Repository navigation
programs: fix zstd -l infinite loop on a large skippable frame - #4833
ilyas-mallah wants to merge 1 commit into
Conversation
|
Hi @ilyas-mallah! Thank you for your pull request and welcome to our community. Action RequiredIn order to merge any pull request (code, docs, etc.), we require contributors to sign our Contributor License Agreement, and we don't seem to have one on file for you. ProcessIn order for us to review and merge your suggested changes, please sign at https://code.facebook.com/cla. If you are contributing on behalf of someone else (eg your employer), the individual CLA may not be sufficient and your employer may need to sign the corporate CLA. Once the CLA is signed, our tooling will perform checks and validations. Afterwards, the pull request will be tagged with If you have received this in error or have any questions, please contact us at cla@meta.com. Thanks! |
|
Thank you for signing our Contributor License Agreement. We can now accept your code for this (and any) Meta Open Source project. Thanks! |
What and why
zstd -lnever returns on a file with a skippable frame whoseFrame_Sizeis0xFFFFFFF8. InFIO_analyzeFrames(),8 + frameSizeis 32-bit unsigned and wraps to 0, so the seek goes backwards and the loop rereads the same header forever.Where
longis 32 bits, the cast also breaks valid files with a skippable frame of 2 GB or more. A 32-bit Linux build fails on a file with a 3 GiB skippable frame withError: could not find end of skippable frame. 64-bit Windows has the same 32-bitlong.With the offset computed in 64 bits, the crafted file is reported as truncated, and the 3 GiB file lists as 2 frames with 1 skip in the 32-bit build. To reproduce:
The new
playTests.shcase uses that file, andmake -C tests test-zstdand the cli-tests pass.Checklist
Tools used
AI usage: Claude Code helped with the test runs and the 32-bit build. I found the loop, made the fix, and validated every change.