aws / aws/aws-encryption-sdk-python
potential issue with large reads on nonframed messages
- Dominant language
- Python
- Stars
- 255
- Forks
- 92
- Avg merge
- 2d 17h
- Merged PRs (30d)
- 2
Description
In tracking down an issue in an unrelated codebase, I discovered that at least in some cases, passing more than 2GiB to the pyca/cryptography `Cipher.update()` methods can cause issues with the underlying OpenSSL implementation.
This is not an issue with framed messages because our max frame size is 2GiB, but could be an issue for nonframed messages larger than 2GiB.
We should add tests that check for this edge case, and if it is an issue we can add chunking logic.
Contributor guide
Research direction
Start by reproducing the reported behavior with more than 2GiB passed to the pyca/cryptography Cipher.update() methods for a nonframed message, and compare it with framed messages. Add regression coverage for the edge case; done means large nonframed messages work reliably, with chunking logic added if the underlying OpenSSL issue is confirmed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- cryptography
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100