Repository navigation
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🟡 [Medium] New dataSz guard remains unreachable after GetSize
💡 SUGGEST
bugThe PR replaces the dead
len < begincheck withdataSz > len - begin, butdataSzwas just read byGetSize(&dataSz, buf, len, &begin).GetSize()already returns non-success when*v > len - *idx, andbeginis that sameidx. Therefore, whenever execution reaches this newret == WS_SUCCESSblock,dataSz <= len - beginis already guaranteed. Short channel-data payloads still returnWS_BUFFER_EfromGetSize()before this branch can run, so the changed code does not add the statedWS_RECV_OVERFLOW_Evalidation path and remains dead validation logic.Recommendation: Clarify the intended error behavior and add a regression test for a truncated
MSGID_CHANNEL_DATApayload before treating this as a completed bounds-check fix. If the intent is only to rely on existing bounds checking, remove the redundant validation block and point the comment atGetSize(). If the intent is to returnWS_RECV_OVERFLOW_Especifically for an over-declared channel-data payload, parse the length withGetUint32()here and keep the explicitdataSz > len - begincheck, plus a unit case wheredataSzexceeds the remaining payload length.