Packages
rabbit_common
4.3.4
4.3.4
4.2.1
4.2.0
retired
4.2.0-rc.1
retired
4.1.6
4.1.5
retired
4.1.5-rc.2
retired
4.1.5-rc.1
4.0.3
4.0.3-rc.1
4.0.2
4.0.2-rc.2
4.0.2-rc.1
4.0.1
4.0.0
4.0.0-rc.2
4.0.0-rc.1
3.13.7
3.13.6
3.13.5
3.13.4
3.13.3
3.13.2
3.13.2-rc.1
3.13.1
3.13.0
3.13.0-rc.6
3.13.0-rc.5
3.13.0-rc.4
3.13.0-rc.3
3.13.0-rc.2
3.13.0-rc.1
3.12.14
3.12.13
3.12.12
3.12.11
3.12.10
3.12.9
3.12.8
3.12.7
3.12.6
3.12.5
3.12.4
3.12.3
3.12.2
3.12.1
3.12.0
3.12.0-rc.4
3.12.0-rc.3
3.12.0-rc.2
3.12.0-rc.1
3.11.28
3.11.27
3.11.26
3.11.25
3.11.24
3.11.23
3.11.22
3.11.21
3.11.20
3.11.19
3.11.18
3.11.17
3.11.16
3.11.15
3.11.14
3.11.13
3.11.12
3.11.11
3.11.10
3.11.9
3.11.8
3.11.7
3.11.6
3.11.5
3.11.4
3.11.3
3.11.2
3.11.1
3.11.0
3.11.0-rc.2
3.11.0-rc.1
3.11.0-1
3.10.25
3.10.24
3.10.23
3.10.22
3.10.21
3.10.20
3.10.19
3.10.18
3.10.17
3.10.16
3.10.15
3.10.14
3.10.13
3.10.12
3.10.11
3.10.10
3.10.9
3.10.8
3.10.7
3.10.6
3.10.5
3.10.4
3.10.3
3.10.2
3.10.1
3.10.0
3.10.0-rc.6
3.10.0-rc.5
3.9.29
3.9.28
3.9.27
3.9.26
3.9.25
3.9.24
3.9.23
3.9.22
3.9.21
3.9.20
3.9.19
3.9.18
3.9.17
3.9.16
3.9.15
3.9.11
3.9.10
3.9.9
3.9.8
3.9.7
3.9.6
3.9.5
3.9.4
3.9.3
3.9.2
3.9.1
3.8.35
3.8.34
3.8.33
3.8.32
3.8.31
3.8.30
3.8.26
3.8.25
3.8.24
3.8.23
3.8.22
3.8.21
3.8.20
3.8.19
3.8.14
3.8.12-rc.3
3.8.12-rc.2
3.8.12-rc.1
3.8.11
3.8.10
3.8.10-rc.6
3.8.10-rc.5
3.8.10-rc.1
3.8.9
3.8.8
3.8.7
3.8.6
3.8.6-rc.2
3.8.6-rc.1
3.8.5
3.8.5-rc.2
3.8.5-rc.1
3.8.4
3.8.4-rc.3
3.8.4-rc.1
3.8.3
3.8.3-rc.2
3.8.3-rc.1
3.8.2
3.8.2-rc.1
3.8.1
3.8.1-rc.1
3.8.0
3.8.0-rc.3
3.8.0-rc.2
3.8.0-rc.1
3.7.28
3.7.27
3.7.27-rc.2
3.7.27-rc.1
3.7.26
3.7.25
3.7.25-rc.1
3.7.24
3.7.24-rc.2
3.7.24-rc.1
3.7.23
3.7.23-rc.1
3.7.22
3.7.22-rc.2
3.7.22-rc.1
3.7.21
3.7.20
3.7.20-rc.2
3.7.20-rc.1
3.7.19
3.7.18
3.7.18-rc.1
3.7.17
3.7.17-rc.3
3.7.17-rc.2
3.7.17-rc.1
retired
3.7.16
retired
3.7.16-rc.4
retired
3.7.16-rc.3
retired
3.7.16-rc.2
retired
3.7.16-rc.1
retired
3.7.16-beta.1
3.7.15
3.7.14
3.7.14-rc.2
3.7.14-rc.1
3.7.13
3.7.13-rc.2
3.7.13-rc.1
3.7.12
3.7.12-rc.2
3.7.12-rc.1
3.7.11
3.7.11-rc.2
3.7.11-rc.1
3.7.10-rc.4
3.7.10-rc.3
3.7.10-rc.2
3.7.10-rc.1
3.7.9
3.7.9-rc.3
3.7.9-rc.2
3.7.8
3.7.8-rc.4
3.7.8-rc.3
3.7.8-rc.2
3.7.8-rc.1
3.7.7
3.7.7-rc.2
3.7.7-rc.1
3.7.6
3.7.6-rc.2
3.7.6-rc.1
3.7.5
3.7.5-rc.1
3.7.4
3.7.4-rc.4
3.7.4-rc.3
3.7.4-rc.2
3.7.4-rc.1
3.7.3
3.7.3-rc.2
3.7.3-rc.1
3.7.2
3.7.1
3.7.0-rc.2
3.7.0-alpha.544
3.7.0-alpha.542
3.6.16
3.6.16-rc.1
3.6.15
3.6.15-rc.1
3.6.14
3.6.13
3.6.12
3.6.11
3.6.10
3.6.9
3.6.8
3.6.7
3.6.7-pre.1
3.5.6
3.5.0
3.4.0
3.3.5
3.0.2
0.0.0-rc.1
Modules shared by rabbitmq-server and rabbitmq-erlang-client
Current section
Files
Jump to
Current section
Files
src/rabbit_term_decoding.erl
%% This Source Code Form is subject to the terms of the Mozilla Public
%% License, v. 2.0. If a copy of the MPL was not distributed with this
%% file, You can obtain one at https://mozilla.org/MPL/2.0/.
