Uh oh!
There was an error while loading. Please reload this page.
gh-132983: Don't allow trailer data in ZstdFile - #133736
Conversation
emmatyping
commented
May 9, 2025
The current behavior matches LZMA. I think unlike >>> from lzma import LZMAFile, compress
>>> from io import BytesIO
>>> invalid = compress(b'foo') +b'bar'
>>> LZMAFile(BytesIO(invalid)).read()
b'foo'
>>> |
Rogdham
commented
May 9, 2025
You are right this is the case for However, >>>fromlzmaimportLZMAFile, compress, FORMAT_XZ>>>fromioimportBytesIO>>>invalid=compress(b'foo') +b'bar'>>>LZMAFile(BytesIO(invalid), format=FORMAT_XZ).read()
Traceback (mostrecentcalllast):
File"<python-input-3>", line1, in<module>LZMAFile(BytesIO(invalid), format=FORMAT_XZ).read()
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^^File"/redacted/lzma.py", line208, inreadreturnself._buffer.read(size)
~~~~~~~~~~~~~~~~~^^^^^^File"/redacted/_compression.py", line118, inreadallwhiledata:=self.read(sys.maxsize):
~~~~~~~~~^^^^^^^^^^^^^File"/redacted/_compression.py", line99, inreadraiseEOFError("Compressed file ended before the ""end-of-stream marker was reached")
EOFError: Compressedfileendedbeforetheend-of-streammarkerwasreached |
In addition, consider
Since for |
Thanks @Rogdham for the PR, and @AA-Turner for merging it 🌮🎉.. I'm working now to backport this PR to: 3.14. |
(cherry picked from commit 50b5370) Co-authored-by: Rogdham <3994389+Rogdham@users.noreply.github.com>
GH-133799 is a backport of this pull request to the 3.14 branch. |
We previously made sure that an exception is raised when decompressing trailer data with
decompress:Indeed, the Zstandard specification says “Zstandard compressed data is made of one or more frames”, and it does not say that random data can be added at the end.
However, this is not the case in
ZstdFile/zstd.open:After this PR, the last call becomes: