You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
One row the clause at terminal.py:723 still misses — found while adding the same guard to the
adb-shell route in #1476, so it is not a critique of the diff's shape, which is what I mirrored.
json.loads accepts the non-standard Infinity literal, and int(float("inf")) raises OverflowError, which except (TypeError, ValueError) does not catch. Of the four classes that can
arrive in a resize frame, three are already covered — "abc" → ValueError, [1] → TypeError, NaN → ValueError (NaN is truthy, so msg.get("cols") or 80 keeps it instead of falling back) —
and Infinity is the one that falls out.
On this route it is quieter than on the mobile one, because the exception never reaches the handler: reader() dies, asyncio.wait(..., return_when=asyncio.FIRST_COMPLETED) (:734) returns on that
task, writer_task is cancelled as pending, and the exception itself is swallowed by with contextlib.suppress(Exception): t.result() at :743. So there is no logger.exception("terminal session failed") line at all — the handler just falls into its finally
and detaches the session, so the user loses the terminal with nothing in the log. Read from the shipped
lines at a02e3e18, not executed: this route is @posix_only in test and needs a real PTY, which this
box cannot provide, so I have no capture of it.
Adding OverflowError to the clause is a one-word change and touches nothing else in the diff. If you
would rather keep the scope as it is, that is fine too — #1476 documents the mobile route's version.
For contrast, the rows that need the range check rather than the except: cols=70000 and cols=-1
do not escape this route today, because _set_winsize at :110-115 catches Exception ("Errors are
non-fatal"), so the struct.error: 'H' format requires 0 <= number <= 65535 from struct.pack("HHHH", …) is logged at debug level and the size simply is not applied. What does get
applied is a frame like {"cols":1,"rows":9999} — representable in an unsigned short, so it reaches TIOCSWINSZ and resizes the PTY to a geometry no terminal can render. That is what your bounds check
fixes. The mobile route has neither protection, which is why #1475 exists.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
变更说明
终端 WebSocket 的初始窗口尺寸和运行时
resize消息此前没有范围校验。异常客户端可以发送非正数或过大的尺寸,导致 PTY 调整失败,或把无效尺寸写入会话状态。本 PR 做了以下处理:
20–500、行数5–200的校验。resize消息使用相同范围校验,越界消息直接忽略。CHANGELOG.md的 Unreleased 修复项中记录此变更。风险与范围
仅修改终端 WebSocket 路由、对应单元测试和变更日志,不涉及 UI、数据库或其他功能模块。
验证
git diff --check通过。Fixes #1317