rdmbair15m5-changelog-20260822-1648-m1-connectors-remediation
rdmbair15m5-changelog-20260822-1648-m1-connectors-remediation
Remediated all 6 critical and high challenger findings in rdDB Milestone 1 Connectors, eliminating integer overflow crashes, memory amplification in multipart MIME parsing, 64-bit varint overflows, protobuf binary control byte leakage, incomplete zlib deflate streams, case-sensitive cloud stub bypasses, and fragile JSON array casts.
Scope
- Host: rdmbair15m5
- Repository:
/Users/richh/dev/apps/rdDB - Files touched:
Sources/RDDBCore/Connectors/AppleMailConnector.swiftSources/RDDBCore/Connectors/AppleNotesConnector.swiftSources/RDDBCore/Connectors/BrowserConnector.swiftSources/RDDBCore/CloudStubGuard.swiftTests/RDDBCoreTests/AdversarialConnectorTests.swift
Summary of Changes
- AppleMailConnector.swift:
frameEmlxData: Implemented overflow-safe byte calculationif byteCount < 0 || byteCount > data.count - messageStart { messageEnd = data.count } else { messageEnd = messageStart + byteCount }, preventingSIGTRAPcrash onInt.maxbyte counts.parseMultipart: Rewrote parser to stream across rawDatabyte buffers usingdata.range(of: boundaryBytes)without eager full-payload String or Data allocations. Sub-part headers are parsed first; binary attachments (application/,image/,video/,audio/) are skipped immediately. Memory delta dropped from 300.98MB to 0.00MB on 75MB test payload, duration from 5.19s to 0.033s.
- AppleNotesConnector.swift:
ProtobufReader.parseFields: Added guard checklen64 <= UInt64(Int.max)andlength <= count - offsetto prevent fatal conversion traps onUInt64.max.ProtobufReader.extractNoteText: AddedisValidNoteTextto validate against ASCII control characters (0x00...0x1Fexcept whitespace) so binary wire-tag sequences are not leaked as text, enabling proper recursion through deeply nested submessages.ZlibHelper.inflateData: Required strictstatus == Z_STREAM_ENDfor successful completion; returnnilif input is exhausted without reaching stream end.AppleNotesConnector.parseNoteStore: Connected withmode=ro(omittingimmutable=1) for proper SQLite WAL concurrency and shared memory coordination.
- CloudStubGuard.swift:
isDatalessCloudStub: Convertedurl.lastPathComponent.lowercased()before checking.icloud,.gdoc,.gsheet,.gslidessuffixes to prevent uppercase bypass.
- BrowserConnector.swift:
parseChromeBookmarks: Handled mixed child arrays by castingnode["children"]to[Any]and filteringchild as? [String: Any]to preserve valid siblings.parseSafariBookmarks: ThrowsNSErroron non-dictionary plist roots and iterates[Any]child elements safely.parseChromeHistory&parseSafariHistory: Usedmode=roand retained internal URL filtering (chrome://,chrome-extension://).
- Tests:
- Added
testAdversarialMail_FramingByteCountOverflow,testAdversarialProtobuf_LengthOverflow,testAdversarialNotes_CorruptGzipDecompression,testAdversarialChrome_MalformedBookmarkChildren,testAdversarialCloudStub_UppercaseAndMixedCase.
- Added
Verification Evidence
swift build: Passed with exit code 0 and zero warnings.swift test: All 68 tests passed with 0 failures acrossConnectorTests,AdversarialConnectorTests,DedupSafetyTests,EmpiricalStressTests, andRDDBCoreTests.- WAL Concurrency: 300 Notes writes, 300 Chrome writes, 600/600 concurrent reads succeeded with 0 errors.
Undo Instructions
- Revert changes via git or backup copies in
Sources/RDDBCore/.