Repository navigation
feat(scanner): reject plugin archive decompression bombs - #1166
Draft
seonghobae wants to merge 5 commits into
Draft
seonghobae wants to merge 5 commits into
seonghobae wants to merge 5 commits into
Conversation
Summary: - RED: zip/tar members with huge uncompressed/compressed ratio stay receipt pass. - Highly nested zip-in-zip and tar-in-tar stay receipt pass. - Honest small zip/tar of plugin.json+LICENSE, ../escape traversal, and oversized file-count stay negative. Rationale: - Issue #1099 lists hostile oversized/decompression-bomb/deep-recursion packages as admission fail, distinct from byte/file caps and zip-slip. Tests: - tests/test_claude_plugin_decompression_bomb.py (8 fail / 5 pass)
Summary: - Zip/tar members whose uncompressed/compressed ratio exceeds 100 fail as claude-plugin-decompression-bomb. - Nested zip/tar deeper than one archive layer is the same class. - Honest small zip/tar of plugin.json+LICENSE, ../escape traversal, and oversized file-count stay their classes. - Bomb payloads are not extracted; snippets are path labels. Rationale: - Issue #1099 lists decompression-bomb/deep-recursion as admission fail, distinct from byte/file caps and zip-slip. Tests: - tests/test_claude_plugin_decompression_bomb.py plus plugin suites 268 passed - detector statement coverage 2201/2201 on Python 3.13
2 of 4 tasks
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
added a commit
that referenced
this pull request
Sep 7, 2026
Summary: - Snapshot 20:26 UTC records Draft #1166 `90cd031` stacked on #1165. - Archive ratio >100 or nesting deeper than 1 fail closed. - Bomb members are not extracted; zip-slip stays #1135. Rationale: - #999 is the single writer of the product-technical gap baseline. - #1099 remaining surfaces stay on stacked successors, not Close. Tests: - documentation-only; detector evidence lives on #1166 (2201/2201)
Summary: - Sum zip ZipInfo.file_size and tar regular TarInfo.size before extract. - Totals above _MAX_PACKAGE_BYTES fail as claude-plugin-decompression-bomb. - Traversal members and directories are omitted; payloads are not read. Rationale: - Per-member ratio/depth still allowed many safe members to exceed the budget. - Oversized-package after materialization is too late to bound extraction. Tests: - tests/test_claude_plugin_archive_aggregate_admission.py plus plugin suites 275 passed - detector statement coverage 2238/2238 on Python 3.13
seonghobae
added a commit
that referenced
this pull request
Sep 7, 2026
Summary: - Snapshot 21:03 UTC records Draft #1166 `0ef0f7d` stacked on #1165. - Aggregate in-root uncompressed bytes fail closed before extract. - Ratio/depth bombs and zip-slip stay their existing classes. Rationale: - #999 is the single writer of the product-technical gap baseline. - RED `e1b3f39` on the canonical writer is not Close; it is GREEN. Tests: - documentation-only; detector evidence lives on #1166 (2238/2238)
Contributor
Author
Contributor
Author
|
Successor Draft #1167 ( |
seonghobae
added a commit
that referenced
this pull request
Sep 7, 2026
Summary: - Snapshot 21:14 UTC records Draft #1167 `18bb1a0` stacked on #1166. - Receipt policy_provenance binds scanner release version and policy digest. - Verify fails closed when those disagree with the running scanner. Rationale: - #999 is the single writer of the product-technical gap baseline. - Noema/macos_utility_packs canaries are not this lane. Tests: - documentation-only; detector evidence lives on #1167 (2272/2272)
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Successor of #1165 / issue #1099. Does not Close those. Does not steal #1165 setuid/world-writable, #1164 hide-actions/self-modify/goal-escalation, or G-06 #1152. Archive path traversal stays #1135.
Current exact authority
feat/claude-plugin-insecure-file-mode-1099@57905590731b5fb5cb7bf8b5e9bed43241bd56050ef0f7d7f3c63faa822a8cff5a20e76514285da2Unique delta
Fail closed when a zip/tar member would expand far beyond compressed size, nest recursively, or exceed the package byte budget in aggregate:
claude-plugin-decompression-bombZipInfo.file_size/TarInfo.sizesum exceeds_MAX_PACKAGE_BYTES→ same class, before extractplugin.json+LICENSEis not this class and still extracts../escapemembers stayclaude-plugin-archive-path-traversaland are omitted from the byte sumclaude-plugin-oversized-packageRatio, depth, and budget are explicit:
_MAX_ARCHIVE_COMPRESSION_RATIO = 100,_MAX_ARCHIVE_NESTING_DEPTH = 1,_MAX_PACKAGE_BYTESfor aggregate admission.Repair: aggregate extraction admission is GREEN
RED
e1b3f397d46dc1caad6ba0e1aed73f40098d0f92(tests/test_claude_plugin_archive_aggregate_admission.py) proved many individually safe ZIP_STORED/TAR members could exceed_MAX_PACKAGE_BYTESwhile still extracting. GREEN0ef0f7dinspects zip/tar metadata only and fails closed when the summed uncompressed size of regular in-root members exceeds the budget, with zero extracted members.Gate
Keep Draft. Predecessor suite counts do not transfer. Require exact-head Tests/security/SAST/CodeQL and qualifying independent current-head review. Do not merge on robot review alone.
Relates to #1099. Relates to #1165. Relates to #1135.
Current non-force restack — 2026-09-12
This Draft is an ordinary two-parent descendant of prior head
0ef0f7d7f3c63faa822a8cff5a20e76514285da2and current #1165 head4714d13ec38d85a4c2f34e9518064b70127753c8. Exact head is348df03ac25d98d6c3ce31b9073f2428b06cd9e0; exact tree isa105e56ef887525b0ebead212bc26c6f65cdd013. GitHub compare reports 5 ahead / 0 behind and preserves archive ratio/depth/aggregate pre-extraction admission with the current mode, directive, command-rule, and MCP precision lineage. Exact-tree Claude-plugin tests are 311/311; detector/CLI compile and diff checks pass. No hosted workflow or qualifying independent current-head review exists, so this custom-base PR remains Draft. Earlier exact-authority strings are historical evidence only.