#!/usr/bin/env python3 """Deterministic authored ZIP inputs for the bounded-input expansion guard.""" import hashlib import json from pathlib import Path import struct import zlib ROOT = Path(__file__).resolve().parent def build(output_size: int, padded_size: int | None = None) -> tuple[bytes, dict]: plain = b"x" * output_size compressor = zlib.compressobj(9, zlib.DEFLATED, -15) compressed = compressor.compress(plain) + compressor.flush() payload = compressed if padded_size is None else compressed.ljust(padded_size, b"\0") name = b"index.html" crc = zlib.crc32(plain) local = struct.pack(" None: manifest = {"generator": "generate.py; Python stdlib zlib, raw DEFLATE", "content": "Authored repeated ASCII x; no external material or fonts.", "files": {}} for name, size, padded, expectation in [ ("padded-33mib.zip", 33 * 1024 * 1024, 256 * 1024, "open succeeds; extraction E_ARCHIVE_LIMIT before more than 32 MiB is sent"), ("threshold-32mib.zip", 32 * 1024 * 1024, None, "open and extraction succeed; ratio threshold is strictly greater than 32 MiB"), ("unpadded-33mib.zip", 33 * 1024 * 1024, None, "open E_ARCHIVE_LIMIT from metadata preflight"), ]: archive, info = build(size, padded) (ROOT / name).write_bytes(archive) manifest["files"][name] = info | {"expected": expectation} (ROOT / "manifest.json").write_text(json.dumps(manifest, indent=2) + "\n") if __name__ == "__main__": main()