This is an automated email from the ASF dual-hosted git repository.
martin-g pushed a change to branch bound-allocated-bytes-for-fixed-schema-size
in repository https://gitbox.apache.org/repos/asf/avro-rs.git
omit e51c6d7 fix: Fixed-schema decode allocates attacker-chosen size with
no budget check
add fecaf4b fix: Nested collections multiply the 512MB allocation budget
arbitrarily
add 08c5625 fix: Fixed-schema decode allocates attacker-chosen size with
no budget check
This update added new revisions after undoing existing revisions.
That is to say, some revisions that were in the old version of the
branch are not in the new version. This situation occurs
when a user --force pushes a change and generates a repository
containing something like this:
* -- * -- B -- O -- O -- O (e51c6d7)
\
N -- N -- N
refs/heads/bound-allocated-bytes-for-fixed-schema-size (08c5625)
You should already have received notification emails for all of the O
revisions, and so the following emails describe only the N revisions
from the common base, B.
Any revisions marked "omit" are not gone; other references still
refer to them. Any revisions marked "discard" are gone forever.
No new revisions were added by this update.
Summary of changes:
avro/src/decode.rs | 137 +++++++++++++++++++++++++++++++++++----
avro/src/reader/block.rs | 4 +-
avro/src/reader/datum.rs | 11 +++-
avro/src/reader/single_object.rs | 4 +-
4 files changed, 141 insertions(+), 15 deletions(-)