Files
sim/apps
Waleed 47e8f1eb5b fix(ssh/sftp): cap remote file reads on received bytes, not stat() size (#6168)
The SFTP/SSH download routes buffered a remote file into memory with the
only size guard being sftp.stat().size — a value the caller-supplied SSH
server controls. A server that reports a tiny size and then streams
endlessly drove unbounded heap growth until OOM.

Read through the existing readNodeStreamToBufferWithLimit limiter, which
enforces the cap on bytes actually received and destroys the stream on
breach, via a small readSftpFileCapped wrapper in sftp/utils. All four
SFTP-reading tool routes now share it — download, download-file,
read-file-content, and the append path of write-file-content, which had
no cap at all.

The wrapper keeps a no-op error listener on the stream for its whole
life: ssh2 rejects still-pending SFTP requests when the channel closes,
which arrives as a late error event after the limiter has detached its
own handlers, and an error event with no listener would take the process
down. Too-large responses now return 413 to match how the rest of the
routes surface PayloadSizeLimitError, and responses report the actual
byte count rather than the server-reported stat size.
2026-08-01 16:53:46 -07:00
..