Skip to content

fix(telegram): parse Ogg Opus packet offset - #6872

Merged
houko merged 6 commits into
mainfrom
fix/telegram-ogg-opus-detection
Aug 12, 2026
Merged

houko merged 6 commits into
mainfrom
fix/telegram-ogg-opus-detection

Conversation

@houko

@houko houko commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Summary

  • derive the first Ogg packet offset from the page segment table
  • recognize valid Opus identification headers with non-default page layouts
  • reject truncated pages, continued packets, and misplaced OpusHead bytes

Verification

  • cargo test --manifest-path sdk/rust/librefang-sidecar-telegram/Cargo.toml ogg_opus_detection_uses_the_first_packet_offset
  • cargo test --manifest-path sdk/rust/librefang-sidecar-telegram/Cargo.toml --all-targets
  • cargo clippy --manifest-path sdk/rust/librefang-sidecar-telegram/Cargo.toml --all-targets -- -D warnings
  • git diff --check

@houko
houko force-pushed the fix/telegram-ogg-opus-detection branch from 53f455a to 2eef34c Compare August 10, 2026 00:07
@github-actions github-actions Bot added area/sdk JavaScript and Python SDKs size/M 50-249 lines changed labels Aug 10, 2026
houko and others added 4 commits August 10, 2026 13:21
looks_like_ogg_opus() parses attacker/network-controlled bytes from
Telegram voice uploads, so add a test that walks every possible
truncation of a valid page and asserts it is rejected without
panicking, alongside a few malformed/too-short inputs.

houko commented Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

Automated daily review pass.

looks_like_ogg_opus itself looks correct: the fixed-header/version/continuation checks, the segment-table bounds arithmetic (with checked_add guarding the page-length sum), and the first-packet-length walk that stops at the first lacing value < 255 all match the Ogg framing spec, and the truncation test (ogg_opus_detection_rejects_every_truncation_without_panicking) exercises every prefix of a valid page plus several malformed inputs. No off-by-one or panic path found. Changelog fragment (changelog.d/fixed/6872-telegram-ogg-opus-detection.md) is correctly formatted and attributed.

One minor, non-blocking note: the body of test(telegram): cover every truncation of an Ogg/Opus page (d13f0f3) is hard-wrapped at a fixed column across four lines, mid-sentence. CLAUDE.md's prose-wrapping rule ("Prose wrapping: no column limit; break only at sentence boundaries") explicitly lists commit message bodies as in scope. Not asking for a history rewrite here — just flagging for future commit messages on this branch/series.


Generated by Claude Code

Comments were hard-wrapped mid-sentence instead of one sentence per line.
@houko
houko merged commit ed5c5db into main Aug 12, 2026
35 checks passed
@houko
houko deleted the fix/telegram-ogg-opus-detection branch August 12, 2026 00:38
@houko houko mentioned this pull request Aug 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/sdk JavaScript and Python SDKs size/M 50-249 lines changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants