Harden rail fence cipher decoding against resource exhaustion - #109
Closed
krotname wants to merge 1 commit into
Closed
Harden rail fence cipher decoding against resource exhaustion#109krotname wants to merge 1 commit into
krotname wants to merge 1 commit into
Conversation
Owner
Author
krotname
deleted the
codex/propose-fix-for-railfencecipher-vulnerability
branch
August 1, 2026 02:18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
decodeimplementation performed allocations and O(n^2) work based on the caller-controlled rail countn, and created per-characterString/LinkedListobjects even for empty input, enabling CPU/memory exhaustion for largen.Description
IllegalArgumentExceptionifn < 2, and return immediately whens.isEmpty()orn >= s.length()to avoid unnecessary work and allocations.sumArrscans andTreeMap/LinkedListper-character conversions with anint[] positionoffset array and a singleStringBuilderresult to reconstruct characters directly from the input.Stringallocations and linked-list buffering so decoding runs in linear time relative to the input length plus rail bookkeeping.shouldDecodeWithoutAllocatingForUnusedRailsasserting that extreme rail counts (e.g.Integer.MAX_VALUE) do not cause allocation or incorrect decoding for empty and short inputs.Testing
mvn -Dtest=RailFenceCipherTest testand theRailFenceCipherTestsuite completed with all tests passing (5 tests, 0 failures).mvn -q testand it completed successfully with no test failures.Codex Task