihan/HelloGitHub#3832 ·
-
难度 2/5 1-3 小时 新手友好度 84/100
-
难度 2/5 1-3 小时 新手友好度 82/100
canonical/opentelemetry-collector-operator#409 ·
维护者通常 1 天内回复