Files
mfer/mfer/deserialize_test.go
T
clawbot aad3279c39
check / check (push) Waiting to run
Limit how much fetch and check read for a manifest or a file (closes #168)
NewManifestFromReader reads at most one byte past MaxManifestSize, a new
constant of 258 MiB: the 256 MiB decompressed limit grown by zstd's worst
case of 1/256, plus 1 MiB for the signature, the signing key and the
other outer fields. It refuses a larger manifest. fetch, and check given
a URL, stop downloading a manifest at the same point, so the refusal
comes from the library. fetch stops reading a file one byte past its
listed size, so a longer body ends in the size mismatch at once instead
of filling the disk. docs/FORMAT.md states the limit and gives the
decompressed limit as 256 MiB, the size the code uses.

Model: opus-5-5
2026-10-07 09:59:50 +00:00

34 lines
908 B
Go

//nolint:testpackage // white-box tests exercise unexported internals
package mfer
import (
"io"
"testing"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
)
// zeros is an io.Reader of zero bytes without end.
type zeros struct{}
func (zeros) Read(p []byte) (int, error) {
clear(p)
return len(p), nil
}
// TestNewManifestFromReaderRefusesTooLarge gives NewManifestFromReader
// 1 MiB more than MaxManifestSize. It must refuse the manifest after
// reading one byte past the maximum, and no more.
//
//nolint:paralleltest // holds 258 MiB; kept apart from other large reads
func TestNewManifestFromReaderRefusesTooLarge(t *testing.T) {
size := MaxManifestSize + 1<<20
input := &io.LimitedReader{R: zeros{}, N: size}
_, err := NewManifestFromReader(input)
require.ErrorIs(t, err, errManifestTooLarge)
assert.Equal(t, MaxManifestSize+1, size-input.N, "bytes read")
}