Conversation
ProtoReader.readBuffer, readData, readFixed32, readFixed64 and readVarint checked the wire type of the current field with fatalError or precondition. Generated code picks the read primitive from the schema, but the wire type comes from the input. A known field number sent with a different wire type therefore stopped the process. A catch block cannot handle a failed precondition, so a caller had no way to reject the bytes. The five functions already throw. They now throw ProtoDecoder.Error.invalidStructure on a mismatch, as beginMessage does for its own state check and as the Kotlin runtime does with ProtocolException. Valid input and unknown fields decode the same as before.
oldergod
marked this pull request as ready for review
September 25, 2026 15:48
dnkoutso
approved these changes
Sep 25, 2026
oldergod
deleted the
bquenaudon.2026-09-25.proto-reader-throw-on-wire-type-mismatch
branch
September 25, 2026 16:09
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Harden the Swift decoder so that bad bytes throw an error and do not stop the process.
ProtoReader.readBuffer,readData,readFixed32,readFixed64andreadVarintcheck that the wire type of the current field is the one they read. When the check failed, they calledfatalErrororprecondition. Generated code picks the read primitive from the schema, but the wire type comes from the input. So a known field number with a different wire type stopped the process, in debug and in release builds. Ado/catcharoundProtoDecoder.decodecannot handle this.The five functions already
throw, so no caller changes. On a mismatch they now throwProtoDecoder.Error.invalidStructure(message:). This is the same approach asbeginMessage, which throwsmessageWithoutLengthfor its own state check, and as the Kotlin runtime, which throwsProtocolException. I did not useinvalidFieldWireType, because that case reports a wire type value that does not exist.Valid input, truncated input and unknown fields decode the same as before.
Tests:
ProtoReaderTests: one test for each of the five primitives. Each test gives a field key with a different wire type and expectsinvalidStructurewith the message.ProtoDecoderTests.testDecodeRejectsKnownFieldWithMismatchedWireType: decodesPersonwith known fields sent with each wrong wire type, and expects a thrown error.Without the fix, each new test stops the test process with signal 5 at its own check.