Fleet changelogs · dev.ecs0.net
rdmbair15m5-changelog-20260822-1648-m1-connectors-remediation

rdmbair15m5-changelog-20260822-1648-m1-connectors-remediation

Remediated all 6 critical and high challenger findings in rdDB Milestone 1 Connectors, eliminating integer overflow crashes, memory amplification in multipart MIME parsing, 64-bit varint overflows, protobuf binary control byte leakage, incomplete zlib deflate streams, case-sensitive cloud stub bypasses, and fragile JSON array casts.

Scope

Summary of Changes

  1. AppleMailConnector.swift:
    • frameEmlxData: Implemented overflow-safe byte calculation if byteCount < 0 || byteCount > data.count - messageStart { messageEnd = data.count } else { messageEnd = messageStart + byteCount }, preventing SIGTRAP crash on Int.max byte counts.
    • parseMultipart: Rewrote parser to stream across raw Data byte buffers using data.range(of: boundaryBytes) without eager full-payload String or Data allocations. Sub-part headers are parsed first; binary attachments (application/, image/, video/, audio/) are skipped immediately. Memory delta dropped from 300.98MB to 0.00MB on 75MB test payload, duration from 5.19s to 0.033s.
  2. AppleNotesConnector.swift:
    • ProtobufReader.parseFields: Added guard check len64 <= UInt64(Int.max) and length <= count - offset to prevent fatal conversion traps on UInt64.max.
    • ProtobufReader.extractNoteText: Added isValidNoteText to validate against ASCII control characters (0x00...0x1F except whitespace) so binary wire-tag sequences are not leaked as text, enabling proper recursion through deeply nested submessages.
    • ZlibHelper.inflateData: Required strict status == Z_STREAM_END for successful completion; return nil if input is exhausted without reaching stream end.
    • AppleNotesConnector.parseNoteStore: Connected with mode=ro (omitting immutable=1) for proper SQLite WAL concurrency and shared memory coordination.
  3. CloudStubGuard.swift:
    • isDatalessCloudStub: Converted url.lastPathComponent.lowercased() before checking .icloud, .gdoc, .gsheet, .gslides suffixes to prevent uppercase bypass.
  4. BrowserConnector.swift:
    • parseChromeBookmarks: Handled mixed child arrays by casting node["children"] to [Any] and filtering child as? [String: Any] to preserve valid siblings.
    • parseSafariBookmarks: Throws NSError on non-dictionary plist roots and iterates [Any] child elements safely.
    • parseChromeHistory & parseSafariHistory: Used mode=ro and retained internal URL filtering (chrome://, chrome-extension://).
  5. Tests:
    • Added testAdversarialMail_FramingByteCountOverflow, testAdversarialProtobuf_LengthOverflow, testAdversarialNotes_CorruptGzipDecompression, testAdversarialChrome_MalformedBookmarkChildren, testAdversarialCloudStub_UppercaseAndMixedCase.

Verification Evidence

Undo Instructions