Handle malformed sandbox output safely

This commit is contained in:
Hamza Ayed
2026-10-03 16:51:39 +03:00
parent ac8359de6f
commit 0eec46fd47
3 changed files with 16 additions and 4 deletions
@@ -906,16 +906,27 @@ int wmain() {
pythonRuntimeFiles, entryScriptReady ? L"true" : L"false",
pythonRunResult, pythonVersionVisible ? L"true" : L"false");
std::vector<wchar_t> pythonOutputWide(pythonOutput.size() + 1);
bool pythonOutputValidUtf8 = true;
if (!pythonOutput.empty()) {
int wideCount = MultiByteToWideChar(CP_UTF8, MB_ERR_INVALID_CHARS,
pythonOutput.data(), static_cast<int>(pythonOutput.size()),
pythonOutputWide.data(), static_cast<int>(pythonOutputWide.size()));
if (wideCount <= 0) {
pythonOutputValidUtf8 = false;
wideCount = MultiByteToWideChar(CP_UTF8, 0,
pythonOutput.data(), static_cast<int>(pythonOutput.size()),
pythonOutputWide.data(), static_cast<int>(pythonOutputWide.size()));
}
if (wideCount > 0) pythonOutputWide[wideCount] = L'\0';
else pythonOutputWide[0] = L'\0';
}
wprintf(L"python_output_bytes=%llu\npython_output_truncated=%s\npython_output=%ls\n",
const bool pythonOutputHasReplacement =
std::wstring(pythonOutputWide.data()).find(L'\uFFFD') != std::wstring::npos;
wprintf(L"python_output_bytes=%llu\npython_output_truncated=%s\npython_output_valid_utf8=%s\npython_output_replacement_present=%s\npython_output=%ls\n",
static_cast<unsigned long long>(pythonOutput.size()),
pythonOutputTruncated ? L"true" : L"false",
pythonOutputValidUtf8 ? L"true" : L"false",
pythonOutputHasReplacement ? L"true" : L"false",
pythonOutputWide.data());
wprintf(L"overflow_run_exit=%lu\noverflow_output_bytes=%llu\noverflow_truncated=%s\n",
overflowRunResult, static_cast<unsigned long long>(overflowOutput.size()),
@@ -933,7 +944,7 @@ int wmain() {
allowedWriteResult != 0 || !allowedWorkspaceWriteVisible ||
!stagedInputCopied || stagedReadResult != 0 || !stagedInputRoundTripMatches ||
!pythonRuntimeCopied || !pythonProbeReady || pythonRunResult != 0 ||
!pythonVersionVisible ||
!pythonVersionVisible || pythonOutputValidUtf8 || !pythonOutputHasReplacement ||
overflowRunResult != 0 || overflowOutput.size() != 64 * 1024 ||
!overflowTruncated ||
!curlCopied || curlVersionResult != 0 || curlNetworkResult == 0 ||
@@ -9,3 +9,4 @@ result.write_text(
encoding="ascii",
)
print("sandbox-python-smoke-ok")
sys.stderr.buffer.write(b"sandbox-invalid-utf8:\xff\xfe\n")