Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

decryptStream causes unbounded memory growth

Open Beginner friendly
#1,656 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
68/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Quiet
Tech stack
aws, node.js, typescript

Research direction

Start at the _decryptStream entry point and inspect the pipeline connecting parseHeaderStream, verifyStream, and decipherStream to the PassThrough. Replace the unread output sink as described, then validate by streaming a large S3 object and confirming memory no longer grows with the object size.

Written by the indexing model from the issue text.

Description

Problem:

While using decryptStream to stream-decrypt large S3 objects, I noticed a memory increase roughly equal to the size of the object.

I think the issue is that _decryptStream returns a duplexify wrapper and internally runs a pipeline:

const stream = new Duplexify(parseHeaderStream, decipherStream)

pipeline(
  parseHeaderStream,
  verifyStream,
  decipherStream,
  new PassThrough(),
  (err: Error) => {
    if (err) stream.emit('error', err)
  }
)

The caller reads from decipherStream via the duplexify wrapper. The pipeline also pushes decipherStream's output into the PassThrough. Since nothing ever reads from that PassThrough, its internal buffer appears to grow without bound.

Solution:

Replacing the PassThrough with a no-op Writable that discards chunks fixes the memory growth while still absorbing the destroy() call:

const drain = new Writable({
  write(_chunk, _encoding, callback) {
    callback()
  },
})

pipeline(
  parseHeaderStream,
  verifyStream,
  decipherStream,
  drain,
  (err: Error) => {
    if (err) stream.emit('error', err)
  }
)

I tested this change locally and the memory usage stopped increasing while streaming.

Dominant language
TypeScript
Stars
260
Forks
68
PR merge metrics
No merged PRs in 30d

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from aws/aws-encryption-sdk-javascript

All issues in aws/aws-encryption-sdk-javascript

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.