Limit how much fetch and check read for a manifest or a file (closes #168)
check / check (push) Waiting to run

NewManifestFromReader reads at most one byte past MaxManifestSize, a new
constant of 258 MiB: the 256 MiB decompressed limit grown by zstd's worst
case of 1/256, plus 1 MiB for the signature, the signing key and the
other outer fields. It refuses a larger manifest. fetch, and check given
a URL, stop downloading a manifest at the same point, so the refusal
comes from the library. fetch stops reading a file one byte past its
listed size, so a longer body ends in the size mismatch at once instead
of filling the disk. docs/FORMAT.md states the limit and gives the
decompressed limit as 256 MiB, the size the code uses.

Model: opus-5-5
This commit is contained in:
2026-10-07 09:49:54 +00:00
parent 2a174e3ba2
commit 1fc69d5115
7 changed files with 139 additions and 9 deletions
+4 -1
View File
@@ -112,7 +112,10 @@ func (mfa *CLIApp) fetchManifestToTemp(
}
tmpPath := tmpFile.Name()
_, cpErr := io.Copy(tmpFile, rc)
// One byte past mfer.MaxManifestSize is enough for loading the
// manifest to refuse one that is too large.
_, cpErr := io.Copy(tmpFile, io.LimitReader(rc, mfer.MaxManifestSize+1))
_ = rc.Close()
_ = tmpFile.Close()