Sitelet https://github.com/RustCrypto/formats/pull/2414
Skip to content

tls_codec: return an error instead of panicking on truncated VLBytes - #2414

Open
WorkingRobot wants to merge 1 commit into
RustCrypto:masterfrom
WorkingRobot:tls_codec/truncated-vlbytes-debug-assert
Open

WorkingRobot wants to merge 1 commit into
RustCrypto:masterfrom
WorkingRobot:tls_codec/truncated-vlbytes-debug-assert

Conversation

@WorkingRobot

Copy link
Copy Markdown

In debug mode, VLBytes::tls_deserialize_bytes and VLByteVec::tls_deserialize_bytes panic instead of returning an Err. Panics should happen on invariants, not on untrusted input.

Signed-off-by: Asriel Camora <asriel@camora.dev>

@franziskuskiefer franziskuskiefer left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why do you want an error in this case? Panicking is what allows you to debug.

@WorkingRobot

Copy link
Copy Markdown
Author

It means that I can't properly test over-the-wire runs in debug mode. If I want a panic, I can easily add a .unwrap(). Having it panic in debug mode really only makes sense when the library has a logic error. If it helps, I'm using tls_codec for an MLS implementation, not for TLS.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants