Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 10 additions & 3 deletions src/clusterfuzz/_internal/bot/tasks/utasks/uworker_io.py
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,11 @@
import uuid
import zlib

# Maximum decompressed size for uworker messages (256 MB).
# Prevents a malicious or compromised uworker from causing an OOM
# on the trusted tworker via a zlib decompression bomb.
_MAX_UWORKER_MSG_SIZE = 256 * 1024 * 1024

from google.cloud import ndb
from google.cloud.datastore_v1.types import entity as entity_pb2
from google.cloud.ndb import model
Expand Down Expand Up @@ -126,7 +131,7 @@ def download_and_deserialize_uworker_input(
download URL."""
data = storage.download_signed_url(uworker_input_download_url)
try:
data = zlib.decompress(data)
data = zlib.decompress(data, max_length=_MAX_UWORKER_MSG_SIZE)
except zlib.error:
# This is for backward compatiblity during the merge.
# TOOD(metzman): Remove backward compatibility efforts when every
Expand Down Expand Up @@ -167,7 +172,8 @@ def download_input_based_on_output_url(
input_url = uworker_output_path_to_input_path(output_url)
data = storage.read_data(input_url)
try:
serialized_uworker_input = zlib.decompress(data)
serialized_uworker_input = zlib.decompress(
data, max_length=_MAX_UWORKER_MSG_SIZE)
except zlib.error:
# For backwards compatability support uncompressed.
serialized_uworker_input = data
Expand All @@ -181,7 +187,8 @@ def download_and_deserialize_uworker_output(
"""Downloads and deserializes uworker output."""
data = storage.read_data(output_url)
try:
serialized_uworker_output = zlib.decompress(data)
serialized_uworker_output = zlib.decompress(
data, max_length=_MAX_UWORKER_MSG_SIZE)
except zlib.error:
# For backwards compatability support uncompressed.
serialized_uworker_output = data
Expand Down