From a236f6cdf0308666f4ff4bbc8deeb65049c383b2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Th=C3=A9ophile=20BR=C3=89ZOT?= Date: Tue, 29 Sep 2026 16:34:14 +0200 Subject: [PATCH] fix: policy paring --- CHANGELOG.md | 8 ++++++++ Cargo.lock | 2 +- Cargo.toml | 2 +- src/abe/policy/access_policy.rs | 6 ++++++ 4 files changed, 16 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 52e7d576..13179400 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,14 @@ All notable changes to this project will be documented in this file. +## [16.0.1] - 2026-09-29 + +### Bug Fixes + +- Fix a bug due to unproper handling of UTF-8 characters in the policy parsing + that causes a runtime panic. The fix restricts the range of expressible + policies to the ones only using ASCII characters. + ## [16.0.0] - 2026-02-13 ### 🚀 Features diff --git a/Cargo.lock b/Cargo.lock index 0843c6b6..68575071 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -184,7 +184,7 @@ checksum = "c2459377285ad874054d797f3ccebf984978aa39129f6eafde5cdc8315b612f8" [[package]] name = "cosmian_cover_crypt" -version = "16.0.0" +version = "16.0.1" dependencies = [ "cosmian_crypto_core", "cosmian_openssl_provider", diff --git a/Cargo.toml b/Cargo.toml index 2d3eea8a..f26a9011 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "cosmian_cover_crypt" -version = "16.0.0" +version = "16.0.1" authors = [ "Théophile Brezot ", "Bruno Grieder ", diff --git a/src/abe/policy/access_policy.rs b/src/abe/policy/access_policy.rs index b8ca195d..8d74b4ea 100644 --- a/src/abe/policy/access_policy.rs +++ b/src/abe/policy/access_policy.rs @@ -91,6 +91,11 @@ impl AccessPolicy { /// /// - "DPT::MKG DPT::FIN" pub fn parse(mut e: &str) -> Result { + if !e.is_ascii() { + return Err(Error::InvalidBooleanExpression( + "non-ascii character used".to_owned(), + )); + } let seeker = |c: &char| !"()|&".contains(*c); let mut q = LinkedList::::new(); loop { @@ -303,5 +308,6 @@ mod tests { assert!(AccessPolicy::parse("D1").is_err()); assert!(AccessPolicy::parse("D1::A (&& D2::A || D2::B)").is_err()); assert!(AccessPolicy::parse("|| D2::B").is_err()); + assert!(AccessPolicy::parse("(é::à && (ó::ï) || ø::ú)").is_err()); } }