Packages

rabbit_common

4.3.4
4.3.4 4.2.1 4.2.0 retired 4.2.0-rc.1 retired 4.1.6 4.1.5 retired 4.1.5-rc.2 retired 4.1.5-rc.1 4.0.3 4.0.3-rc.1 4.0.2 4.0.2-rc.2 4.0.2-rc.1 4.0.1 4.0.0 4.0.0-rc.2 4.0.0-rc.1 3.13.7 3.13.6 3.13.5 3.13.4 3.13.3 3.13.2 3.13.2-rc.1 3.13.1 3.13.0 3.13.0-rc.6 3.13.0-rc.5 3.13.0-rc.4 3.13.0-rc.3 3.13.0-rc.2 3.13.0-rc.1 3.12.14 3.12.13 3.12.12 3.12.11 3.12.10 3.12.9 3.12.8 3.12.7 3.12.6 3.12.5 3.12.4 3.12.3 3.12.2 3.12.1 3.12.0 3.12.0-rc.4 3.12.0-rc.3 3.12.0-rc.2 3.12.0-rc.1 3.11.28 3.11.27 3.11.26 3.11.25 3.11.24 3.11.23 3.11.22 3.11.21 3.11.20 3.11.19 3.11.18 3.11.17 3.11.16 3.11.15 3.11.14 3.11.13 3.11.12 3.11.11 3.11.10 3.11.9 3.11.8 3.11.7 3.11.6 3.11.5 3.11.4 3.11.3 3.11.2 3.11.1 3.11.0 3.11.0-rc.2 3.11.0-rc.1 3.11.0-1 3.10.25 3.10.24 3.10.23 3.10.22 3.10.21 3.10.20 3.10.19 3.10.18 3.10.17 3.10.16 3.10.15 3.10.14 3.10.13 3.10.12 3.10.11 3.10.10 3.10.9 3.10.8 3.10.7 3.10.6 3.10.5 3.10.4 3.10.3 3.10.2 3.10.1 3.10.0 3.10.0-rc.6 3.10.0-rc.5 3.9.29 3.9.28 3.9.27 3.9.26 3.9.25 3.9.24 3.9.23 3.9.22 3.9.21 3.9.20 3.9.19 3.9.18 3.9.17 3.9.16 3.9.15 3.9.11 3.9.10 3.9.9 3.9.8 3.9.7 3.9.6 3.9.5 3.9.4 3.9.3 3.9.2 3.9.1 3.8.35 3.8.34 3.8.33 3.8.32 3.8.31 3.8.30 3.8.26 3.8.25 3.8.24 3.8.23 3.8.22 3.8.21 3.8.20 3.8.19 3.8.14 3.8.12-rc.3 3.8.12-rc.2 3.8.12-rc.1 3.8.11 3.8.10 3.8.10-rc.6 3.8.10-rc.5 3.8.10-rc.1 3.8.9 3.8.8 3.8.7 3.8.6 3.8.6-rc.2 3.8.6-rc.1 3.8.5 3.8.5-rc.2 3.8.5-rc.1 3.8.4 3.8.4-rc.3 3.8.4-rc.1 3.8.3 3.8.3-rc.2 3.8.3-rc.1 3.8.2 3.8.2-rc.1 3.8.1 3.8.1-rc.1 3.8.0 3.8.0-rc.3 3.8.0-rc.2 3.8.0-rc.1 3.7.28 3.7.27 3.7.27-rc.2 3.7.27-rc.1 3.7.26 3.7.25 3.7.25-rc.1 3.7.24 3.7.24-rc.2 3.7.24-rc.1 3.7.23 3.7.23-rc.1 3.7.22 3.7.22-rc.2 3.7.22-rc.1 3.7.21 3.7.20 3.7.20-rc.2 3.7.20-rc.1 3.7.19 3.7.18 3.7.18-rc.1 3.7.17 3.7.17-rc.3 3.7.17-rc.2 3.7.17-rc.1 retired 3.7.16 retired 3.7.16-rc.4 retired 3.7.16-rc.3 retired 3.7.16-rc.2 retired 3.7.16-rc.1 retired 3.7.16-beta.1 3.7.15 3.7.14 3.7.14-rc.2 3.7.14-rc.1 3.7.13 3.7.13-rc.2 3.7.13-rc.1 3.7.12 3.7.12-rc.2 3.7.12-rc.1 3.7.11 3.7.11-rc.2 3.7.11-rc.1 3.7.10-rc.4 3.7.10-rc.3 3.7.10-rc.2 3.7.10-rc.1 3.7.9 3.7.9-rc.3 3.7.9-rc.2 3.7.8 3.7.8-rc.4 3.7.8-rc.3 3.7.8-rc.2 3.7.8-rc.1 3.7.7 3.7.7-rc.2 3.7.7-rc.1 3.7.6 3.7.6-rc.2 3.7.6-rc.1 3.7.5 3.7.5-rc.1 3.7.4 3.7.4-rc.4 3.7.4-rc.3 3.7.4-rc.2 3.7.4-rc.1 3.7.3 3.7.3-rc.2 3.7.3-rc.1 3.7.2 3.7.1 3.7.0-rc.2 3.7.0-alpha.544 3.7.0-alpha.542 3.6.16 3.6.16-rc.1 3.6.15 3.6.15-rc.1 3.6.14 3.6.13 3.6.12 3.6.11 3.6.10 3.6.9 3.6.8 3.6.7 3.6.7-pre.1 3.5.6 3.5.0 3.4.0 3.3.5 3.0.2 0.0.0-rc.1

Modules shared by rabbitmq-server and rabbitmq-erlang-client

Current section

Files

Jump to
rabbit_common src rabbit_term_decoding.erl
Raw

src/rabbit_term_decoding.erl

%% This Source Code Form is subject to the terms of the Mozilla Public
%% License, v. 2.0. If a copy of the MPL was not distributed with this
%% file, You can obtain one at https://mozilla.org/MPL/2.0/.
%%
%% Copyright (c) 2007-2026 Broadcom. All Rights Reserved. The term "Broadcom" refers to Broadcom Inc. and/or its subsidiaries. All rights reserved.
%%
%% Bounded decoding of External Term Format (ETF) payloads. Caps the
%% incoming wire size, the post-decompression size, and the number of
%% atom-creating positions in the term, before calling
%% `binary_to_term/1`. Rejects fun, export, pid, port, ref, and
%% atom-cache-ref tags, which have no place in a data payload.
-module(rabbit_term_decoding).
-export([
bounded_decompress/2,
count_atom_tags_bounded/2,
decode_bounded/3
]).
-define(MAX_ETF_NESTING_DEPTH, 256).
%% Combined entry point: enforce a wire-size cap, optionally inflate
%% under a separate output cap, run the atom-tag scanner under a count
%% cap, and only then call `binary_to_term/1`. Returns the decoded term
%% on success.
-spec decode_bounded(binary(), pos_integer(), pos_integer()) ->
{ok, term()} | {error, atom()}.
decode_bounded(Bin, MaxBytes, MaxAtoms) when is_binary(Bin) ->
case byte_size(Bin) =< MaxBytes of
false ->
{error, payload_too_large};
true ->
case bounded_decompress(Bin, MaxBytes) of
{ok, Etf} ->
case count_atom_tags_bounded(Etf, MaxAtoms) of
{ok, _Count} ->
try {ok, erlang:binary_to_term(Etf)}
catch _:_ -> {error, decode_failure}
end;
{error, _} = E -> E
end;
{error, _} = E ->
E
end
end;
decode_bounded(_, _, _) ->
{error, not_a_binary}.
%% Returns uncompressed ETF (always starting with `<<131, _/binary>>`).
%% For compressed inputs the inner zlib stream is inflated under both a
%% header-claim check and a streaming observed-size cap.
-spec bounded_decompress(binary(), pos_integer()) ->
{ok, binary()} | {error, atom()}.
bounded_decompress(<<131, 80, UncompressedSize:32, _/binary>>, MaxBytes)
when UncompressedSize > MaxBytes ->
{error, declared_inflated_size_exceeds_cap};
bounded_decompress(<<131, 80, _UncompressedSize:32, Zlib/binary>>, MaxBytes) ->
case streaming_inflate(Zlib, MaxBytes) of
{ok, Inflated} -> {ok, <<131, Inflated/binary>>};
{error, _} = E -> E
end;
bounded_decompress(<<131, _/binary>> = Bin, _MaxBytes) ->
{ok, Bin};
bounded_decompress(_, _) ->
{error, not_etf}.
streaming_inflate(Zlib, MaxBytes) ->
Z = zlib:open(),
try
ok = zlib:inflateInit(Z),
do_streaming_inflate(Z, Zlib, MaxBytes, 0, [])
catch
_:_ ->
{error, inflate_error}
after
zlib:close(Z)
end.
do_streaming_inflate(Z, Input, MaxBytes, SoFar, Acc) ->
case zlib:safeInflate(Z, Input) of
{finished, Out} ->
Total = SoFar + iolist_size(Out),
if Total =< MaxBytes ->
{ok, iolist_to_binary(lists:reverse([Out | Acc]))};
true ->
{error, inflated_size_exceeds_cap}
end;
{continue, Out} ->
Total = SoFar + iolist_size(Out),
if Total =< MaxBytes ->
do_streaming_inflate(Z, [], MaxBytes, Total, [Out | Acc]);
true ->
{error, inflated_size_exceeds_cap}
end
end.
-spec count_atom_tags_bounded(binary(), pos_integer()) ->
{ok, non_neg_integer()} | {error, atom()}.
count_atom_tags_bounded(<<131, Rest/binary>>, MaxAtoms) ->
case scan_one(Rest, 0, MaxAtoms, 0) of
{ok, Count, <<>>} -> {ok, Count};
{ok, _, _Trailing} -> {error, trailing_bytes_after_term};
{error, _} = E -> E
end;
count_atom_tags_bounded(_, _) ->
{error, not_etf}.
scan_one(_Bin, _Count, _Max, Depth) when Depth > ?MAX_ETF_NESTING_DEPTH ->
{error, max_nesting_depth_exceeded};
scan_one(_Bin, Count, Max, _Depth) when Count > Max ->
{error, too_many_atom_tags};
scan_one(<<100, Len:16, _Name:Len/binary, Rest/binary>>, Count, Max, _Depth) ->
bump_atoms(Count, Max, Rest);
scan_one(<<115, Len:8, _Name:Len/binary, Rest/binary>>, Count, Max, _Depth) ->
bump_atoms(Count, Max, Rest);
scan_one(<<118, Len:16, _Name:Len/binary, Rest/binary>>, Count, Max, _Depth) ->
bump_atoms(Count, Max, Rest);
scan_one(<<119, Len:8, _Name:Len/binary, Rest/binary>>, Count, Max, _Depth) ->
bump_atoms(Count, Max, Rest);
scan_one(<<97, _:8, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<98, _:32, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<70, _:64, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<106, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
%% Length-prefixed opaque bodies. The scanner MUST NOT descend into
%% the body; arbitrary bytes inside a `BINARY_EXT` or `STRING_EXT` can
%% otherwise look like atom tags to a byte-pattern scanner.
scan_one(<<109, Len:32, _Body:Len/binary, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<107, Len:16, _Body:Len/binary, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<110, N:8, _Sign:8, _Mag:N/binary, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<111, N:32, _Sign:8, _Mag:N/binary, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<104, Arity:8, Rest/binary>>, Count, Max, Depth) ->
scan_n_elements(Arity, Rest, Count, Max, Depth + 1);
scan_one(<<105, Arity:32, Rest/binary>>, Count, Max, Depth) ->
scan_n_elements(Arity, Rest, Count, Max, Depth + 1);
scan_one(<<108, Len:32, Rest/binary>>, Count, Max, Depth) ->
case scan_n_elements(Len, Rest, Count, Max, Depth + 1) of
{ok, NewCount, AfterElements} ->
scan_one(AfterElements, NewCount, Max, Depth + 1);
{error, _} = E ->
E
end;
scan_one(<<116, Arity:32, Rest/binary>>, Count, Max, Depth) ->
scan_n_elements(Arity * 2, Rest, Count, Max, Depth + 1);
scan_one(<<112, _/binary>>, _Count, _Max, _Depth) -> {error, fun_tag_not_allowed};
scan_one(<<117, _/binary>>, _Count, _Max, _Depth) -> {error, fun_tag_not_allowed};
scan_one(<<113, _/binary>>, _Count, _Max, _Depth) -> {error, export_tag_not_allowed};
scan_one(<<82, _/binary>>, _Count, _Max, _Depth) -> {error, atom_cache_ref_not_allowed};
scan_one(<<88, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<89, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<90, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<91, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<101, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<102, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<103, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<114, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<77, _/binary>>, _Count, _Max, _Depth) -> {error, bit_binary_not_allowed};
scan_one(<<99, _/binary>>, _Count, _Max, _Depth) -> {error, deprecated_float_not_allowed};
scan_one(_Bin, _Count, _Max, _Depth) ->
{error, unknown_or_truncated_etf}.
scan_n_elements(0, Bin, Count, _Max, _Depth) ->
{ok, Count, Bin};
scan_n_elements(N, Bin, Count, Max, Depth) when N > 0 ->
case scan_one(Bin, Count, Max, Depth) of
{ok, NewCount, Rest} ->
scan_n_elements(N - 1, Rest, NewCount, Max, Depth);
{error, _} = E ->
E
end.
bump_atoms(Count, Max, _Rest) when Count + 1 > Max ->
{error, too_many_atom_tags};
bump_atoms(Count, _Max, Rest) ->
{ok, Count + 1, Rest}.