Skip to content

Workflow status is tracked in GitHub. This local document is retained as an engineering spec/evidence record.

ED2KSRV-BUG-001 - Bound packed-frame decompression

Summary

Packed 0xD4 frames are decompressed into an unbounded buffer after only the compressed wire length has been bounded. Add an independent configurable ceiling for decompressed output so a small zlib payload cannot exhaust process memory.

Current State

src/proto/frame.rs uses flate2::read::ZlibDecoder::read_to_end without an output ceiling.

Scope Constraints

  • Preserve valid stock eMule/aMule packed-frame behavior.
  • Use standard bounded I/O/decompression mechanisms.
  • Treat malformed and oversized input as a connection-level protocol error, not a process failure.
  • Tag, string, and collection parser limits are tracked separately by ED2KSRV-BUG-005.

Acceptance Criteria

  • [ ] Compressed wire length and decompressed output have independent explicit ceilings.
  • [ ] The decompressed ceiling is configurable and defaults safely for existing configurations.
  • [ ] Decompression terminates after at most one byte beyond the configured ceiling.
  • [ ] Normal, exact-boundary, limit-plus-one, high-expansion, truncated-stream, and wire-limit regression tests pass.
  • [ ] Plain frames and valid packed frames retain their existing behavior.

Validation

Run locked unit/integration tests, formatting, Clippy, and the managed Linux release build.