Skip to content

fix: fail reads that end before the declared entry size - #490

Open
unxed wants to merge 2 commits into
bodgit:mainfrom
unxed:fix-short-read
Open

unxed wants to merge 2 commits into
bodgit:mainfrom
unxed:fix-short-read

Conversation

@unxed

@unxed unxed commented Sep 25, 2026

Copy link
Copy Markdown

Problem

With a wrong password on an encrypted archive, the decoder can hit io.EOF before producing UncompressedSize bytes. fileReader.Read passed that EOF through, so callers got a short (often empty) file and a clean EOF, with nothing to say the password was wrong (see also #38, #49).

Change

  • fileReader.Read: an EOF that arrives before the entry's declared size becomes a ReadError wrapping io.ErrUnexpectedEOF. The Encrypted flag is kept so callers can ask for another password. A normal EOF at the declared size is unchanged.
  • New subtest in TestOpenReaderWithWrongPassword (t4.7z with a password that used to give an empty success).
  • TestBraRead: pr472.7z is encrypted and the test opens it without a password, so it used to read 0 of 12345344 bytes with no error. It now checks for the new error. The timeout that guards against the fix: return EOF when buffer is empty #476 loop is still there.

Testing

go vet + go test ./... on ubuntu, windows and macOS: https://github.com/unxed/sandbox/actions/runs/36143285563 (baseline for main: https://github.com/unxed/sandbox/actions/runs/36143289687).

🤖 Generated with Claude Code

refaim and others added 2 commits September 25, 2026 13:47
A wrong password on an AES-encrypted 7z stream can make the decoder
return io.EOF before UncompressedSize bytes were produced, so callers
saw an empty file and a clean EOF. Convert that early EOF into a
ReadError wrapping io.ErrUnexpectedEOF, keeping the Encrypted flag so
password handling can react.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…sword

pr472.7z is encrypted and TestBraRead opens it without a password. The
entry now ends with a ReadError wrapping io.ErrUnexpectedEOF instead of
an empty success, so check for that error; the timeout still guards
against the endless read loop fixed in bodgit#476.

Also use require.ErrorIs in the new wrong-password subtest.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants