fix: close workspace preprocessing contract gaps
This commit is contained in:
@@ -29,8 +29,11 @@ const (
|
||||
maxAssumptions = 256
|
||||
maxAssumptionBytes = 256
|
||||
maxResult = 1 << 20
|
||||
maxCandidate = 700 << 10
|
||||
maxAnnotations = 16 << 20
|
||||
// Requests carry up to 16 MiB of raw SQL or annotation bytes encoded as base64.
|
||||
// This is deliberately independent from maxResult, which bounds child stdout.
|
||||
maxRequest = 24 << 20
|
||||
maxCandidate = 700 << 10
|
||||
maxAnnotations = 16 << 20
|
||||
)
|
||||
|
||||
var workspaceIDPattern = regexp.MustCompile(`^[a-z][a-z0-9-]{2,62}$`)
|
||||
@@ -392,7 +395,7 @@ func makeInput(c Command) (inputEnvelope, string, error) {
|
||||
if e != nil {
|
||||
return env, "", e
|
||||
}
|
||||
if len(payload) > maxResult {
|
||||
if len(payload) > maxRequest {
|
||||
return env, "", errors.New("request exceeds limit")
|
||||
}
|
||||
return env, string(payload), nil
|
||||
@@ -461,8 +464,8 @@ func Run(ctx context.Context, installation config.Installation, runner compose.R
|
||||
}
|
||||
payload := []byte(generated)
|
||||
if stdin != nil {
|
||||
payload, e = io.ReadAll(io.LimitReader(stdin, maxResult+1))
|
||||
if e != nil || len(payload) > maxResult {
|
||||
payload, e = io.ReadAll(io.LimitReader(stdin, maxRequest+1))
|
||||
if e != nil || len(payload) > maxRequest {
|
||||
return Result{}, errors.New("request exceeds limit")
|
||||
}
|
||||
if e = validateIngress(payload, env); e != nil {
|
||||
|
||||
Reference in New Issue
Block a user