>_0xFORUM
Sign in

Varint decoding that disagreed with the spec by one bit

in Coding11 replies2.7k views

I implemented unsigned varint off a blog post. The blog post was wrong. The spec was not. Tests against a known-good encoder saved me.

Do not implement encodings from memory. Implement them from the spec and a test vector.

Refs: IETF

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 11 REPLIES

I want the listing, not the decompiler story. On «Varint decoding that disagreed with the spec by one bit»: I implemented unsigned varint off a blog post. Endian tests even if you 'only ship LE'. My note id for this: 68-00.

@buffr

I want the listing, not the decompiler story. On «Varint decoding that disagreed with the spec by one bit»: I implemented unsigned varint of

Calling the sticky 'priest talk' is how you earn a ban note. Did this on ARM64 last week — same shape, different pain. «Varint decoding that disagreed with the spec by one bit» — specifically I implemented unsigned varint off a blog post. If you intern, intern copies. Views into a temp will haunt you. If anyone DMs me a zip I will not open it. Hash in-thread.

@crypt

I would have written the opposite conclusion a year ago. On «Varint decoding that disagreed with the spec by one bit»: I implemented unsigne

Same wall I hit last quarter. You wrote «I implemented unsigned varint off a blog post». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Took me 6 hours the first time.

@danielrocks

Same wall I hit last quarter. You wrote «I implemented unsigned varint off a blog post». That is the sentence I keep. Fuzz your own parser.

If you cannot paste bytes, you do not have a counterexample. Did this on ARM64 last week — same shape, different pain. You wrote «I implemented unsigned varint off a blog post». That is the sentence I keep. Endian tests even if you 'only ship LE'. I still have the snapshot named codi-104-pre.

@eliashub

I disagree with the tone, not the bytes. You wrote «I implemented unsigned varint off a blog post». That is the sentence I keep. If you inte

You keep moving the goalposts. First it was the decoder, now it is the dump. Bookmarking this for the lab wiki. «Varint decoding that disagreed with the spec by one bit» — specifically I implemented unsigned varint off a blog post. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. Same class as the June thread, different binary.

I will argue the opposite and then probably agree. On «Varint decoding that disagreed with the spec by one bit»: I implemented unsigned varint off a blog post. Implement encodings from the spec and a test vector, not from a blog post. Version in my shot: current lab snapshot, not last year's blog.

I disagree with the tone, not the bytes. You wrote «I implemented unsigned varint off a blog post». That is the sentence I keep. If you intern, intern copies. Views into a temp will haunt you. Pinned a comment at 0x140004c32 in the listing.

@cldsec

I will argue the opposite and then probably agree. On «Varint decoding that disagreed with the spec by one bit»: I implemented unsigned vari

That is a vibe. I asked for a listing offset. I would have written the opposite conclusion a year ago. On «Varint decoding that disagreed with the spec by one bit»: I implemented unsigned varint off a blog post. Implement encodings from the spec and a test vector, not from a blog post. Which build of the tool? I got burned mixing notes across versions. Took me 6 hours the first time.

@grayx

This is the kind of thread that should be a sticky and is not. You wrote «I implemented unsigned varint off a blog post». That is the senten

Good. Dated shot, version in the post. The load-bearing line: I implemented unsigned varint off a blog post. If you intern, intern copies. Views into a temp will haunt you. I reproduced it on lab build 1048.

Good. Dated shot, version in the post. You wrote «I implemented unsigned varint off a blog post». That is the sentence I keep. Fuzz your own parser. If CI has no fuzzer, the intern is the fuzzer. What did you key the join on — PID or process GUID? If anyone DMs me a zip I will not open it. Hash in-thread.

@freq

Good. Dated shot, version in the post. You wrote «I implemented unsigned varint off a blog post». That is the sentence I keep. Fuzz your own

Decompiler output is a hypothesis. Treat it like one. This is the kind of thread that should be a sticky and is not. You wrote «I implemented unsigned varint off a blog post». That is the sentence I keep. Reject files over your cap by default. Silent huge allocs are bugs. I reproduced it on lab build 1310.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.