Skip to content

expr: check NewAttributeDecoder error before use in CtTimeout - #368

Open
vulragrag-star wants to merge 1 commit into
google:mainfrom
vulragrag-star:fix/367-ct-timeout-decoder-err
Open

vulragrag-star wants to merge 1 commit into
google:mainfrom
vulragrag-star:fix/367-ct-timeout-decoder-err

Conversation

@vulragrag-star

@vulragrag-star vulragrag-star commented Sep 20, 2026 •

Copy link
Copy Markdown

Summary

CtTimeout.unmarshal set decoder.ByteOrder before checking the error from netlink.NewAttributeDecoder. On a truncated nested NFTA_CT_TIMEOUT_DATA payload the decoder is nil, so that assignment panicked instead of returning an error.

Every other similar call site in the repo checks err first; this one was the only inversion.

Fixes #367

Test plan

go test ./expr/ -run TestCtTimeoutUnmarshalMalformedNestedAttr -count=1
go test ./...
  • Without the reorder: the new test panics at expr/ct.go on decoder.ByteOrder.
  • With the fix: the test returns an error and the package suite stays green.

Partial fix for the check-after-use called out in #367 (other short-attribute sites from that issue left for follow-up).

CtTimeout.unmarshal set decoder.ByteOrder before checking the error
from NewAttributeDecoder. On a truncated nested NFTA_CT_TIMEOUT_DATA
payload the decoder is nil, so that assignment panicked instead of
returning an error.

Move the error check above the dereference and add a regression test.

Fixes google#367

Signed-off-by: Jason Wang <vulragrag@gmail.com>
@google-cla

google-cla Bot commented Sep 20, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@vulragrag-star

Copy link
Copy Markdown
Author

I signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Multiple Netlink Decode Paths Can Panic on Malformed or Undersized Input

1 participant