core: meta/veloxpart — resume sidecar, reader first + fuzzed (stage 5)

util/crc32.hpp — header-only CRC-32 (zlib polynomial, reflected), used to
integrity-check the sidecar.

meta/veloxpart — the <name>.veloxpart.meta resume file (docs/04 §5).
Little-endian, versioned, CRC-32 over the whole record. Layout: magic,
version, flags, total_size, downloaded, url set (original/effective/
mirrors), etag/last-modified/content-type, segment records (start, end
INCLUSIVE, completed), optional sha256 streaming-hash blob.

parse_veloxpart() is the attacker-facing surface (the file sits in a
world-writable-ish download dir) and is total on any byte string: CRC
checked before any field is interpreted; magic, a version it understands,
every count and length bounded by a hard cap AND checked against the
remaining buffer; ByteReader latches on overrun; trailing bytes rejected.
Every malformation is meta_corrupt / meta_version_unsupported, never a
crash or an unbounded allocation. serialize_veloxpart() is deterministic
(unchanged sidecar isn't rewritten). File helpers write atomically
(temp + rename) and fdatasync the file and its directory.

Tests: crc32 known vector; full + minimal round-trips; deterministic
serialize; file round-trip; and a truncation/corruption table — bad
magic, CRC mismatch (payload and CRC-field flips), future version,
truncation at every stage, hostile url_count / segment_count / lp_string
length (the case the brief singles out), trailing bytes, impossible
segment.completed.

tools/fuzz/fuzz_veloxpart — feeds raw bytes and bytes-with-valid-CRC
(so the field parser and ByteReader bounds checks are actually reached),
and round-trip-stability-checks anything accepted. Ran 1.1M execs clean
under ASan+UBSan+libFuzzer (clang++-21); fuzz_content_disposition and
fuzz_url likewise re-run to 1.1M. tools/fuzz gains a -runs=0 seed-replay
CTest smoke per target (regression tripwire; the campaign stays manual).

Fuzz-found and fixed: parse_content_disposition could emit a filename
containing NUL / control bytes from a mangled filename* ext-value —
strip_path only removed path separators. Now sanitize_leaf() also drops
C0 controls and DEL (rules/ still owns the authoritative sanitize; `..`
and printable-unsafe content pass through as before).

Co-Authored-By: Claude Sonnet 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01HPPSGhiArbvQgwC2DNiURS
This commit is contained in:
2026-09-10 13:52:34 +04:00
co-authored by Claude Sonnet 5
parent 2e3251f0b5
commit 092e99f7a0
15 changed files with 830 additions and 15 deletions
@@ -135,6 +135,23 @@ VT_TEST(cd_bad_percent_escapes_in_ext_value) {
VT_CHECK(cd.type == Type::attachment);
}
VT_TEST(cd_strips_control_bytes_and_nul) {
// A mangled ext-value that decodes to bytes with embedded NULs (fuzz-found).
std::string h1("attachment; filename*=x''%e2%82%a");
h1.push_back('\0');
h1.push_back('\0');
h1 += "ff.pdf";
auto cd = parse_content_disposition(h1);
for (unsigned char c : cd.filename)
VT_CHECK(c >= 0x20 && c != 0x7F);
// a plain filename with a tab / newline / SOH loses them
std::string h2("attachment; filename=\"a\tb\nc");
h2.push_back('\x01');
h2 += ".txt\"";
auto cd2 = parse_content_disposition(h2);
VT_CHECK_EQ(cd2.filename, std::string("abc.txt"));
}
VT_TEST(cd_case_insensitive_keys_and_type) {
auto cd = parse_content_disposition(R"(ATTACHMENT; FileName="x.txt")");
VT_CHECK(cd.type == Type::attachment);