Closed Bug 1212600 Opened 9 years ago Closed 8 years ago

No upper limit on digest256 list file size

Categories

(Toolkit :: Safe Browsing, defect)

43 Branch
defect
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla43
Tracking Status
firefox48 --- fixed

People

(Reporter: mwobensmith, Assigned: dimi)

References

Details

(Whiteboard: tpe-seceng)

Attachments

(1 file)

Some error/boundary tests revealed that Firefox accepted and parsed an 88mb list file. We don't anticipate ever supporting a list file that big, and in fact would like to limit the list size to something more reasonable, such as 32mb. 

As per discussion with François, we'd probably want to reject this condition at download time, parse time, or both.
Blocks: 1149867
Component: DOM: Security → Safe Browsing
Product: Core → Toolkit
Summary: No upper limit on shaver list file size → No upper limit on digest256 list file size
Assignee: francois → nobody
Whiteboard: tpe-seceng
Assignee: nobody → dlee
Comment on attachment 8735383 [details]
MozReview Request: Bug 1212600 - No upper limit on digest256 list file size. r=francois

https://reviewboard.mozilla.org/r/42765/#review39233
Attachment #8735383 - Flags: review?(francois) → review+
Comment on attachment 8735383 [details]
MozReview Request: Bug 1212600 - No upper limit on digest256 list file size. r=francois

gcp, does that look reasonable to you too?
Attachment #8735383 - Flags: review?(gpascutto)
Comment on attachment 8735383 [details]
MozReview Request: Bug 1212600 - No upper limit on digest256 list file size. r=francois

https://reviewboard.mozilla.org/r/42765/#review39479

Looks fine, but we should consider gathering these limits together. (i.e. this + MAX_CHUNK_SIZE, MAX_CHUNK_RANGE, etc)
Attachment #8735383 - Flags: review?(gpascutto) → review+
Keywords: checkin-needed
https://hg.mozilla.org/mozilla-central/rev/7c857bd36bc2
Status: NEW → RESOLVED
Closed: 8 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: