Conversation
A wrong password on an AES-encrypted 7z stream can make the decoder return io.EOF before UncompressedSize bytes were produced, so callers saw an empty file and a clean EOF. Convert that early EOF into a ReadError wrapping io.ErrUnexpectedEOF, keeping the Encrypted flag so password handling can react. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…sword pr472.7z is encrypted and TestBraRead opens it without a password. The entry now ends with a ReadError wrapping io.ErrUnexpectedEOF instead of an empty success, so check for that error; the timeout still guards against the endless read loop fixed in bodgit#476. Also use require.ErrorIs in the new wrong-password subtest. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
With a wrong password on an encrypted archive, the decoder can hit
io.EOFbefore producingUncompressedSizebytes.fileReader.Readpassed that EOF through, so callers got a short (often empty) file and a clean EOF, with nothing to say the password was wrong (see also #38, #49).Change
fileReader.Read: an EOF that arrives before the entry's declared size becomes aReadErrorwrappingio.ErrUnexpectedEOF. TheEncryptedflag is kept so callers can ask for another password. A normal EOF at the declared size is unchanged.TestOpenReaderWithWrongPassword(t4.7zwith a password that used to give an empty success).TestBraRead:pr472.7zis encrypted and the test opens it without a password, so it used to read 0 of 12345344 bytes with no error. It now checks for the new error. The timeout that guards against the fix: return EOF when buffer is empty #476 loop is still there.Testing
go vet+go test ./...on ubuntu, windows and macOS: https://github.com/unxed/sandbox/actions/runs/36143285563 (baseline formain: https://github.com/unxed/sandbox/actions/runs/36143289687).🤖 Generated with Claude Code