Bugs item #1898977, was opened at 2008-02-21 10:00
Message generated for change (Tracker Item Submitted) made by Item Submitter
You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=540672&aid=1898977&group_id=74338
Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: None
Group: None
Status: Open
Resolution: None
Priority: 5
Private: No
Submitted By: Derek Anderson (rantenki)
Assigned to: Nobody/Anonymous (nobody)
Summary: picklecol truncates/corrupts data dangerously
Initial Comment:
When a picklecol is created, it defaults to a tinyblob. This in itself is probably a good behavior, but when combined with the failure mode of writing too much data, it can be dangerous. For example:
{{{
class enomalism_user(TG_User,permissions_mixin):
class sqlmeta:
table = 'enomalism_user'
idName = 'id'
uuid = StringCol(length=36,alternateID=True,alternateMethodName='by_uuid',\
default=gen_uuid)
lang_pref = StringCol(length=16,varchar=True,alternateID=False,default="en",unique=False,notNone=True)
data = PickleCol(title="data",dbName="data",default={},length=2**24)
}}}
If you write "X"*257 to the data field, it will overflow with a "truncated" error, but that leaves the data in a corrupted state, and an exception is thrown when trying to read the user row. A better solution would be to throw the error, but to not store the data, preventing the exception, and leaving the user data in a usable state.
Note: This leaves a Turbogears user in an unusable state, and could lead to a DOS attack. Obviously my obligation is to test for this kind of thing, but it is the ideal behind the SQLO ORM to prevent db based failures by default, so...
----------------------------------------------------------------------
You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=540672&aid=1898977&group_id=74338
|