check / check (push) Canceled after 0s
NewManifestFromReader reads at most one byte past MaxManifestSize, a new constant of 258 MiB: the 256 MiB decompressed limit grown by zstd's worst case of 1/256, plus 1 MiB for the signature, the signing key and the other outer fields. It refuses a larger manifest. fetch, and check given a URL, stop downloading a manifest one byte past the same size and report it as too large; tests lower that size to keep their memory small. fetch stops reading a file one byte past its listed size, so a longer body ends in the size mismatch at once instead of filling the disk. docs/FORMAT.md states the limit and gives the decompressed limit as 256 MiB, the size the code uses. Model: opus-5-5
52 lines
1.9 KiB
Go
52 lines
1.9 KiB
Go
package mfer
|
|
|
|
const (
|
|
// Version is the current mfer release version.
|
|
Version = "0.1.0"
|
|
|
|
// ReleaseDate is the date on which Version was released.
|
|
ReleaseDate = "2025-12-17"
|
|
|
|
// MaxDecompressedSize is the maximum allowed size of decompressed manifest
|
|
// data (256 MiB). This prevents decompression bombs from consuming excessive
|
|
// memory.
|
|
MaxDecompressedSize int64 = 256 * 1024 * 1024
|
|
|
|
// MaxManifestSize is the largest manifest file mfer reads (258 MiB).
|
|
// zstd's worst case grows data it cannot compress by 1/256, so an inner
|
|
// message of MaxDecompressedSize compresses to at most 257 MiB; the
|
|
// last MiB is room for the signature, the signing key and the other
|
|
// outer fields.
|
|
MaxManifestSize = MaxDecompressedSize + MaxDecompressedSize/256 + 1<<20
|
|
|
|
// zstdWindowSize is the zstd window zstd.SpeedBestCompression gives mfer's writer.
|
|
zstdWindowSize = 8 << 20
|
|
|
|
// uuidLength is the length in bytes of a binary UUID.
|
|
uuidLength = 16
|
|
|
|
// Numbers in mf.proto of MFFile.files and of the MFFilePath fields
|
|
// that decoding sets aside a fixed amount of memory for.
|
|
filesFieldNumber = 101
|
|
hashesFieldNumber = 3
|
|
mimeTypeFieldNumber = 301
|
|
mtimeFieldNumber = 302
|
|
ctimeFieldNumber = 303
|
|
|
|
// Bytes decoding sets aside for each file entry, hash, timestamp and
|
|
// MIME type, however short its encoding. checkDecodedSize refuses an
|
|
// inner message for which these add up to more than maxDecodedGrowth
|
|
// times its size. The mode is held in the file entry itself.
|
|
decodedFileEntrySize = 176
|
|
decodedHashSize = 112
|
|
decodedTimestampSize = 64
|
|
decodedMIMETypeSize = 16
|
|
|
|
// Each file entry mfer writes holds a path of at least one byte, a
|
|
// multihash at least as long as SHA-256's 34 bytes (AddFileWithHash
|
|
// refuses shorter ones) and a modification time: at least 47 bytes,
|
|
// counted at 352. So its manifests add up to at most about 7.49 times
|
|
// their size, and this limit is about 7% above that.
|
|
maxDecodedGrowth = 8
|
|
)
|