3 ms·
Let's say you want the user of your service to be able to write and upload a configuration file, but you specifically don't want them to be able to execute arbi
by kiwidrew 6y ago
Let's say you want the user of your service to be able to write and upload a configuration file, but you specifically don't want them to be able to execute arbitrary code on your server(s).
It would be nice to be able to statically verify that their submitted configuration "behaves nicely", but the moment you introduce any kind of Turing-complete configuration language all guarantees go out the window because the problem becomes literally undecidable. [And then you try to mitigate it by imposing limits like "kill the parse process if it takes longer than X seconds or uses more than Y megabytes of memory".]
The advantage of, say, a simple .INI file for configuration purposes is that the time required to parse it (and storage space required to remember what's in it) is O(n) where n=size of config file...
EDIT: so take the example Lua file from the original post but change the loop limits from "32" to "16777216":
for i = 0, 16777216 do
for j = 0, 1677216 do
add_body({x = 20 * i, y = 20 * j, mass = -0.1, rad = 2})
end
end
Congrats! Your 128 byte long configuration file now requires 2^48 iterations of the inner loop to parse and generates 2^48 instances of the "body" object. That's an expansion factor of at least 2^41 generated bytes for every byte of input, which is a shockingly bad Denial-of-Service attack against whatever is responsible for parsing the evil config file.
- fit2rule 6y agoThis is hardly a failing of Lua-morphing-from-config-to-turing language, as it is missing sanitation in the customer interaction workflow. Like, I get that there are services that require this level of trust to the end user, but why wouldn't I solve this problem by timing the config load and immediately stopping any config process that takes longer than it should? Its the 21st century, we can still use interrupts. ;)
- mustvalidate 6y agoProper limits are needed regardless of how the config is loaded. In this example I would expect add_body to fail after adding some number of objects well before the loop limit is encountered. More troubling are loops which consume CPU without hitting memory limits. I would hope Lua provides a way to limit the number of instructions when evaluating expressions. If not then delegating reading the config to a limited subprocess could work at the cost of still more complexity.
- fish45 6y agoI hadn't added this before I posted here but Lua does have a way to limit vm instructions so I've added a pretty conservative limit