Skip to content

terminal: bounds check params in DCS passthrough entry - #11088

Merged
mitchellh merged 1 commit into
mainfrom
push-tsmrqzqmrsru
Mar 1, 2026
Merged

mitchellh merged 1 commit into
mainfrom
push-tsmrqzqmrsru

Conversation

@mitchellh

@mitchellh mitchellh commented Mar 1, 2026 •

Copy link
Copy Markdown
Contributor

When a DCS sequence has more than MAX_PARAMS parameters, entering dcs_passthrough would write to params[params_idx] without a bounds check, causing an out-of-bounds access. Add the same guard that csi_dispatch already has.

Found by AFL fuzzing, test and fix produced by Codex.

@mitchellh
mitchellh requested a review from a team as a code owner March 1, 2026 05:04
@mitchellh
mitchellh force-pushed the push-tsmrqzqmrsru branch from 7c10440 to b4adcba Compare March 1, 2026 05:08
When a DCS sequence has more than MAX_PARAMS parameters, entering
dcs_passthrough would write to params[params_idx] without a bounds
check, causing an out-of-bounds access. Drop the entire DCS hook
when params overflow, consistent with how csi_dispatch handles it.

Found by AFL fuzzing.
@mitchellh
mitchellh force-pushed the push-tsmrqzqmrsru branch from b4adcba to 12f43df Compare March 1, 2026 05:11
@mitchellh
mitchellh merged commit 25f1208 into main Mar 1, 2026
26 checks passed
@mitchellh
mitchellh deleted the push-tsmrqzqmrsru branch March 1, 2026 05:14
@github-actions github-actions Bot added this to the 1.3.0 milestone Mar 1, 2026
mitchellh added a commit that referenced this pull request Mar 1, 2026
This adds a `test/fuzz-libghostty` which is a standalone `zig build`
target for building an AFL++ instrumented executable for fuzzing the
libghostty-vt parser. I also added a `pkg/afl++` (based on zig-afl-kit)
so instrumenting objects and using AFL++ is a bit easier.

Fuzzing `libghostty-vt`'s parser is as easy as `zig build run`, but see
the README for a lot more details. I ran the fuzzer for ~14 hours total
and only found one crash #11088. I'm pretty confident at this point our
Parser layer isn't obviously crash-able, but need to instrument more
places to fuzz.

We don't use Zig's built-in fuzzing yet because as of 0.15 (our current
stable), it isn't ready and AFL++ is an industry proven tool to do this.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants