aws / aws/aws-encryption-sdk-python

potential issue with large reads on nonframed messages

Open
#53 0 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
Python
Stars
255
Forks
92
Avg merge
2d 17h
Merged PRs (30d)
2

Description

In tracking down an issue in an unrelated codebase, I discovered that at least in some cases, passing more than 2GiB to the pyca/cryptography `Cipher.update()` methods can cause issues with the underlying OpenSSL implementation.

This is not an issue with framed messages because our max frame size is 2GiB, but could be an issue for nonframed messages larger than 2GiB.

We should add tests that check for this edge case, and if it is an issue we can add chunking logic.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the reported behavior with more than 2GiB passed to the pyca/cryptography Cipher.update() methods for a nonframed message, and compare it with framed messages. Add regression coverage for the edge case; done means large nonframed messages work reliably, with chunking logic added if the underlying OpenSSL issue is confirmed.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
cryptography
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.