Builder.AddFileWithHash accepts a hash that is not a multihash #129

Open
opened 2026-10-04 06:32:37 +02:00 by clawbot · 1 comment
Collaborator

Problem

Builder.AddFileWithHash (mfer/builder.go) accepts any non-empty byte string as a file's hash. The format says each hash is a multihash, and the reader in #128 refuses hashes shorter than the smallest multihash, so the builder can write a manifest that mfer itself will not load.

Definition of done

  • AddFileWithHash rejects a hash that is not a valid multihash, using the go-multihash library the builder already imports, with a plain error.
  • A test covers a one-byte hash and a malformed multihash.
  • make check passes.
  • Lands after #128.
  • Commit title ends with (closes #N) for this issue's number.

Model: opus-5-5

## Problem `Builder.AddFileWithHash` (`mfer/builder.go`) accepts any non-empty byte string as a file's hash. The format says each hash is a multihash, and the reader in https://git.eeqj.de/sneak/mfer/pulls/128 refuses hashes shorter than the smallest multihash, so the builder can write a manifest that `mfer` itself will not load. ## Definition of done - `AddFileWithHash` rejects a hash that is not a valid multihash, using the `go-multihash` library the builder already imports, with a plain error. - A test covers a one-byte hash and a malformed multihash. - `make check` passes. - Lands after https://git.eeqj.de/sneak/mfer/pulls/128. - Commit title ends with ` (closes #N)` for this issue's number. Model: opus-5-5
Author
Collaborator

#139 makes AddFileWithHash refuse a hash that is not a valid multihash. It also refuses a valid multihash whose digest is shorter than 32 bytes, the SHA-256 size the reader's decoding-cost limit assumes, because a shorter one (an empty identity hash, SHA-1) can still make a manifest that mfer refuses to load.

Model: opus-5-5

https://git.eeqj.de/sneak/mfer/pulls/139 makes `AddFileWithHash` refuse a hash that is not a valid multihash. It also refuses a valid multihash whose digest is shorter than 32 bytes, the SHA-256 size the reader's decoding-cost limit assumes, because a shorter one (an empty identity hash, SHA-1) can still make a manifest that `mfer` refuses to load. Model: opus-5-5
Sign in to join this conversation.