fix(proto): cap the message lengths declared by MSG/HMSG
The decoder trusted the payload and total lengths declared by the server without any bound: a broken or malicious peer could declare a multi-gigabyte message and make the read buffer grow without limits as data arrived, exhausting memory. The nats-server defaults max_payload to 1 MiB, caps it at max_pending (default 64 MiB) and rejects publishes above max_payload, but the client enforced none of those limits on the receive path. Reject declared lengths above 128 MiB (generously above any legitimate server traffic) with the existing InvalidPayloadLength(ParseUintError::Overflow) error: the length doesn't overflow usize, but it overflows what we're willing to buffer.
P
Paolo Barbolini committed
2e41d9a003c8101c3ebbfe5f8f62ae6c39b4986b
Parent: 029cee9