You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 39d2f72
Browse filesBrowse the repository at this point in the historyBrowse files
- Values flagged as compressed were inflated with no size limit, so a
~130 KB stored item could expand to 128 MB on read (about 1000:1),
whatever the client's compress or serializer settings. A new
decompressed_max_bytes option (default 128 MiB, nil for no limit) caps
it: the built-in Deflate and Gzip compressors inflate in chunks and
raise UnmarshalError as soon as the output passes the limit. Custom
compressors whose decompress takes only the data keep working, without
the limit.
- The size in a VA reply was passed straight to IO#read, which allocates
that many bytes up front, so a hostile server could make the client
allocate gigabytes. Sizes over 1 GiB (memcached's largest item) or
negative now raise DalliError before any read, on the single-key paths
and in the pipelined parser.
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
0 commit comments