Conversation
|
|
Reviewed this against the same "parsing untrusted, machine-generated 1. The native-fs residual gap — can it be closed with the same 2. No compression-ratio guard — I think that's the right call here, and worth keeping. #22 floated a ratio heuristic; you (correctly, IMO) went with absolute caps only. 3. Defaults vs. the wasm target. The reporter calls out browser/WASM as the untrusted path, and that's where the 256 MiB entry / 1 GiB total defaults are least conservative — a single ~1 GiB allocation frequently fails on wasm32 (and on mobile browsers, well before that), so the process can still OOM inside the "allowed" envelope. Since the limits are already configurable, this may just be a docs note ("on wasm, tighten If helpful I can contribute a crafted-fixture test for the lying-header case (declared-small / inflates-past-cap) to pin the in-memory strict-bound behavior and document the native-fs difference — that's the case most likely to regress quietly. |
Fixes #22.
Reading a
.lottietrusted the ZIP-declared uncompressed size and read entries with no upper bound, so a crafted archive could force a huge up-front allocation or a decompression-bomb OOM.Adds a
Limitstype (max_entry_bytes/max_total_bytes/max_entries, default 256 MiB / 1 GiB / 10k, plusLimits::unlimited()) threaded throughfrom_bytes/from_file/open. Entry count is checked from the central directory before any decompression, each entry is read through a bounded reader that caps the initial allocation and errors past the cap, and the cumulative size is tracked across eager loads. Violations returnLimitExceeded.Breaking for the Rust API (new required
limitsarg). The JS bindings take an optional trailinglimitsobject, so existing JS callers are unaffected.Note: on the
native-fspath the underlying streaming reader materializes an entry (under its own ~2 GiB cap) before we can reject it, so theremaxEntryBytesbounds the accepted result rather than the transient peak. In-memoryfromBytesenforces the cap strictly.Test plan
cargo test -p dotlottie-io(default +--features native-fs)cargo clippy -p dotlottie-io --all-targetsclean