Fuzz NewManifestFromReader and cap the zstd decoder (closes #65)
check / check (push) Successful in 1m35s
check / check (push) Successful in 1m35s
FuzzNewManifestFromReader fails when the parser returns both or neither of a manifest and an error, or allocates more than sixteen times its input and the decompressed data it may read, plus room for the decoder's window buffers. make test runs the seed corpus; make fuzz fuzzes for one minute. Parser bug: MaxDecompressedSize did not bound decompression. The zstd decoder decoded a payload under 128 KiB in full before the LimitReader read any of it. It now decodes synchronously, only what the LimitReader reads, and refuses windows over the 8 MiB mfer writes with, since each frame asking for a larger window gets a new buffer. Seeds: a frame claiming 8 GiB, two frames together over the limit, empty frames with growing windows. Model: opus-5-5
This commit is contained in:
@@ -47,7 +47,9 @@ allows verifying data integrity before decompression.
|
||||
The `innerMessage` field is compressed with
|
||||
[Zstandard (zstd)](https://facebook.github.io/zstd/). Implementations must
|
||||
enforce a decompression size limit to prevent decompression bombs. The reference
|
||||
implementation limits decompressed size to 256 MB.
|
||||
implementation limits decompressed size to 256 MB. It writes zstd frames with a
|
||||
window of at most 8 MiB, the largest window the zstd format recommends decoders
|
||||
support, and refuses frames that ask for a larger one.
|
||||
|
||||
## Inner Message (`MFFile`)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user