Skip to content

Commit 2c9b12d

Browse files
Ignore data after the end of the stream in the capped inflate
With decompressed_max_bytes in effect, a value whose compressed form had bytes after the end of its zlib or gzip stream (a second stream or member, or trailing junk) came back with those bytes appended, because Zlib::Inflate#finish returns them. The uncapped path, like the code before the cap, ignores them. The capped path now stops at the end of the stream. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
1 parent 1cf990d commit 2c9b12d

2 files changed

Lines changed: 13 additions & 0 deletions

File tree

‎lib/dalli/compressor.rb‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,12 @@ def self.inflate_within_limit(inflater, data, max_bytes)
3939
out = String.new(encoding: Encoding::BINARY)
4040
0.step(data.bytesize - 1, INFLATE_SLICE_BYTES) do |pos|
4141
inflate_slice(inflater, data.byteslice(pos, INFLATE_SLICE_BYTES), out, max_bytes)
42+
# Anything after the end of the stream isn't part of the value, as
43+
# with Zlib::Inflate.inflate; finish would return it as output
44+
break if inflater.finished?
4245
end
46+
return out if inflater.finished?
47+
4348
append_within_limit(out, inflater.finish, max_bytes)
4449
ensure
4550
inflater.close

‎test/test_compressor.rb‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,6 +42,14 @@
4242
assert_raises(Dalli::UnmarshalError) { compressor.decompress(bomb, max_bytes: 1024 * 1024) }
4343
end
4444

45+
# Bytes after the end of the compressed stream aren't part of the value,
46+
# whichever path inflates it
47+
it 'ignores data after the end of the stream, as without max_bytes' do
48+
["#{compressed}TRAILER", compressed + compressed, compressed + ('x' * 200_000)].each do |input|
49+
assert_equal compressor.decompress(input).b, compressor.decompress(input, max_bytes: 10_000_000).b
50+
end
51+
end
52+
4553
it 'has no limit without max_bytes' do
4654
assert_equal data.b, compressor.decompress(compressed).b
4755
end

0 commit comments

Comments
 (0)