ZIP: revocation probe exceeds the stream deadline under shared-host load #1050

Open
opened 2026-10-04 09:42:05 +00:00 by kayg · 0 comments
Owner

#867's existing attack2.py ZIP revocation section exceeded its 30-second stream-read deadline on both exact binaries: production dev 6074f71d1 and merge round 7b2 0c4fd513e. Both runs uploaded 40 × 512 KiB files through the real API, began B's Shared folder archive, read the first 64 KiB, then revoked the Share and swapped the original/private folder names.

Both reported:

zip mid-stream: SLOW: archive stream did not finish within 30 seconds

The checked partial bytes did not contain PRIVATE-MARKER. The timeout leaves the archive tail unverified; it is not proof that the entire stream is safe or complete. This is pre-existing and SLOW-only on the shared build host (load around 30). The owner rule treats it as load, so it does not block this fix job.

Next: run this same section once in the merge round, retain the deadline and partial-byte disclosure check, and record whether the server aborted or the host stalled. Do not turn an incomplete security check into a pass. Avoid a new broad attack campaign or longer silent waits.

#867's existing `attack2.py` ZIP revocation section exceeded its 30-second stream-read deadline on both exact binaries: production dev 6074f71d1 and merge round 7b2 0c4fd513e. Both runs uploaded 40 × 512 KiB files through the real API, began B's Shared folder archive, read the first 64 KiB, then revoked the Share and swapped the original/private folder names. Both reported: ``` zip mid-stream: SLOW: archive stream did not finish within 30 seconds ``` The checked partial bytes did not contain PRIVATE-MARKER. The timeout leaves the archive tail unverified; it is not proof that the entire stream is safe or complete. This is pre-existing and SLOW-only on the shared build host (load around 30). The owner rule treats it as load, so it does not block this fix job. Next: run this same section once in the merge round, retain the deadline and partial-byte disclosure check, and record whether the server aborted or the host stalled. Do not turn an incomplete security check into a pass. Avoid a new broad attack campaign or longer silent waits.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#1050
No description provided.