%%
%% Copyright (c) 2007-2026 Broadcom. All Rights Reserved. The term "Broadcom" refers to Broadcom Inc. and/or its subsidiaries. All rights reserved.
%%
%% Bounded decoding of External Term Format (ETF) payloads. Caps the
%% incoming wire size, the post-decompression size, and the number of
%% atom-creating positions in the term, before calling
%% `binary_to_term/1`. Rejects fun, export, pid, port, ref, and
%% atom-cache-ref tags, which have no place in a data payload.
-module(rabbit_term_decoding).
-export([
bounded_decompress/2,
count_atom_tags_bounded/2,
decode_bounded/3
]).
-define(MAX_ETF_NESTING_DEPTH, 256).
%% Combined entry point: enforce a wire-size cap, optionally inflate
%% under a separate output cap, run the atom-tag scanner under a count
%% cap, and only then call `binary_to_term/1`. Returns the decoded term
%% on success.
-spec decode_bounded(binary(), pos_integer(), pos_integer()) ->
{ok, term()} | {error, atom()}.
decode_bounded(Bin, MaxBytes, MaxAtoms) when is_binary(Bin) ->
case byte_size(Bin) =< MaxBytes of
false ->
{error, payload_too_large};
true ->
case bounded_decompress(Bin, MaxBytes) of
{ok, Etf} ->
case count_atom_tags_bounded(Etf, MaxAtoms) of
{ok, _Count} ->
try {ok, erlang:binary_to_term(Etf)}
catch _:_ -> {error, decode_failure}
end;
{error, _} = E -> E
end;
{error, _} = E ->
E
end
end;
decode_bounded(_, _, _) ->
{error, not_a_binary}.
%% Returns uncompressed ETF (always starting with `<<131, _/binary>>`).
%% For compressed inputs the inner zlib stream is inflated under both a
%% header-claim check and a streaming observed-size cap.
-spec bounded_decompress(binary(), pos_integer()) ->
{ok, binary()} | {error, atom()}.
bounded_decompress(<<131, 80, UncompressedSize:32, _/binary>>, MaxBytes)
when UncompressedSize > MaxBytes ->
{error, declared_inflated_size_exceeds_cap};
bounded_decompress(<<131, 80, _UncompressedSize:32, Zlib/binary>>, MaxBytes) ->
case streaming_inflate(Zlib, MaxBytes) of
{ok, Inflated} -> {ok, <<131, Inflated/binary>>};
{error, _} = E -> E
end;
bounded_decompress(<<131, _/binary>> = Bin, _MaxBytes) ->
{ok, Bin};
bounded_decompress(_, _) ->
{error, not_etf}.
streaming_inflate(Zlib, MaxBytes) ->
Z = zlib:open(),
try
ok = zlib:inflateInit(Z),
do_streaming_inflate(Z, Zlib, MaxBytes, 0, [])
catch
_:_ ->
{error, inflate_error}
after
zlib:close(Z)
end.
do_streaming_inflate(Z, Input, MaxBytes, SoFar, Acc) ->
case zlib:safeInflate(Z, Input) of
{finished, Out} ->
Total = SoFar + iolist_size(Out),
if Total =< MaxBytes ->
{ok, iolist_to_binary(lists:reverse([Out | Acc]))};
true ->
{error, inflated_size_exceeds_cap}
end;
{continue, Out} ->
Total = SoFar + iolist_size(Out),
if Total =< MaxBytes ->
do_streaming_inflate(Z, [], MaxBytes, Total, [Out | Acc]);
true ->
{error, inflated_size_exceeds_cap}
end
end.
