check / check (push) Waiting to run
NewManifestFromReader reads at most one byte past MaxManifestSize, a new constant of 258 MiB: the 256 MiB decompressed limit grown by zstd's worst case of 1/256, plus 1 MiB for the signature, the signing key and the other outer fields. It refuses a larger manifest. fetch, and check given a URL, stop downloading a manifest one byte past the same size and report it as too large; tests lower that size to keep their memory small. fetch stops reading a file one byte past its listed size, so a longer body ends in the size mismatch at once instead of filling the disk. docs/FORMAT.md states the limit and gives the decompressed limit as 256 MiB, the size the code uses. Model: opus-5-5
91 lines
2.3 KiB
Go
91 lines
2.3 KiB
Go
package cli
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
"io"
|
|
"net/http"
|
|
"strings"
|
|
"time"
|
|
|
|
"github.com/urfave/cli/v3"
|
|
)
|
|
|
|
// manifestFetchTimeout bounds HTTP requests made to fetch a manifest.
|
|
const manifestFetchTimeout = 30 * time.Second
|
|
|
|
// errHTTPStatus indicates an HTTP response with a non-OK status code.
|
|
//
|
|
// Its text is the literal "HTTP" prefix of the rendered "HTTP <code>"
|
|
// message that mfer has always printed, so that wrapping it does not
|
|
// change any user-visible output. Match it with errors.Is; do not read
|
|
// its message.
|
|
var errHTTPStatus = errors.New("HTTP")
|
|
|
|
// errManifestTooLarge indicates a manifest download that passed
|
|
// CLIApp.maxManifestSize.
|
|
var errManifestTooLarge = errors.New("manifest exceeds maximum allowed size")
|
|
|
|
// isHTTPURL returns true if the string starts with http:// or https://.
|
|
func isHTTPURL(s string) bool {
|
|
return strings.HasPrefix(s, "http://") || strings.HasPrefix(s, "https://")
|
|
}
|
|
|
|
// openManifestReader opens a manifest from a path or URL and returns a ReadCloser.
|
|
// The caller must close the returned reader.
|
|
func (mfa *CLIApp) openManifestReader(
|
|
ctx context.Context, pathOrURL string,
|
|
) (io.ReadCloser, error) {
|
|
if isHTTPURL(pathOrURL) {
|
|
client := &http.Client{Timeout: manifestFetchTimeout}
|
|
|
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, pathOrURL, nil)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to fetch %s: %w", pathOrURL, err)
|
|
}
|
|
|
|
resp, err := client.Do(req)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to fetch %s: %w", pathOrURL, err)
|
|
}
|
|
|
|
if resp.StatusCode != http.StatusOK {
|
|
_ = resp.Body.Close()
|
|
|
|
return nil, fmt.Errorf("failed to fetch %s: %w %d",
|
|
pathOrURL, errHTTPStatus, resp.StatusCode)
|
|
}
|
|
|
|
return resp.Body, nil
|
|
}
|
|
|
|
f, err := mfa.Fs.Open(pathOrURL)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
return f, nil
|
|
}
|
|
|
|
// resolveManifestArg resolves the manifest path from CLI arguments.
|
|
// HTTP(S) URLs are returned as-is. Directories are searched for index.mf.
|
|
// If no argument is given, the current directory is searched.
|
|
func (mfa *CLIApp) resolveManifestArg(cmd *cli.Command) (string, error) {
|
|
if cmd.Args().Len() > 0 {
|
|
arg := cmd.Args().Get(0)
|
|
if isHTTPURL(arg) {
|
|
return arg, nil
|
|
}
|
|
|
|
info, statErr := mfa.Fs.Stat(arg)
|
|
if statErr == nil && info.IsDir() {
|
|
return findManifest(mfa.Fs, arg)
|
|
}
|
|
|
|
return arg, nil
|
|
}
|
|
|
|
return findManifest(mfa.Fs, ".")
|
|
}
|