decryptStream causes unbounded memory growth
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 68/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- aws, node.js, typescript
- Domain
- backend, cloud, stream-processing
Research direction
Start at the _decryptStream entry point and inspect the pipeline connecting parseHeaderStream, verifyStream, and decipherStream to the PassThrough. Replace the unread output sink as described, then validate by streaming a large S3 object and confirming memory no longer grows with the object size.
Written by the indexing model from the issue text.
Description
Problem:
While using decryptStream to stream-decrypt large S3 objects, I noticed a memory increase roughly equal to the size of the object.
I think the issue is that _decryptStream returns a duplexify wrapper and internally runs a pipeline:
const stream = new Duplexify(parseHeaderStream, decipherStream)
pipeline(
parseHeaderStream,
verifyStream,
decipherStream,
new PassThrough(),
(err: Error) => {
if (err) stream.emit('error', err)
}
)
The caller reads from decipherStream via the duplexify wrapper. The pipeline also pushes decipherStream's output into the PassThrough. Since nothing ever reads from that PassThrough, its internal buffer appears to grow without bound.
Solution:
Replacing the PassThrough with a no-op Writable that discards chunks fixes the memory growth while still absorbing the destroy() call:
const drain = new Writable({
write(_chunk, _encoding, callback) {
callback()
},
})
pipeline(
parseHeaderStream,
verifyStream,
decipherStream,
drain,
(err: Error) => {
if (err) stream.emit('error', err)
}
)
I tested this change locally and the memory usage stopped increasing while streaming.
- Dominant language
- TypeScript
- Stars
- 260
- Forks
- 68
- PR merge metrics
- No merged PRs in 30d
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from aws/aws-encryption-sdk-javascript
-
Difficulty 4/5 3-5 days Newbie friendliness 68/100
aws/aws-encryption-sdk-javascript#1691 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
aws/aws-encryption-sdk-javascript#1665 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 52/100
aws/aws-encryption-sdk-javascript#1663 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
aws/aws-encryption-sdk-javascript#1520 · 1 comment ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
aws/aws-encryption-sdk-javascript#1192 · 3 comments ·
All issues in aws/aws-encryption-sdk-javascript
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
external-issue to-triage
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
diegosouzapw/OmniRoute#15401 ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
code-yeongyu/oh-my-openagent#9454 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
smart-village-solutions/sva-studio#1654 ·
Maintainers usually reply within 1 day