szaszm opened a new pull request, #2251:
URL: https://github.com/apache/nifi-minifi-cpp/pull/2251

   …ld be limited
   
   It's used on network streams, and we want to avoid letting compromised 
network peers allocate large buffers on memory-constrained systems. This issue 
was pointed out in a security report, but given the trusted nature of the C2 
server and S2S peers, we treat this as a defense-in-depth mitigation measure.
   
   I've used symbolic constants for the limit at some but not all places. When 
there was no obvious place to put a constant to make it widely reusable, I've 
skipped them. The limits are not meant to be precise, but just a rough upper 
bound to the strings in that context. I've not modified the corresponding 
OutputStream::write overload.
   
   This mitigation is just a "quick fix". A proper fix would involve rethinking 
how to manage streams in the project, and separating streams from 
readers/writers that serialize data from/onto them, but that would be a scary 
big undertaking.
   
   -----------------
   Thank you for submitting a contribution to Apache NiFi - MiNiFi C++.
   
   In order to streamline the review of the contribution we ask you to ensure 
the following steps have been taken:
   
   ### For all changes:
   - [x] Is there a JIRA ticket associated with this PR? Is it referenced in 
the commit message?
   
   - [x] Does your PR title start with MINIFICPP-XXXX where XXXX is the JIRA 
number you are trying to resolve? Pay particular attention to the hyphen "-" 
character.
   
   - [x] Has your PR been rebased against the latest commit within the target 
branch (typically main)?
   
   - [x] Is your initial contribution a single, squashed commit?
   
   ### For code changes:
   - [x] If adding new dependencies to the code, are these dependencies 
licensed in a way that is compatible for inclusion under [ASF 
2.0](http://www.apache.org/legal/resolved.html#category-a)?
   - [x] If applicable, have you updated the LICENSE file?
   - [x] If applicable, have you updated the NOTICE file?
   
   ### For documentation related changes:
   - [x] Have you ensured that format looks appropriate for the output in which 
it is rendered?
   
   ### Note:
   Please ensure that once the PR is submitted, you check GitHub Actions CI 
results for build issues and submit an update to your PR as soon as possible.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to