diff --git a/src/rpc/object_storage.cc b/src/rpc/object_storage.cc index 9cee97d4..b79b783a 100644 --- a/src/rpc/object_storage.cc +++ b/src/rpc/object_storage.cc @@ -64,8 +64,12 @@ object_storage::insert(const char* key_data, uint32_t key_size, const torrent::O if (std::find(key_data, key_data + key_size, '\0') != key_data + key_size) throw torrent::input_error("Found nul-char in string."); - // Check for size > key_size. - // Check for empty string. + // key_type turns a key this long into the empty key. + if (key_size >= object_storage::key_size) + throw torrent::input_error("Key is too long."); + + if (key_size == 0) + throw torrent::input_error("Key is empty."); bool use_raw = false; torrent::Object object; diff --git a/test/rpc/test_object_storage.cc b/test/rpc/test_object_storage.cc index aef2e143..3284c7ba 100644 --- a/test/rpc/test_object_storage.cc +++ b/test/rpc/test_object_storage.cc @@ -49,6 +49,17 @@ TestObjectStorage::test_validate_keys() { torrent::raw_string raw_string_4("test_4\0foo", 10); ASSERT_CATCH_INPUT_ERROR( { m_storage.insert(raw_string_4, torrent::Object("a"), rpc::object_storage::flag_string_type); } ); + ASSERT_CATCH_INPUT_ERROR( { m_storage.insert_str("", torrent::Object("a"), rpc::object_storage::flag_string_type); } ); + + std::string key_max(rpc::object_storage::key_size - 1, 'k'); + + CPPUNIT_ASSERT(m_storage.insert_str(key_max, torrent::Object("a"), rpc::object_storage::flag_string_type)->first == key_max); + ASSERT_CATCH_INPUT_ERROR( { m_storage.insert_str(key_max + 'k', torrent::Object("a"), rpc::object_storage::flag_string_type); } ); + + // The over-long key must not have been stored as the empty key. + CPPUNIT_ASSERT(m_storage.find_raw_string(torrent::raw_string::from_c_str("")) == m_storage.end()); + + m_storage.clear(); } // And test many other bad/good string combos.