initial commit

This commit is contained in:
2026-09-21 13:41:40 +09:00
commit 855c7328df
411 changed files with 85352 additions and 0 deletions
+50
View File
@@ -0,0 +1,50 @@
#!/usr/bin/env python3
"""Deterministic authored ZIP inputs for the bounded-input expansion guard."""
import hashlib
import json
from pathlib import Path
import struct
import zlib
ROOT = Path(__file__).resolve().parent
def build(output_size: int, padded_size: int | None = None) -> tuple[bytes, dict]:
plain = b"x" * output_size
compressor = zlib.compressobj(9, zlib.DEFLATED, -15)
compressed = compressor.compress(plain) + compressor.flush()
payload = compressed if padded_size is None else compressed.ljust(padded_size, b"\0")
name = b"index.html"
crc = zlib.crc32(plain)
local = struct.pack("<IHHHHHIIIHH", 0x04034B50, 20, 0x800, 8, 0, 33,
crc, len(payload), len(plain), len(name), 0)
central = struct.pack("<IHHHHHHIIIHHHHHII", 0x02014B50, (3 << 8) | 20,
20, 0x800, 8, 0, 33, crc, len(payload), len(plain),
len(name), 0, 0, 0, 0, 0o100600 << 16, 0) + name
offset = len(local) + len(name) + len(payload)
end = struct.pack("<IHHHHIIH", 0x06054B50, 0, 0, 1, 1, len(central), offset, 0)
archive = local + name + payload + central + end
return archive, {
"output_bytes": len(plain), "deflate_stream_bytes": len(compressed),
"zip_declared_compressed_bytes": len(payload),
"sha256": hashlib.sha256(archive).hexdigest(),
"output_sha256": hashlib.sha256(plain).hexdigest(),
}
def main() -> None:
manifest = {"generator": "generate.py; Python stdlib zlib, raw DEFLATE",
"content": "Authored repeated ASCII x; no external material or fonts.", "files": {}}
for name, size, padded, expectation in [
("padded-33mib.zip", 33 * 1024 * 1024, 256 * 1024, "open succeeds; extraction E_ARCHIVE_LIMIT before more than 32 MiB is sent"),
("threshold-32mib.zip", 32 * 1024 * 1024, None, "open and extraction succeed; ratio threshold is strictly greater than 32 MiB"),
("unpadded-33mib.zip", 33 * 1024 * 1024, None, "open E_ARCHIVE_LIMIT from metadata preflight"),
]:
archive, info = build(size, padded)
(ROOT / name).write_bytes(archive)
manifest["files"][name] = info | {"expected": expectation}
(ROOT / "manifest.json").write_text(json.dumps(manifest, indent=2) + "\n")
if __name__ == "__main__":
main()
+30
View File
@@ -0,0 +1,30 @@
{
"generator": "generate.py; Python stdlib zlib, raw DEFLATE",
"content": "Authored repeated ASCII x; no external material or fonts.",
"files": {
"padded-33mib.zip": {
"output_bytes": 34603008,
"deflate_stream_bytes": 33647,
"zip_declared_compressed_bytes": 262144,
"sha256": "fd84b25c229191d4efb24939c14a20506ea442e4becf2164d034a4bdc983291a",
"output_sha256": "7d641a2a7b1c449f586b444bd47a2005d83be0e142596f6d1a52da9c2256c96b",
"expected": "open succeeds; extraction E_ARCHIVE_LIMIT before more than 32 MiB is sent"
},
"threshold-32mib.zip": {
"output_bytes": 33554432,
"deflate_stream_bytes": 32617,
"zip_declared_compressed_bytes": 32617,
"sha256": "2f49d2152f9d10daad3109eecb532bd3e2c720f15708f1c1338c14785b7d7ef1",
"output_sha256": "05f052c8f6da8ee5228ec291820b559c4be183773b9e97a6b82e30dacff85dd3",
"expected": "open and extraction succeed; ratio threshold is strictly greater than 32 MiB"
},
"unpadded-33mib.zip": {
"output_bytes": 34603008,
"deflate_stream_bytes": 33647,
"zip_declared_compressed_bytes": 33647,
"sha256": "205c8ef001b932dc20cc0672bb515f72420202c5a147de7a6b8496439745ea5c",
"output_sha256": "7d641a2a7b1c449f586b444bd47a2005d83be0e142596f6d1a52da9c2256c96b",
"expected": "open E_ARCHIVE_LIMIT from metadata preflight"
}
}
}
Binary file not shown.
Binary file not shown.
Binary file not shown.