From c480a40b85e745967450e7d7b63563988db4b13b Mon Sep 17 00:00:00 2001 From: Aleksa Sarai Date: Wed, 8 Nov 2017 03:30:47 +1100 Subject: [PATCH] image: add import test for CVE-2017-14992 To ensure that we don't revert CVE-2017-14992, add a test that is quite similar to that upstream tar-split test (create an empty archive with lots of junk and make sure the daemon doesn't crash). Signed-off-by: Aleksa Sarai (cherry picked from commit 0a13f827a10d3bf61744d9b3f7165c5885a39c5d) Signed-off-by: Victor Vieux --- .../engine/integration/image/import_test.go | 36 +++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 components/engine/integration/image/import_test.go diff --git a/components/engine/integration/image/import_test.go b/components/engine/integration/image/import_test.go new file mode 100644 index 0000000000..955891f288 --- /dev/null +++ b/components/engine/integration/image/import_test.go @@ -0,0 +1,36 @@ +package image + +import ( + "archive/tar" + "bytes" + "context" + "io" + "testing" + + "github.com/docker/docker/api/types" + "github.com/docker/docker/integration/util/request" + "github.com/docker/docker/internal/testutil" +) + +// Ensure we don't regress on CVE-2017-14992. +func TestImportExtremelyLargeImageWorks(t *testing.T) { + client := request.NewAPIClient(t) + + // Construct an empty tar archive with about 8GB of junk padding at the + // end. This should not cause any crashes (the padding should be mostly + // ignored). + var tarBuffer bytes.Buffer + tw := tar.NewWriter(&tarBuffer) + if err := tw.Close(); err != nil { + t.Fatal(err) + } + imageRdr := io.MultiReader(&tarBuffer, io.LimitReader(testutil.DevZero, 8*1024*1024*1024)) + + _, err := client.ImageImport(context.Background(), + types.ImageImportSource{Source: imageRdr, SourceName: "-"}, + "test1234:v42", + types.ImageImportOptions{}) + if err != nil { + t.Fatal(err) + } +}