Zipper
Extracts, inspects and repacks multi-gigabyte archives over Telegram while holding an active byte-and-time budget over the 7z child process to stop decompression bombs.
- Project
- Archive bot
- Language
- Python
- Started
- 2024-01
The story
Zipper takes an archive over Telegram and gives back its contents, or the reverse. The whole design question is what happens when the archive is malicious.
Checking the declared size before extracting is not enough — headers lie. So the extraction is supervised: the 7z child process runs under a live byte and entry budget and is killed the instant it crosses it. Extracted paths are re-resolved with lstat and realpath before anything is written, because an archive containing a symlink to /etc is a legal archive.
The rest is throughput work: chunked streaming for multi-gigabyte files, and a debouncer so a fifty-file drop produces one status card rather than fifty.
Under the hood
The decisions that make it work.
- Active bomb budget
- The 7z child is watched while it runs and killed the moment output bytes or entry counts cross the bound — a limit that holds even when the header lies about its size.
- Path safety
- Every extracted target is re-checked with lstat and realpath, so a symlink cannot walk the write out of the working directory.
- Upload debouncer
- Bursts of files collapse into one status card refreshed on a one-second debounce instead of a message per item.
- No-database mode
- memory_db.py mirrors the PyMongo surface so the bot runs with zero external dependencies.