Reject manifests whose file entries decode far larger than their bytes (closes #123)
check / check (push) Failing after 1s

Parser fix: before decoding the manifest, the parser walks its file
entries and adds up what decoding sets aside for each entry, hash,
timestamp and MIME type, however short its encoding. It refuses the
manifest once that sum passes 8 times the decompressed size; manifests
mfer writes come to at most about 7.15 times. Empty entries decoded to
about 50 times their size, so a manifest of under 1 KB allocated about
500 MB. A test refuses entries counted at just over 8 times and loads
them at just under. The fuzz target's ceiling rises from 16 to 20 times
the input and decompressed data, and seeds of empty entries and of
empty hashes fail it without the fix.

Model: opus-5-5
This commit is contained in:
2026-10-04 07:38:09 +00:00
parent 45eac1f6f8
commit 10ad90ba22
7 changed files with 208 additions and 6 deletions
+3 -1
View File
@@ -49,7 +49,9 @@ The `innerMessage` field is compressed with
enforce a decompression size limit to prevent decompression bombs. The reference
implementation limits decompressed size to 256 MB. It writes zstd frames with a
window of at most 8 MiB, the largest window the zstd format recommends decoders
support, and refuses frames that ask for a larger one.
support, and refuses frames that ask for a larger one. It also refuses an inner
message whose file entries, hashes, timestamps and MIME types, counted at 160,
112, 64 and 16 bytes each, add up to more than 8 times its size.
## Inner Message (`MFFile`)