Files
Matt Godbolt (bot acct) 51317dc13f Cap conan package extraction size; require http(s) package URLs (#8820)
Fixes #8817. Kept deliberately simple per discussion — the conan server
is CE's own infrastructure, so these are hygiene bounds, not attack
mitigations:

- A generous fixed 2GiB cap on the total declared size of extracted
files (tar-stream enforces entry bodies match their headers, so summing
`header.size` bounds bytes written). Real packages are tens to a few
hundred MiB; hitting this means a packaging error or a corrupt/bombed
archive, and the extraction rejects cleanly through the existing error
path.
- The package URL conan returns must be http(s). No redirect
restrictions (conan may legitimately hand out redirecting/presigned
URLs), no config plumbing.

Both paths tested (cap exercised by lowering the limit on the instance
under test; scheme via a `file://` URL).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: mattgodbolt-molty <mattgodbolt-molty@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 22:25:07 +01:00
..
2026-06-04 23:41:19 +02:00
2026-06-04 23:41:19 +02:00
2025-07-28 10:34:46 -05:00
2025-07-28 10:34:46 -05:00
2026-06-02 12:19:29 -05:00
2026-05-23 14:47:16 +03:00