Follow-up from PR #58 (handler plugin system).
In batch_retrieve, the raw batch_resp is passed to plugins via on_batch_retrieve. A plugin issues device ops (e.g. prefetch/pin) using handle.offset + kv_offset and kv_length — server-supplied values. Core validates these ranges before handing out a CPU view (get_buffer_view returns None on out-of-bounds), but the plugin seam bypasses that check.
Under Maru's trust model the server is trusted, so this is defense-in-depth, not a live vulnerability. Options:
- core exposes a bounds-checked accessor (region size / validated device offset) that plugins reuse, or
- core validates
kv_offset + kv_length <= region_size before dispatching entries to plugins.
Raised as MEDIUM/LOW in the PR #58 review; deferred from that PR to keep it a faithful extraction.
Follow-up from PR #58 (handler plugin system).
In
batch_retrieve, the rawbatch_respis passed to plugins viaon_batch_retrieve. A plugin issues device ops (e.g. prefetch/pin) usinghandle.offset + kv_offsetandkv_length— server-supplied values. Core validates these ranges before handing out a CPU view (get_buffer_viewreturnsNoneon out-of-bounds), but the plugin seam bypasses that check.Under Maru's trust model the server is trusted, so this is defense-in-depth, not a live vulnerability. Options:
kv_offset + kv_length <= region_sizebefore dispatching entries to plugins.Raised as MEDIUM/LOW in the PR #58 review; deferred from that PR to keep it a faithful extraction.