Skip to content

v0.2.0

Choose a tag to compare

@hustcer hustcer released this 15 Mar 03:30
· 116 commits to main since this release

v0.2.0 - 2026-03-08

Security & Robustness

  • Zip Bomb Prevention: Hardened decompression safeguards against zip bombs. Introduced a configurable max_output_size (defaulted to 100MB) and max_input_size in InflateOptions, GunzipOptions, and UnzlibOptions. Added a dynamic compression ratio check in ZIP extraction (rejecting entries if uncompressed is > 1000x compressed).
  • Checksum Validations: Enforced missing integrity validation steps in unzlib_sync (Adler-32) and gunzip_sync (CRC-32), natively rejecting payloads with mismatched trailer checksums.
  • Filename Bound Checks: Capped ZIP filename lengths at a generous but safe 4096 bytes and added bounds checking to prevent out-of-bounds panics when parsing corrupted central directory headers.

Refactoring & Chores

  • Code Duplication Reduction: Created constants.mbt for shared size limit constants (default_max_output_size, default_max_input_size). Extracted buffer trimming into a trim_buf helper function, replacing repeated slc(buf, 0, e=len) patterns across deflate.mbt, gzip.mbt, inflate.mbt, string.mbt, and zlib.mbt.
  • Testing: Added security validation tests covering checksum verification failures and size limit enforcement.