progress: count amount of data "delivered" to application

... and apply the CURLOPT_MAXFILESIZE limit (if set) on that as well.
This effectively protects the user against "zip bombs".

Test case 1618 verifies using a 14 byte brotli payload that otherwise
explodes to 102400 zero bytes.
This commit is contained in:
Daniel Stenberg 2026-03-02 11:02:03 +01:00
parent 4b583b7585
commit d332b9057f
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
10 changed files with 115 additions and 7 deletions

View file

@ -211,6 +211,7 @@ void Curl_pgrsReset(struct Curl_easy *data)
Curl_pgrsSetUploadSize(data, -1);
Curl_pgrsSetDownloadSize(data, -1);
data->progress.speeder_c = 0; /* reset speed records */
data->progress.deliver = 0;
pgrs_speedinit(data);
}
@ -339,6 +340,26 @@ void Curl_pgrsStartNow(struct Curl_easy *data)
p->ul_size_known = FALSE;
}
/* check that the 'delta' amount of bytes are okay to deliver to the
application, or return error if not. */
CURLcode Curl_pgrs_deliver_check(struct Curl_easy *data, size_t delta)
{
if(data->set.max_filesize &&
((curl_off_t)delta > data->set.max_filesize - data->progress.deliver)) {
failf(data, "Would have exceeded max file size");
return CURLE_FILESIZE_EXCEEDED;
}
return CURLE_OK;
}
/* this counts how much data is delivered to the application, which
in compressed cases may differ from downloaded amount */
void Curl_pgrs_deliver_inc(struct Curl_easy *data, size_t delta)
{
data->progress.deliver += delta;
}
void Curl_pgrs_download_inc(struct Curl_easy *data, size_t delta)
{
if(delta) {