wasphin opened a new pull request, #3485:
URL: https://github.com/apache/brpc/pull/3485

   ### What problem does this PR solve?
   
   Issue Number: resolve
   
   Problem Summary:
   
   When a client creates multiple streams in one RPC, it expects the server 
response to return exactly one `extra_stream_id` for every stream after the 
first. The response path indexed this list using the number of locally created 
streams without first validating its size. A malformed response could therefore 
read past the returned identifiers, while surplus identifiers had no valid 
client-stream mapping.
   
   ### What is changed and the side effects?
   
   Changed:
   
   - Require the number of returned `extra_stream_ids` to exactly match the 
number of additional client streams.
   - Fail the RPC with `ERESPONSE` and use the existing stream cleanup path 
when the counts differ.
   - Add full client/server regression coverage for both missing and surplus 
returned stream identifiers.
   
   Side effects:
   - Performance effects: One integer comparison is added when completing a 
multi-stream RPC.
   
   - Breaking backward compatibility: Malformed responses with missing or 
surplus stream identifiers are now rejected instead of being partially 
processed.
   
   ---
   ### Check List:
   - Please make sure your changes are compilable.
   - When providing us with a new feature, it is best to add related tests.
   - Please follow [Contributor Covenant Code of 
Conduct](https://github.com/apache/brpc/blob/master/CODE_OF_CONDUCT.md).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to