check / check (push) Failing after 2s
AddFileWithHash took any non-empty bytes as a hash, so the builder could write a manifest that mfer refuses to load. It now decodes the hash with go-multihash and also requires a digest of at least 32 bytes, the SHA-256 length the reader's decoding-cost limit assumes: a valid but shorter multihash, such as an empty identity hash or SHA-1, still makes a manifest of one-character paths too costly to load. Test fixtures that used 34 zero bytes, which is not a valid multihash, now use a SHA-256 multihash. Model: opus-5-5
45 lines
1.5 KiB
Go
45 lines
1.5 KiB
Go
package mfer
|
|
|
|
const (
|
|
// Version is the current mfer release version.
|
|
Version = "0.1.0"
|
|
|
|
// ReleaseDate is the date on which Version was released.
|
|
ReleaseDate = "2025-12-17"
|
|
|
|
// MaxDecompressedSize is the maximum allowed size of decompressed manifest
|
|
// data (256 MB). This prevents decompression bombs from consuming excessive
|
|
// memory.
|
|
MaxDecompressedSize int64 = 256 * 1024 * 1024
|
|
|
|
// zstdWindowSize is the zstd window zstd.SpeedBestCompression gives mfer's writer.
|
|
zstdWindowSize = 8 << 20
|
|
|
|
// uuidLength is the length in bytes of a binary UUID.
|
|
uuidLength = 16
|
|
|
|
// Numbers in mf.proto of MFFile.files and of the MFFilePath fields
|
|
// that decoding sets aside a fixed amount of memory for.
|
|
filesFieldNumber = 101
|
|
hashesFieldNumber = 3
|
|
mimeTypeFieldNumber = 301
|
|
mtimeFieldNumber = 302
|
|
ctimeFieldNumber = 303
|
|
|
|
// Bytes decoding sets aside for each file entry, hash, timestamp and
|
|
// MIME type, however short its encoding. checkDecodedSize refuses an
|
|
// inner message for which these add up to more than maxDecodedGrowth
|
|
// times its size.
|
|
decodedFileEntrySize = 160
|
|
decodedHashSize = 112
|
|
decodedTimestampSize = 64
|
|
decodedMIMETypeSize = 16
|
|
|
|
// Each file entry mfer writes holds a path of at least one byte, a
|
|
// multihash at least as long as SHA-256's 34 bytes (AddFileWithHash
|
|
// refuses shorter ones) and a modification time: at least 47 bytes,
|
|
// counted at 336. So its manifests add up to at most about 7.15 times
|
|
// their size, and this limit is about 12% above that.
|
|
maxDecodedGrowth = 8
|
|
)
|