-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Unknown
-
Affects Version/s: None
-
Component/s: None
-
None
-
None
-
Go Drivers
-
Not Needed
-
None
-
None
-
None
-
None
-
None
-
None
Context
From PR 2638:
decodeOpReply reads the OP_REPLY flags, cursorID, startingFrom, numberReturned, and documents directly off the wire, then when the QueryFailure flag is set it builds a QueryFailureError from reply.documents[0]. ReadReplyDocuments hands back an empty slice with ok=true when the reply carries no documents, so a server, proxy, or MITM that sends an OP_REPLY with the QueryFailure flag set and numberReturned of 0 makes documents[0] panic with index out of range and takes down the goroutine reading the reply. decodeResult dispatches on the server-supplied opcode, so this is reachable through the legacy OP_QUERY/OP_REPLY path before authentication completes.
Reject the QueryFailure-with-no-documents reply as malformed before indexing, alongside the other malformed-reply errors decodeOpReply already returns. Keeping the check next to the flag handling means the error path stays local to where the flag is interpreted rather than relying on the later numberReturned/len consistency check, which does not run for the early-return flag branches.
Definition of done
- Return an error if OP_REPLY has the QueryFailure flag set but the documents list is empty.
- Add a test that decodeOpReply returns an error if OP_REPLY has status QueryFailure but no documents.
Pitfalls
What should the implementer watch out for? What are the risks?