oscerd opened a new pull request, #26892:
URL: https://github.com/apache/camel/pull/26892

   JIRA: https://issues.apache.org/jira/browse/CAMEL-25023
   
   ## Description
   
   `IOHelper.copy(InputStream, OutputStream, int, boolean, long maxSize)` kept 
its running byte count in an `int`. An `int` cannot exceed `Integer.MAX_VALUE` 
and wraps to a negative value after 2 GiB. So a `maxSize` of 
`Integer.MAX_VALUE` or more, or one within a read buffer below it, never 
triggered the check, and the return value went negative for copies larger than 
2 GiB.
   
   This overload implements the `maxDecompressedSize` option for 
`ZipFileDataFormat.unmarshal`, `ZipIterator`/`ZipSplitter` and 
`TarFileDataFormat.unmarshal`, so any configured limit of 2 GiB or more was 
ignored. The 1 GiB default was enforced correctly. `TarIterator` is not 
affected: it uses a long-based `BoundedInputStream`.
   
   ## Changes
   
   - `IOHelper.copy` counts in a `long` and returns `(int) Math.min(total, 
Integer.MAX_VALUE)`, so the public signature is unchanged. The Javadoc now 
documents `maxSize` and the capped return value.
   - New tests in `IOHelperTest`, which use synthetic zero streams so they need 
no heap or disk:
     - Copies past limits of `Integer.MAX_VALUE - 100`, `Integer.MAX_VALUE`, 2 
GiB and 5 GiB, expecting the `IOException`.
     - Checks the capped return value for a 3 GiB copy.
     - Pins the existing boundary: exactly `maxSize` bytes pass, and one more 
byte fails.
   - Upgrade guide (4.23): a note that limits of 2 GiB or more are now enforced.
   
   ## Testing
   
   - `IOHelperTest`: all 5 tests pass. The two overflow tests fail on the code 
before this change (the limit is not enforced, and the return value is 
`-1073741824`).
   - The `camel-zipfile` and `camel-tarfile` test suites pass.
   - Full reactor build (`mvn clean install -DskipTests`) with no 
generated-file drift.
   
   Backports to `camel-4.22.x` and `camel-4.18.x` will follow once this is 
merged.
   
   _Claude Code on behalf of oscerd_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to