Objects fetched from the store are untrusted; several decode paths let one
expand or print without limit.
- blobgen.LimitReader errors past a byte cap (not io.LimitReader's silent
EOF). DecodeManifest reads through caps on both compressed input and
decompressed output, far above any real manifest, so json.Decode cannot
buffer a compressible bomb. FetchAndDecryptBlob bounds decompression to
the blob's recorded uncompressed_size (not the restoring host's
blob_size_limit).
- downloadSnapshotDB streams straight from storage to its temp file with
io.Copy, replacing two ReadAll calls that held the whole database twice.
- FetchBlob drops the per-blob Stat round-trip, its expectedSize parameter
and returned size, all of which only fed a debug log.
- TTYHandler and ui.Writer escape control characters in messages,
attribute keys/values, and rendered identifiers/paths before colour
codes are applied, so a crafted value cannot drive the terminal.
Model: opus-4-8