Skip to content

Commit e356cca

Browse files
oschwaldclaude
andcommitted
Tidy the changelog wording for the decoder limits
The changelog and the macro comment called the Reader Resource Limits guidance proposed. The MaxMind DB specification change has merged (maxmind/MaxMind-DB#282). The second bullet also now says "denial-of-service issue" to match the first. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
1 parent d9361c0 commit e356cca

2 files changed

Lines changed: 15 additions & 16 deletions

File tree

‎Changes.md‎

Lines changed: 13 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -5,20 +5,19 @@
55
one entry cost exponential time and memory from a small file. The decoder now
66
limits each returned list to 65,536 values and returns
77
`MMDB_DECODER_LIMIT_ERROR` when an entry exceeds it. The largest real records
8-
MaxMind produces decode a few hundred values. This follows the proposed Reader
9-
Resource Limits guidance for the MaxMind DB specification. See
10-
GHSA-hj94-g986-h9r7.
11-
- Fixed a related payload-amplification denial of service. A crafted database
12-
can point many times at one large value, so `MMDB_get_entry_data_list()`
13-
returns a bounded number of nodes that together reference far more bytes than
14-
the file holds. A caller that copies each node into a string then materializes
15-
that amplified total. The decoder now also limits the total string and bytes
16-
payload it exposes for a single entry to 2 MiB. Exceeding either new limit
17-
returns `MMDB_DECODER_LIMIT_ERROR` and leaves the output list set to `NULL`.
18-
These limits also protect the `languages` and `description` structures read by
19-
`MMDB_open()`, where an over-limit structure is reported as
20-
`MMDB_INVALID_METADATA_ERROR`. Both limits can be raised when rebuilding the
21-
library with `-DMAXIMUM_DATA_STRUCTURE_VALUES=<values>` and
8+
MaxMind produces decode a few hundred values. This follows the Reader Resource
9+
Limits guidance in the MaxMind DB specification. See GHSA-hj94-g986-h9r7.
10+
- Fixed a related payload-amplification denial-of-service issue. A crafted
11+
database can point many times at one large value, so
12+
`MMDB_get_entry_data_list()` returns a bounded number of nodes that together
13+
reference far more bytes than the file holds. A caller that copies each node
14+
into a string then materializes that amplified total. The decoder now also
15+
limits the total string and bytes payload it exposes for a single entry to 2
16+
MiB. Exceeding either new limit returns `MMDB_DECODER_LIMIT_ERROR` and leaves
17+
the output list set to `NULL`. These limits also protect the `languages` and
18+
`description` structures read by `MMDB_open()`, where an over-limit structure
19+
is reported as `MMDB_INVALID_METADATA_ERROR`. Both limits can be raised when
20+
rebuilding the library with `-DMAXIMUM_DATA_STRUCTURE_VALUES=<values>` and
2221
`-DMAXIMUM_DATA_STRUCTURE_BYTES=<bytes>`. Applications using a packaged
2322
library can retrieve individual values with `MMDB_get_value()` or
2423
`MMDB_aget_value()` without expanding the complete structure. See

‎src/maxminddb.c‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,8 +38,8 @@ typedef ADDRESS_FAMILY sa_family_t;
3838
// The maximum number of data-section values decoded for a single entry. This
3939
// bounds a pointer fan-out, where nested pointers to shared targets would
4040
// otherwise cost 2**depth decode operations. The largest real records decode a
41-
// few hundred values, so this leaves a wide margin. See the proposed "Reader
42-
// Resource Limits" guidance for the MaxMind DB specification.
41+
// few hundred values, so this leaves a wide margin. See "Reader Resource
42+
// Limits" in the MaxMind DB specification.
4343
#ifndef MAXIMUM_DATA_STRUCTURE_VALUES
4444
#define MAXIMUM_DATA_STRUCTURE_VALUES (1U << 16)
4545
#endif

0 commit comments

Comments
 (0)