ioc: size a DBR_STRING array read by the request stride, not field_size - #206
Closed
physwkim wants to merge 1 commit into
Closed
ioc: size a DBR_STRING array read by the request stride, not field_size#206physwkim wants to merge 1 commit into
physwkim wants to merge 1 commit into
Conversation
getArrayValue sized the read buffer from dbChannelFinalFieldSize, but dbGet writes dbValueSize(final_type) bytes per element — MAX_STRING_SIZE for a DBR_STRING request, regardless of the field's own size — so a DBF_STRING field with field_size < MAX_STRING_SIZE (synApps scalcout PAA..PLL) overflowed the heap. Size by dbValueSize(final_type): unchanged for numeric fields and type-changing filters (dbValueSize == field_size there), MAX_STRING_SIZE for strings.
physwkim
force-pushed
the
fix/qsrv2-dbf-string-array-overflow
branch
from
August 31, 2026 15:02
21cb41e to
d35f3bf
Compare
Member
|
Applied with modifications as ce35c27. Thanks. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
getArrayValue sized its buffer from dbChannelFinalFieldSize, but dbGet writes dbValueSize(final_type) bytes per element — MAX_STRING_SIZE for a DBR_STRING request regardless of the field's own size — so a DBF_STRING field with field_size < 40 (synApps scalcout's PAA..PLL) overflowed the heap.
Size by dbValueSize(final_type) instead: unchanged for numeric fields and type-changing filters (where dbValueSize == field_size, e.g. ts -> DBR_DOUBLE), and MAX_STRING_SIZE for strings. This keeps the field_size-based design while making a malformed field_size unable to overrun the buffer.
Fixes #205.