tomasilluminati commented on PR #777: URL: https://github.com/apache/commons-compress/pull/777#issuecomment-5754887997
Pushed the second version. It is the shape we settled on: size limit only, configured through `CompressorStreamFactory.builder().setMaxDecompressedSize(long)`, composed over `BoundedInputStream` with `setMaxCount` and a throwing `setOnMaxCount`. The guard class and its exception are gone; the limit throws `CompressorException`. The factory got a builder rather than a fourth constructor, following the review; the existing constructors are untouched. One detail worth a look: the callback reads a single byte from the decompressor before throwing, so a stream of exactly the limit reads to EOF and only real excess fails. Without that, `IOUtils.toByteArray` on a legitimate file of exactly N bytes would throw, and Piotr's idea of using a declared entry size as the limit would not work. `CompressorInputStream` now implements `InputStreamStatistics`; the base `getCompressedCount()` returns -1 and keeps the interface's `throws IOException` so subclasses that already declare it keep compiling. Rebased on master; the branch name still says bomb-guard because the PR is bound to it. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
