check / check (push) Waiting to run
NewManifestFromReader reads at most one byte past MaxManifestSize, a new constant of 258 MiB: the 256 MiB decompressed limit grown by zstd's worst case of 1/256, plus 1 MiB for the signature, the signing key and the other outer fields. It refuses a larger manifest. fetch, and check given a URL, stop downloading a manifest at the same point, so the refusal comes from the library. fetch stops reading a file one byte past its listed size, so a longer body ends in the size mismatch at once instead of filling the disk. docs/FORMAT.md states the limit and gives the decompressed limit as 256 MiB, the size the code uses. Model: opus-5-5
34 lines
908 B
Go
34 lines
908 B
Go
//nolint:testpackage // white-box tests exercise unexported internals
|
|
package mfer
|
|
|
|
import (
|
|
"io"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
// zeros is an io.Reader of zero bytes without end.
|
|
type zeros struct{}
|
|
|
|
func (zeros) Read(p []byte) (int, error) {
|
|
clear(p)
|
|
|
|
return len(p), nil
|
|
}
|
|
|
|
// TestNewManifestFromReaderRefusesTooLarge gives NewManifestFromReader
|
|
// 1 MiB more than MaxManifestSize. It must refuse the manifest after
|
|
// reading one byte past the maximum, and no more.
|
|
//
|
|
//nolint:paralleltest // holds 258 MiB; kept apart from other large reads
|
|
func TestNewManifestFromReaderRefusesTooLarge(t *testing.T) {
|
|
size := MaxManifestSize + 1<<20
|
|
input := &io.LimitedReader{R: zeros{}, N: size}
|
|
|
|
_, err := NewManifestFromReader(input)
|
|
require.ErrorIs(t, err, errManifestTooLarge)
|
|
assert.Equal(t, MaxManifestSize+1, size-input.N, "bytes read")
|
|
}
|