Skip to content

fix(resolution): reject oversized targets before decoding (#1553) - #2006

Merged
colbymchenry merged 1 commit into
mainfrom
fix/1553-oversized-resolution-reads
Sep 27, 2026
Merged

colbymchenry merged 1 commit into
mainfrom
fix/1553-oversized-resolution-reads

Conversation

@colbymchenry

Copy link
Copy Markdown
Owner

Problem

Workspace imports could decode excluded dependency archives without a size limit, causing large allocations.

Fix

Reapply only PR #1583's targeted guard and sparse-HAR test, sharing extraction's existing 1 MiB limit. Reject non-files and oversized targets before decoding and cache rejection. Extend coverage using real SQLite and valid ohpm imports.

Validation

  • repro.sh "$PWD": before exit 1 with a 2,097,152-character decode; after exit 0 with zero HAR reads.
  • Four new tests fail without the guard; all five pass with it.
  • npx vitest run __tests__/resolution-file-read.test.ts __tests__/resolution.test.ts __tests__/arkts-resolution.test.ts __tests__/extraction.test.ts __tests__/daemon-pid-reuse.test.ts: 890 passed; daemon test required rerunning with daemon enabled.
  • npx vitest run __tests__/daemon-pid-reuse.test.ts: passed with CODEGRAPH_NO_DAEMON unset.
  • npx tsc && npm run copy-assets, npx tsc --noEmit, and git diff --check: passed.
  • Corrected the external repro script's error message to handle the expected null result.

Fixes #1553

🤖 Generated with Claude Code

Workspace imports could follow excluded dependency archives and decode them without a size guard.
Reuse extraction's 1 MiB limit, reject non-files before reading, and cache null results.
Add sparse-HAR and real ohpm indexing coverage while preserving legitimate import edges.

Co-authored-by: danusha2345 <ewidusoc498@gmail.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant