Skip to main content
All projects

Zipper

Extracts, inspects and repacks multi-gigabyte archives over Telegram while holding an active byte-and-time budget over the 7z child process to stop decompression bombs.

Open source
Project
Archive bot
Language
Python
Started
2024-01

The story

Zipper takes an archive over Telegram and gives back its contents, or the reverse. The whole design question is what happens when the archive is malicious.

Checking the declared size before extracting is not enough — headers lie. So the extraction is supervised: the 7z child process runs under a live byte and entry budget and is killed the instant it crosses it. Extracted paths are re-resolved with lstat and realpath before anything is written, because an archive containing a symlink to /etc is a legal archive.

The rest is throughput work: chunked streaming for multi-gigabyte files, and a debouncer so a fifty-file drop produces one status card rather than fifty.

Under the hood

The decisions that make it work.

Active bomb budget
The 7z child is watched while it runs and killed the moment output bytes or entry counts cross the bound — a limit that holds even when the header lies about its size.
Path safety
Every extracted target is re-checked with lstat and realpath, so a symlink cannot walk the write out of the working directory.
Upload debouncer
Bursts of files collapse into one status card refreshed on a one-second debounce instead of a message per item.
No-database mode
memory_db.py mirrors the PyMongo surface so the bot runs with zero external dependencies.

Built with

  • Python 3.13
  • Pyrogram
  • MongoDB
  • p7zip
  • asyncio