check / check (push) Waiting to run
FuzzNewManifestFromReader fails when the parser returns both or neither of a manifest and an error, or allocates more than a fixed multiple of its input and the decompressed data it may read, plus room for the decoder's window buffers. make test runs the seed corpus; make fuzz fuzzes for one minute. Parser bug: MaxDecompressedSize did not bound decompression; the zstd decoder decoded a payload under 128 KiB in full before the LimitReader read any of it. It now decodes only what the LimitReader reads and refuses windows over the 8 MiB mfer writes with. Seeds: a frame claiming 8 GiB, two frames together over the limit, empty frames with growing windows. Model: opus-5-5
21 lines
581 B
Go
21 lines
581 B
Go
package mfer
|
|
|
|
const (
|
|
// Version is the current mfer release version.
|
|
Version = "0.1.0"
|
|
|
|
// ReleaseDate is the date on which Version was released.
|
|
ReleaseDate = "2025-12-17"
|
|
|
|
// MaxDecompressedSize is the maximum allowed size of decompressed manifest
|
|
// data (256 MB). This prevents decompression bombs from consuming excessive
|
|
// memory.
|
|
MaxDecompressedSize int64 = 256 * 1024 * 1024
|
|
|
|
// zstdWindowSize is the zstd window zstd.SpeedBestCompression gives mfer's writer.
|
|
zstdWindowSize = 8 << 20
|
|
|
|
// uuidLength is the length in bytes of a binary UUID.
|
|
uuidLength = 16
|
|
)
|