If we wanted to enable object to be used with untrusted inputs, the simplest approach I can think of is to add an optional validation pass. This would use the low level API to traverse the data structures in the file (similar to what the readobj example does) and do two things:
- inspect fields for invalid values
- measure the work done, and exit when it is out of proportion with the size of the file. Ideally the limit on work would be at most O(n log n). This would require some care to ensure we are not neglecting to measure some work (e.g. cost of reading a null terminated string or performing a lookup in a collection).
For this to be useful, the validation pass must be exhaustive, which is hard.
If we wanted to enable
objectto be used with untrusted inputs, the simplest approach I can think of is to add an optional validation pass. This would use the low level API to traverse the data structures in the file (similar to what the readobj example does) and do two things:For this to be useful, the validation pass must be exhaustive, which is hard.