diff --git a/changelogs/unreleased/gh-4962-box-cfg-forbid-infinite-numbers.md b/changelogs/unreleased/gh-4962-box-cfg-forbid-infinite-numbers.md new file mode 100644 index 0000000000000000000000000000000000000000..ffe6f461950d5633f3a0f6b27a0016ff658d2d69 --- /dev/null +++ b/changelogs/unreleased/gh-4962-box-cfg-forbid-infinite-numbers.md @@ -0,0 +1,5 @@ +## bugfix/box + +* Added a check that disables setting `box.cfg` and `log.cfg` options to + infinite numbers (NaN, Inf). Setting a `box.cfg` or `log.cfg` option to + an infinite number could result in a crash or invalid behavior (gh-4962). diff --git a/src/box/lua/load_cfg.lua b/src/box/lua/load_cfg.lua index bc707f8a43493f99ccee1d92e4fa7aced94a05c2..fd678e918aa3f8278013f348448a3efd28f56f1d 100644 --- a/src/box/lua/load_cfg.lua +++ b/src/box/lua/load_cfg.lua @@ -810,6 +810,14 @@ local function check_cfg_option_type(template, name, value) template) end end + -- It makes no sense to set any configuration option value to an infinite + -- number (nan, inf, -inf). To prevent such numbers from slipping through + -- configuration option sanity checks and breaking the application logic, + -- we forbid them explicitly at the top level. + if type(value) == 'number' and not + (value == value and value > -math.huge and value < math.huge) then + box.error(box.error.CFG, name, "should be a finite number") + end end local function prepare_cfg(cfg, old_cfg, default_cfg, template_cfg, modify_cfg) diff --git a/test/box-luatest/gh_4962_cfg_infinite_numbers_test.lua b/test/box-luatest/gh_4962_cfg_infinite_numbers_test.lua new file mode 100644 index 0000000000000000000000000000000000000000..098ea1430ac44ac170bfd38d7188fe5499291432 --- /dev/null +++ b/test/box-luatest/gh_4962_cfg_infinite_numbers_test.lua @@ -0,0 +1,28 @@ +local server = require('luatest.server') +local t = require('luatest') + +local g = t.group() + +g.before_all(function(cg) + cg.server = server:new() + cg.server:start() +end) + +g.after_all(function(cg) + cg.server:drop() +end) + +g.test_cfg_infinite_numbers = function(cg) + cg.server:exec(function() + for _, val in ipairs({1 / 0, -1 / 0, 0 / 0}) do + for opt, opt_type in pairs(box.internal.template_cfg) do + if opt_type:find('number') then + t.assert_error_msg_equals( + "Incorrect value for option '" .. opt .. "': " .. + "should be a finite number", + box.cfg, {[opt] = val}) + end + end + end + end) +end