SIGN IN SIGN UP

fix(proto): cap the message lengths declared by MSG/HMSG

The decoder trusted the payload and total lengths declared by the
server without any bound: a broken or malicious peer could declare a
multi-gigabyte message and make the read buffer grow without limits
as data arrived, exhausting memory. The nats-server defaults
max_payload to 1 MiB, caps it at max_pending (default 64 MiB) and
rejects publishes above max_payload, but the client enforced none of
those limits on the receive path.

Reject declared lengths above 128 MiB (generously above any
legitimate server traffic) with the existing
InvalidPayloadLength(ParseUintError::Overflow) error: the length
doesn't overflow usize, but it overflows what we're willing to
buffer.
P
Paolo Barbolini committed
2e41d9a003c8101c3ebbfe5f8f62ae6c39b4986b
Parent: 029cee9