tomasilluminati commented on PR #777:
URL: https://github.com/apache/commons-compress/pull/777#issuecomment-5754887997

   Pushed the second version. It is the shape we settled on: size limit only,
   configured through 
`CompressorStreamFactory.builder().setMaxDecompressedSize(long)`,
   composed over `BoundedInputStream` with `setMaxCount` and a throwing
   `setOnMaxCount`. The guard class and its exception are gone; the limit throws
   `CompressorException`. The factory got a builder rather than a fourth
   constructor, following the review; the existing constructors are untouched.
   
   One detail worth a look: the callback reads a single byte from the 
decompressor
   before throwing, so a stream of exactly the limit reads to EOF and only real
   excess fails. Without that, `IOUtils.toByteArray` on a legitimate file of
   exactly N bytes would throw, and Piotr's idea of using a declared entry size
   as the limit would not work.
   
   `CompressorInputStream` now implements `InputStreamStatistics`; the base
   `getCompressedCount()` returns -1 and keeps the interface's `throws
   IOException` so subclasses that already declare it keep compiling.
   
   Rebased on master; the branch name still says bomb-guard because the PR is
   bound to it.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to