Commit 4563ab5
authored
feat: expose maxMemory to prevent OOM from untrusted input (#1075)
Adds `BashBuilder::max_memory(bytes)` in the Rust core that caps
`max_total_variable_bytes` and clamps `max_function_body_bytes`.
Exposed through JS bindings (`maxMemory`) and Python bindings
(`max_memory`) on both `Bash` and `BashTool` classes.
Includes Rust unit test + doctest and 5 JS security tests.
Closes #10721 parent c06d1c5 commit 4563ab5
File tree
6 files changed
+165
-1
lines changed- crates
- bashkit-js
- __test__
- src
- bashkit-python/src
- bashkit/src
- specs
6 files changed
+165
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
88 | 88 | | |
89 | 89 | | |
90 | 90 | | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
91 | 160 | | |
92 | 161 | | |
93 | 162 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
433 | 433 | | |
434 | 434 | | |
435 | 435 | | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
436 | 442 | | |
437 | 443 | | |
438 | 444 | | |
| |||
461 | 467 | | |
462 | 468 | | |
463 | 469 | | |
| 470 | + | |
464 | 471 | | |
465 | 472 | | |
466 | 473 | | |
| |||
490 | 497 | | |
491 | 498 | | |
492 | 499 | | |
| 500 | + | |
493 | 501 | | |
494 | 502 | | |
495 | 503 | | |
| |||
1459 | 1467 | | |
1460 | 1468 | | |
1461 | 1469 | | |
| 1470 | + | |
| 1471 | + | |
| 1472 | + | |
| 1473 | + | |
1462 | 1474 | | |
1463 | 1475 | | |
1464 | 1476 | | |
| |||
1533 | 1545 | | |
1534 | 1546 | | |
1535 | 1547 | | |
| 1548 | + | |
1536 | 1549 | | |
1537 | 1550 | | |
1538 | 1551 | | |
| |||
1565 | 1578 | | |
1566 | 1579 | | |
1567 | 1580 | | |
| 1581 | + | |
1568 | 1582 | | |
1569 | 1583 | | |
1570 | 1584 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
35 | 47 | | |
36 | 48 | | |
37 | 49 | | |
| |||
122 | 134 | | |
123 | 135 | | |
124 | 136 | | |
| 137 | + | |
125 | 138 | | |
126 | 139 | | |
127 | 140 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
662 | 662 | | |
663 | 663 | | |
664 | 664 | | |
| 665 | + | |
665 | 666 | | |
666 | 667 | | |
667 | 668 | | |
| |||
672 | 673 | | |
673 | 674 | | |
674 | 675 | | |
| 676 | + | |
675 | 677 | | |
676 | 678 | | |
677 | 679 | | |
| |||
689 | 691 | | |
690 | 692 | | |
691 | 693 | | |
| 694 | + | |
692 | 695 | | |
693 | 696 | | |
694 | 697 | | |
| |||
717 | 720 | | |
718 | 721 | | |
719 | 722 | | |
| 723 | + | |
| 724 | + | |
| 725 | + | |
| 726 | + | |
720 | 727 | | |
721 | 728 | | |
722 | 729 | | |
| |||
786 | 793 | | |
787 | 794 | | |
788 | 795 | | |
| 796 | + | |
789 | 797 | | |
790 | 798 | | |
791 | 799 | | |
| |||
935 | 943 | | |
936 | 944 | | |
937 | 945 | | |
| 946 | + | |
938 | 947 | | |
939 | 948 | | |
940 | 949 | | |
| |||
961 | 970 | | |
962 | 971 | | |
963 | 972 | | |
| 973 | + | |
| 974 | + | |
| 975 | + | |
964 | 976 | | |
965 | 977 | | |
966 | 978 | | |
| |||
1067 | 1079 | | |
1068 | 1080 | | |
1069 | 1081 | | |
| 1082 | + | |
1070 | 1083 | | |
1071 | 1084 | | |
1072 | 1085 | | |
| |||
1101 | 1114 | | |
1102 | 1115 | | |
1103 | 1116 | | |
| 1117 | + | |
1104 | 1118 | | |
1105 | 1119 | | |
1106 | 1120 | | |
| |||
1113 | 1127 | | |
1114 | 1128 | | |
1115 | 1129 | | |
| 1130 | + | |
1116 | 1131 | | |
1117 | 1132 | | |
1118 | 1133 | | |
| |||
1138 | 1153 | | |
1139 | 1154 | | |
1140 | 1155 | | |
| 1156 | + | |
| 1157 | + | |
| 1158 | + | |
| 1159 | + | |
1141 | 1160 | | |
1142 | 1161 | | |
1143 | 1162 | | |
| |||
1163 | 1182 | | |
1164 | 1183 | | |
1165 | 1184 | | |
| 1185 | + | |
1166 | 1186 | | |
1167 | 1187 | | |
1168 | 1188 | | |
| |||
1295 | 1315 | | |
1296 | 1316 | | |
1297 | 1317 | | |
| 1318 | + | |
1298 | 1319 | | |
1299 | 1320 | | |
1300 | 1321 | | |
| |||
1315 | 1336 | | |
1316 | 1337 | | |
1317 | 1338 | | |
| 1339 | + | |
| 1340 | + | |
| 1341 | + | |
1318 | 1342 | | |
1319 | 1343 | | |
1320 | 1344 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1100 | 1100 | | |
1101 | 1101 | | |
1102 | 1102 | | |
| 1103 | + | |
| 1104 | + | |
| 1105 | + | |
| 1106 | + | |
| 1107 | + | |
| 1108 | + | |
| 1109 | + | |
| 1110 | + | |
| 1111 | + | |
| 1112 | + | |
| 1113 | + | |
| 1114 | + | |
| 1115 | + | |
| 1116 | + | |
| 1117 | + | |
| 1118 | + | |
| 1119 | + | |
| 1120 | + | |
| 1121 | + | |
| 1122 | + | |
| 1123 | + | |
| 1124 | + | |
| 1125 | + | |
| 1126 | + | |
1103 | 1127 | | |
1104 | 1128 | | |
1105 | 1129 | | |
| |||
5367 | 5391 | | |
5368 | 5392 | | |
5369 | 5393 | | |
| 5394 | + | |
| 5395 | + | |
| 5396 | + | |
| 5397 | + | |
| 5398 | + | |
| 5399 | + | |
| 5400 | + | |
| 5401 | + | |
| 5402 | + | |
| 5403 | + | |
| 5404 | + | |
| 5405 | + | |
| 5406 | + | |
| 5407 | + | |
| 5408 | + | |
| 5409 | + | |
| 5410 | + | |
| 5411 | + | |
| 5412 | + | |
5370 | 5413 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
450 | 450 | | |
451 | 451 | | |
452 | 452 | | |
| 453 | + | |
453 | 454 | | |
454 | 455 | | |
455 | 456 | | |
| |||
473 | 474 | | |
474 | 475 | | |
475 | 476 | | |
476 | | - | |
| 477 | + | |
477 | 478 | | |
478 | 479 | | |
479 | 480 | | |
| |||
0 commit comments