Reject manifests whose file entries decode far larger than their bytes (closes #123) #128

Merged
clawbot merged 1 commits from issue-123-bound-entry-decoding into next 2026-10-04 12:02:28 +02:00
1 Commits
Author SHA1 Message Date
sneak ee07db55b3 Reject manifests whose file entries decode far larger than their bytes (closes #123)
check / check (push) Waiting to run
Before decoding the manifest, the parser adds up what decoding sets
aside for each file entry, hash, timestamp and MIME type, however short
its encoding, and refuses the manifest once that passes 8 times the
decompressed size; manifests mfer writes come to at most about 7.15
times. Empty entries decoded to about 50 times their size: under 1 KB of
manifest allocated about 500 MB. Fields the decoder does not know are
dropped; kept, they took up to 5 times more. A test refuses entries
counted just over 8 times and loads them just under. The fuzz ceiling
rises from 16 to 20 times the input and decompressed data; seeds of
empty entries and of empty hashes fail it without the fix.

Model: opus-5-5
2026-10-04 08:34:06 +00:00