dschmidt commented on PR #3263:
URL: https://github.com/apache/tika/pull/3263#issuecomment-5969627181

   Thanks, all of it was right. Pushed as cb76702d51 and 3587532965, with main 
merged in (no force push):
   
   - Amplification: images are deduplicated per group by their data (offset, 
size), and all rebuilt icons together may take at most 4x the bytes of the 
resource section; beyond that extraction stops with a warning. The "closes a 
256x amplification" claim was wrong. I have not run your PoC; 
`testOutputBudgetAcrossGroups` and `testSharedImageDataInGroupIsRejected` cover 
the two paths, and I am happy to add yours if you send it. Is 4x the multiple 
you had in mind?
   - The section buffer grows with the bytes that arrive. File-backed input is 
no longer buffered at all, it is read at the offsets the tree points to.
   - `@deprecated since 4.2.0`, and a CHANGES entry that names default-on and 
`extractIcons`.
   - Fixture sources and build commands are in the test's class comment. A 
rebuild on Ubuntu 24.04 differs from the committed files only in the link 
timestamp and the checksum.
   - Config shape: left as is, as you suggested deferring it.
   
   A second review pass found more, fixed in the same commits: `e_lfanew == 
0x3f` threw an IllegalArgumentException since the switch to `skipFully`, a 
failing source was recorded as an embedded exception instead of failing the 
parse, the entry budget could run out among the icons before any group was 
read, and resource names went unchecked into the file name and the relationship 
id.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to