Skip to content

Do not size the caveat slice from the wire length - #52

Merged
mjbraun merged 1 commit into
mainfrom
bound-caveat-set-decode
Oct 8, 2026
Merged

mjbraun merged 1 commit into
mainfrom
bound-caveat-set-decode

Conversation

@mjbraun

@mjbraun mjbraun commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

CaveatSet.DecodeMsgpack reserved capacity for the number of caveats the array header claimed before reading any of them, so a few bytes could reserve gigabytes. Let append grow the slice as caveats actually decode.

CaveatSet.DecodeMsgpack reserved capacity for the number of caveats the
array header claimed before reading any of them, so a few bytes could
reserve gigabytes. Let append grow the slice as caveats actually decode.

Reported in HS 201317.
@mjbraun
mjbraun requested a review from timflyio October 8, 2026 19:25
@mjbraun
mjbraun merged commit 6d010fe into main Oct 8, 2026
1 check passed
@mjbraun
mjbraun deleted the bound-caveat-set-decode branch October 8, 2026 19:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants