bspeice/dtparse

Panic on invalid time

Closed this issue · 0 comments

Found using honggfuzz.

\x2D\x2D\x32\x31\x38\x6D causes the panic.

It looks like from_hms_micro panics if the inputs are invalid so from_hms_micro_opt should be used.

thread 'main' panicked at 'invalid time', libcore/option.rs:960:5
stack backtrace:
   0: std::sys::unix::backtrace::tracing::imp::unwind_backtrace
             at libstd/sys/unix/backtrace/tracing/gcc_s.rs:49
   1: std::sys_common::backtrace::print
             at libstd/sys_common/backtrace.rs:71
             at libstd/sys_common/backtrace.rs:59
   2: std::panicking::default_hook::{{closure}}
             at libstd/panicking.rs:211
   3: std::panicking::default_hook
             at libstd/panicking.rs:227
   4: std::panicking::rust_panic_with_hook
             at libstd/panicking.rs:511
   5: std::panicking::continue_panic_fmt
             at libstd/panicking.rs:426
   6: rust_begin_unwind
             at libstd/panicking.rs:337
   7: core::panicking::panic_fmt
             at libcore/panicking.rs:92
   8: core::option::expect_failed
             at libcore/option.rs:960
   9: <core::option::Option<T>>::expect
             at /checkout/src/libcore/option.rs:312
  10: chrono::naive::time::NaiveTime::from_hms_micro
             at /home/user/.cargo/registry/src/github.com-1ecc6299db9ec823/chrono-0.4.4/src/naive/time.rs:300
  11: dtparse::Parser::build_naive
             at /home/user/.cargo/git/checkouts/dtparse-4231ce982140a2f6/f0c3d89/src/lib.rs:809
  12: dtparse::Parser::parse
             at /home/user/.cargo/git/checkouts/dtparse-4231ce982140a2f6/f0c3d89/src/lib.rs:573
  13: dtparse::parse
             at /home/user/.cargo/git/checkouts/dtparse-4231ce982140a2f6/f0c3d89/src/lib.rs:1125
  14: dtparse_parse::main::{{closure}}
             at /home/user/daniel/targets/common/src/lib.rs:300
             at fuzzer-honggfuzz/src/bin/dtparse_parse.rs:8
  15: honggfuzz::fuzz
             at /home/user/.cargo/registry/src/github.com-1ecc6299db9ec823/honggfuzz-0.5.20/src/lib.rs:301
  16: dtparse_parse::main
             at fuzzer-honggfuzz/src/bin/dtparse_parse.rs:7
  17: std::rt::lang_start::{{closure}}
             at /checkout/src/libstd/rt.rs:74
  18: std::panicking::try::do_call
             at libstd/rt.rs:59
             at libstd/panicking.rs:310
  19: __rust_maybe_catch_panic
             at libpanic_unwind/lib.rs:105
  20: std::rt::lang_start_internal
             at libstd/panicking.rs:289
             at libstd/panic.rs:392
             at libstd/rt.rs:58
  21: std::rt::lang_start
             at /checkout/src/libstd/rt.rs:74
  22: main
  23: __libc_start_main
  24: _start