Skip to content

Commit 793986a

Browse files
fix: use incremental hashing in Preset.get_hash() to avoid loading entire file into memory
Preset.get_hash() called f.read() which loads the entire file into memory before hashing. Use incremental hashlib.sha256().update() with 64 KiB chunks to prevent unbounded memory allocation on large or maliciously sized preset files.
1 parent 5e2f9bc commit 793986a

1 file changed

Lines changed: 4 additions & 1 deletion

File tree

‎src/specify_cli/presets/__init__.py‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -452,8 +452,11 @@ def tags(self) -> List[str]:
452452

453453
def get_hash(self) -> str:
454454
"""Calculate SHA256 hash of manifest file."""
455+
h = hashlib.sha256()
455456
with open(self.path, 'rb') as f:
456-
return f"sha256:{hashlib.sha256(f.read()).hexdigest()}"
457+
for chunk in iter(lambda: f.read(65536), b''):
458+
h.update(chunk)
459+
return f"sha256:{h.hexdigest()}"
457460

458461

459462
class PresetRegistry:

0 commit comments

Comments
 (0)