Fuzz NewManifestFromReader and cap the zstd decoder (closes #65)
check / check (push) Successful in 1m5s
check / check (push) Successful in 1m5s
FuzzNewManifestFromReader fails when the parser returns both or neither of a manifest and an error, or allocates more than a fixed multiple of its input and the decompressed data it may read, plus room for the decoder's window buffers. make test runs the seed corpus; make fuzz fuzzes for one minute. Parser bug: MaxDecompressedSize did not bound decompression; the zstd decoder decoded a payload under 128 KiB in full before the LimitReader read any of it. It now decodes only what the LimitReader reads and refuses windows over the 8 MiB mfer writes with. Seeds: a frame claiming 8 GiB, two frames together over the limit, empty frames with growing windows. Model: opus-5-5
This commit was merged in pull request #120.
This commit is contained in:
@@ -47,7 +47,9 @@ allows verifying data integrity before decompression.
|
||||
The `innerMessage` field is compressed with
|
||||
[Zstandard (zstd)](https://facebook.github.io/zstd/). Implementations must
|
||||
enforce a decompression size limit to prevent decompression bombs. The reference
|
||||
implementation limits decompressed size to 256 MB.
|
||||
implementation limits decompressed size to 256 MB. It writes zstd frames with a
|
||||
window of at most 8 MiB, the largest window the zstd format recommends decoders
|
||||
support, and refuses frames that ask for a larger one.
|
||||
|
||||
## Inner Message (`MFFile`)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user