From e5587d89796b51a8226fb00a225b1006e406f659 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Wed, 15 Jul 2026 16:11:30 -1000 Subject: Check `max-blob-size` before reading, default 10 MB Only the tree view honoured the limit, and only after loading the whole object. The raw blob, plain, blame and readme paths now check the size before reading, and the default moves from unlimited to 10 MB so a fresh install never buffers a huge object whole, with zero still the opt-out. --- source/ui-plain.c | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'source/ui-plain.c') diff --git a/source/ui-plain.c b/source/ui-plain.c index c041711..8486fa4 100644 --- a/source/ui-plain.c +++ b/source/ui-plain.c @@ -30,6 +30,14 @@ static int print_object(const struct object_id *oid, const char *path) return 1; } + /* Reject an oversized object before reading it whole into memory. */ + if (ctx.cfg.max_blob_size && size / 1024 > (unsigned long)ctx.cfg.max_blob_size) { + cgit_print_error_page(413, "Too large", + "Object size (%luKB) exceeds limit (%dKB)", + size / 1024, ctx.cfg.max_blob_size); + return 1; + } + buf = odb_read_object(the_repository->objects, oid, &type, &size); if (!buf) { cgit_print_error_page(404, "Not found", "Not found"); -- cgit v2.8.0