fix(security): bound git-history parsing to prevent DoS - #146
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
git log -pintobufio.Reader.ReadString('\n')and usedcontext.Background()for the CLI, which allows unbounded per-line allocations and unbounded runtime when processing attacker-controlled repository history.Description
git logstdout to 256 MiB using anio.LimitedReaderand cancel the Git subprocess when the limit is exceeded to avoid unbounded output processing.ReadStringcalls with a newreadBoundedLinehelper that retains at most 64 KiB per diff line while draining the remainder so oversized single lines cannot cause large allocations or skip subsequent lines.scan-historyCLI by usingcontext.WithTimeoutto prevent unbounded scan execution.TestReadBoundedLineDrainsOversizedLinethat verifies oversized lines are truncated in-memory while subsequent lines remain readable.Testing
go test ./internal/codeguard/history ./internal/cli ./pkg/codeguardran and passed.go test ./...ran and passed.git diff --cached --checkran and passed.fix(security): bound git history secret scansand staged files verified viagit status --short --branch(all checks succeeded).Codex Task