【问题标题】:Why are null bytes appearing? Even after "sanitizing" the stream为什么会出现空字节?即使在“消毒”流之后
【发布时间】:2020-06-05 04:03:08
【问题描述】:

我一直想弄清楚为什么空字节出现在某些字符串中。下面的例子。

{"gender":"fema\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000le"}

我基本上是从 HTTP 请求中包装一个 io.Reader 并解码为一个结构。见下文

func bodyToStruct(res *http.Request, v gojay.UnmarshalerJSONObject) error {
    var reader io.ReadCloser
    var err error
    switch res.Header.Get("Content-Encoding") {
    case "gzip":
        reader, err = pool.Gzip.GetReader(res.Body)
        if err != nil {
            return err
        }
        defer pool.Gzip.PutReader(reader)
    case "deflate":
        reader = flate.NewReader(res.Body)
        defer reader.Close()
    default:
        reader = res.Body
    }

    decoder := gojay.BorrowDecoder(streams.NewNullByteRemoverStream(reader)) //wrapped in NewNullByteRemoverStream
    defer decoder.Release()

    return decoder.DecodeObject(v)
}

我尝试了多种方法来尝试删除空字节,我假设它们来自 Android 客户端的请求。

从早期堆栈线程的帮助中,我能够将以下实现部署到生产中,以尝试删除空字节。

package streams

import (
    "io"
)

// NullByte is a stream wrapper that should remove null bytes from the byte stream as well as reject any and all control bytes
type NullByte struct {
    Reader io.Reader
}

// NewNullByteRemoverStream creates a new NullByte reader which passes passes the parent stream through and remove null bytes
func NewNullByteRemoverStream(reader io.ReadCloser) *NullByte {
    return &NullByte{
        Reader: reader,
    }
}

func (s *NullByte) Read(p []byte) (n int, err error) {
    n, err = s.Reader.Read(p)
    var nn int
    for i := 0; i < n; i++ {
        if p[i] >= 32 && p[i] <= 126 {
            p[nn] = p[i]
            nn++
        } 
    }
    return nn, err
}

我什至尝试删除此处看到的 \u0000 的字符串文字(也在生产中进行了一些测试)

package streams

import (
    "io"
)

const _unicodeCodePointLength = 6

var (
    _sControlByte   = byte(92)
    _sNullByteBlock = []byte{92, 117, 48, 48, 48, 48}
)

// NullByte is a stream wrapper that should remove null bytes from the byte stream as well as reject any and all control bytes
type NullByte struct {
    Reader io.Reader
    state  int
}

// NewNullByteRemoverStream creates a new NullByte reader which passes passes the parent stream through and remove null bytes
// as well as \u0000 as a string representation
func NewNullByteRemoverStream(reader io.ReadCloser) *NullByte {
    return &NullByte{
        Reader: reader,
    }
}

func (s *NullByte) Read(p []byte) (n int, err error) {
    n, err = s.Reader.Read(p)

    var nn, i int
    for i < n {
        if p[i] == _sControlByte {
            s.state = 0
        }

        if p[i] == _sControlByte || s.state > 0 {
            var broke bool
            if p[i] == _sControlByte {
                stop := 0
                for j := i; j < n; j++ {
                    if stop == _unicodeCodePointLength {
                        break
                    }
                    if p[j] != _sNullByteBlock[stop] {
                        broke = true
                        break
                    }
                    stop++
                }

                if broke {
                    p[nn] = p[i]
                    i++
                    nn++
                    s.state = 0
                    continue
                }
            }

            if s.state < _unicodeCodePointLength {
                i++
                s.state++
                continue
            }
        }

        if p[i] != 0 {
            p[nn] = p[i]
            nn++
        }
        i++
    }
    return nn, err
}

不幸的是,这两个版本都没有解决这个问题。我可以在生产日志中看到 \u0000 出现在一定百分比的日志中。我认为通过将 io.Reader 响应包装在上面的 Sanitizers 中,问题就会停止。我可以从测试中看到空字节 0 和 \u0000 被删除......但问题在生产中仍然存在。我怀疑问题仍然在于客户的要求。这是因为该问题仅出现在特定客户端版本中。其他应用程序版本和平台不会触发空字节出现在字符串中,并且所有客户端都与相同的集中式服务器通信。我没主意了。我不知道为什么上面的消毒剂在 JSON 解码器将数据加载到支柱之前不删除空字节。有人有什么见解吗?

【问题讨论】:

  • 虽然我们无法通过上述任何方法解决后端的问题,但我们确实发布了一个发送 gzip 压缩数据的客户端版本。尽管我想为旧版本修复它,但它似乎确实为将来的版本纠正了这个问题。作为压缩的一部分,Gzipping 从客户端正确删除了空字节。

标签: go null streamreader


【解决方案1】:

编辑:这是不正确的,即使它可能巧合地解决了问题。无论是否使用缓冲区,都应删除空字节。

很难说为什么会出现空字节。但是流读取器不丢弃空值的问题可能是因为它们缺少自己的缓冲区。这是一个使用自己的缓冲区 (playground) 的空删除阅读器的示例:

type DropReader struct {
    buf    []byte
    reader io.Reader
    nulls  int
    reads  int
}

func (dr *DropReader) Read(data []byte) (int, error) {

    n, err := dr.reader.Read(dr.buf)

    dr.reads++

    j := 0
    for i := 0; i < n; i++ {

        c := dr.buf[i]

        if c == 0 {
            dr.nulls++
            continue
        }

        data[j] = c
        j++

    }

    return j, err
}

【讨论】:

  • 这很有趣,我这周试试。我确实注意到的一件事是,如果 \u0000 以字符串形式出现,那么字符串表示就是缓冲区返回的内容。例如 []byte{92, 117, 48, 48, 48, 48},但是,如果已经有一个完整的字符串,例如 hello\u0000 并且我转换为字节,那么我有字节表示,0 字节最后而不是最后的 []byte{92, 117, 48, 48, 48, 48}。
  • 这似乎可以解决问题!我将其标记为已接受。你能解释一下为什么添加它自己的缓冲区会起作用吗?
  • 很高兴它有效!我相信读取 n, err := s.Reader.Read(p) 会将 n 个字节写入 p,即使您随后将一个字节子集写入其中并返回一个较小的数字。
  • Go 既有文字字符串又有解释字符串。字符串文字不会解释 \u0000,即,它实际上包含 6 个字符 '\' 'u' '0' '0' '0' '0'。这就是字节序列 []byte{92, 117, 48, 48, 48, 48}。普通字符串会将 \u0000 解释为 unicode 空字符。见String Literals
  • 是的,以上适用于我的测试。解决生产问题的方法是在发送到后端之前压缩内容。我一直在努力考虑这个问题,我认为 gojay 库中可能存在一个错误,用于反射少 JSON,它在一些意外字节上绊倒并存储空值。以某种方式压缩内容解决了所有问题。我从来没有找到根目录,我的 android 开发人员无法重现,但决定使用压缩内容的标准网络堆栈。无论出于何种原因,这有帮助。但我非常感谢您的帮助。
猜你喜欢
  • 1970-01-01
  • 2014-06-02
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2017-06-29
  • 2013-12-09
  • 2015-12-17
  • 1970-01-01
相关资源
最近更新 更多