-spec count_atom_tags_bounded(binary(), pos_integer()) ->
{ok, non_neg_integer()} | {error, atom()}.
count_atom_tags_bounded(<<131, Rest/binary>>, MaxAtoms) ->
case scan_one(Rest, 0, MaxAtoms, 0) of
{ok, Count, <<>>} -> {ok, Count};
{ok, _, _Trailing} -> {error, trailing_bytes_after_term};
{error, _} = E -> E
end;
count_atom_tags_bounded(_, _) ->
{error, not_etf}.
scan_one(_Bin, _Count, _Max, Depth) when Depth > ?MAX_ETF_NESTING_DEPTH ->
{error, max_nesting_depth_exceeded};
scan_one(_Bin, Count, Max, _Depth) when Count > Max ->
{error, too_many_atom_tags};
scan_one(<<100, Len:16, _Name:Len/binary, Rest/binary>>, Count, Max, _Depth) ->
bump_atoms(Count, Max, Rest);
scan_one(<<115, Len:8, _Name:Len/binary, Rest/binary>>, Count, Max, _Depth) ->
bump_atoms(Count, Max, Rest);
scan_one(<<118, Len:16, _Name:Len/binary, Rest/binary>>, Count, Max, _Depth) ->
bump_atoms(Count, Max, Rest);
scan_one(<<119, Len:8, _Name:Len/binary, Rest/binary>>, Count, Max, _Depth) ->
bump_atoms(Count, Max, Rest);
scan_one(<<97, _:8, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<98, _:32, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<70, _:64, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<106, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
%% Length-prefixed opaque bodies. The scanner MUST NOT descend into
%% the body; arbitrary bytes inside a `BINARY_EXT` or `STRING_EXT` can
%% otherwise look like atom tags to a byte-pattern scanner.
scan_one(<<109, Len:32, _Body:Len/binary, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<107, Len:16, _Body:Len/binary, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<110, N:8, _Sign:8, _Mag:N/binary, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<111, N:32, _Sign:8, _Mag:N/binary, Rest/binary>>, Count, _Max, _Depth) ->
{ok, Count, Rest};
scan_one(<<104, Arity:8, Rest/binary>>, Count, Max, Depth) ->
scan_n_elements(Arity, Rest, Count, Max, Depth + 1);
scan_one(<<105, Arity:32, Rest/binary>>, Count, Max, Depth) ->
scan_n_elements(Arity, Rest, Count, Max, Depth + 1);
scan_one(<<108, Len:32, Rest/binary>>, Count, Max, Depth) ->
case scan_n_elements(Len, Rest, Count, Max, Depth + 1) of
{ok, NewCount, AfterElements} ->
scan_one(AfterElements, NewCount, Max, Depth + 1);
{error, _} = E ->
E
end;
scan_one(<<116, Arity:32, Rest/binary>>, Count, Max, Depth) ->
scan_n_elements(Arity * 2, Rest, Count, Max, Depth + 1);
scan_one(<<112, _/binary>>, _Count, _Max, _Depth) -> {error, fun_tag_not_allowed};
scan_one(<<117, _/binary>>, _Count, _Max, _Depth) -> {error, fun_tag_not_allowed};
scan_one(<<113, _/binary>>, _Count, _Max, _Depth) -> {error, export_tag_not_allowed};
scan_one(<<82, _/binary>>, _Count, _Max, _Depth) -> {error, atom_cache_ref_not_allowed};
scan_one(<<88, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<89, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<90, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<91, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<101, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<102, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<103, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<114, _/binary>>, _Count, _Max, _Depth) -> {error, pid_or_port_or_ref_not_allowed};
scan_one(<<77, _/binary>>, _Count, _Max, _Depth) -> {error, bit_binary_not_allowed};
scan_one(<<99, _/binary>>, _Count, _Max, _Depth) -> {error, deprecated_float_not_allowed};
scan_one(_Bin, _Count, _Max, _Depth) ->
{error, unknown_or_truncated_etf}.
scan_n_elements(0, Bin, Count, _Max, _Depth) ->
{ok, Count, Bin};
scan_n_elements(N, Bin, Count, Max, Depth) when N > 0 ->
case scan_one(Bin, Count, Max, Depth) of
{ok, NewCount, Rest} ->
scan_n_elements(N - 1, Rest, NewCount, Max, Depth);
{error, _} = E ->
E
end.
bump_atoms(Count, Max, _Rest) when Count + 1 > Max ->
{error, too_many_atom_tags};
bump_atoms(Count, _Max, Rest) ->
{ok, Count + 1, Rest}.