Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Patch blob and diff downloads buffer the whole response body with no size cap

Chiusa Adatta ai principianti
#571 5 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@mikolalysenko ci sta già lavorando.

Dal 2/10/2026.

  • #607 di @mikolalysenko — aperta

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
84/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
rust
Ambito
api

Direzione di ricerca

Inizia da crates/socket-patch-core/src/api/client.rs, in ApiClient::fetch_binary, poi leggi utils/http.rs e la gestione esistente dei download dei vendor per la mappatura degli errori di capped-reader. Esegui i test indicati per blob e binary fetcher prima di apportare modifiche. Il lavoro è completato quando le risposte blob e diff sovradimensionate falliscono al raggiungimento del limite senza buffering illimitato, mentre i test e2e elencati continuano a passare.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

agent:claimed agent:triaged arch-audit bug priority:p3

[agent] Filed by the scheduled architecture audit routine (CLI and core). Register: discussion #560 register.

Kind: bug. Source: new finding (not in the October review); register C37.

Problem

ApiClient::fetch_binary, which backs fetch_blob and fetch_diff, reads a 200 response with resp.bytes().await and applies no bound (api/client.rs#L1089-L1099). The bytes are hash-checked only after they are fully in memory.

The crate already has a shared capped body reader for this. utils::http::read_capped / read_capped_typed (utils/http.rs#L22-L40) rejects an over-large Content-Length and an over-long stream. Its doc says it was hoisted "so the self-update downloader shares the exact cap semantics". It is used by:

The patch blob and diff path, which is the one every apply/get hits, bypasses it. The diff archive's decompressed size is capped later, at 64 MiB in patch/package.rs, but the download itself is not.

Reproduced twice on main @ 1169ae6 with an integration test against ApiClient (not committed). A local server answers the authenticated blob URL with a 600 MiB application/octet-stream body. fetch_blob returned Ok(Some(len = 629145600)), buffering 600 MiB, more than twice the cap the vendor path enforces on the same client.

Symptoms

None filed.

Impact

A misbehaving or hostile endpoint can exhaust memory with one response: a mis-set --api-url/SOCKET_API_URL, a proxy, or the public patch proxy serving a wrong file. The blob is rejected afterwards anyway. This is low-to-medium risk, a consistency defect with a small fix.

Proposed change
  • In fetch_binary, replace resp.bytes() with read_capped_typed(resp, MAX_PATCH_BLOB_BYTES, kind) and map CapExceeded / Truncated onto ApiError the way the vendor path does.
  • Choose one named cap. 64 MiB matches the per-file cap the patch engine applies elsewhere (MAX_FILE_BYTES, patch/package.rs).
  • No new reader. This deletes the last uncapped bytes() body read in api/.
Size and scope

api/client.rs, ~15–30 production lines plus one test. Out of scope: timeouts (#570) and retry for blob/diff (C15).

Acceptance criteria
  • Regression tests: a blob response over the cap, either by Content-Length or by stream length, returns an error without buffering past the cap. A diff response gets the same test.
  • binary_fetch_error_classification_e2e, blob_fetcher_edges_e2e and covgap_api_blob_fetcher stay green.
Dependencies

None. It is best landed with or next to #570 because both touch fetch_binary.

Lingua principale
Rust
Stelle
8
Fork
0
Merge medio
1g 1h
PR unite (30g)
257

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di SocketDev/socket-patch

Tutte le issue di SocketDev/socket-patch

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.