Skip to content

Defense-in-depth: bounds-check server-supplied offset/length before device ops in handler plugins #59

Description

@hyunyul-XCENA

Follow-up from PR #58 (handler plugin system).

In batch_retrieve, the raw batch_resp is passed to plugins via on_batch_retrieve. A plugin issues device ops (e.g. prefetch/pin) using handle.offset + kv_offset and kv_length — server-supplied values. Core validates these ranges before handing out a CPU view (get_buffer_view returns None on out-of-bounds), but the plugin seam bypasses that check.

Under Maru's trust model the server is trusted, so this is defense-in-depth, not a live vulnerability. Options:

  • core exposes a bounds-checked accessor (region size / validated device offset) that plugins reuse, or
  • core validates kv_offset + kv_length <= region_size before dispatching entries to plugins.

Raised as MEDIUM/LOW in the PR #58 review; deferred from that PR to keep it a faithful extraction.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions