Summary
In internal/compaction/subprocess.go:93, the memory limit config value is interpolated directly into a DuckDB SET statement:
```go
db.Exec(fmt.Sprintf("SET memory_limit='%s'", config.MemoryLimit))
```
While DuckDB's SET is not exploitable for data access, a malformed value could: trigger misleading error logs that expose other config context, or be used to DoS compaction by setting an extremely low limit.
Fix
Validate the format before use with a strict regex:
```go
var validMemoryLimit = regexp.MustCompile(^\d+(\.\d+)?\s*(KB|MB|GB|TB)$)
if !validMemoryLimit.MatchString(config.MemoryLimit) {
logger.Error().Str("limit", config.MemoryLimit).Msg("Invalid memory_limit format, skipping")
} else {
db.Exec(fmt.Sprintf("SET memory_limit='%s'", config.MemoryLimit))
}
```
Severity
Medium — no direct data access risk, but validates untrusted config input before SQL use.
Summary
In
internal/compaction/subprocess.go:93, the memory limit config value is interpolated directly into a DuckDBSETstatement:```go
db.Exec(fmt.Sprintf("SET memory_limit='%s'", config.MemoryLimit))
```
While DuckDB's
SETis not exploitable for data access, a malformed value could: trigger misleading error logs that expose other config context, or be used to DoS compaction by setting an extremely low limit.Fix
Validate the format before use with a strict regex:
```go
var validMemoryLimit = regexp.MustCompile(
^\d+(\.\d+)?\s*(KB|MB|GB|TB)$)if !validMemoryLimit.MatchString(config.MemoryLimit) {
logger.Error().Str("limit", config.MemoryLimit).Msg("Invalid memory_limit format, skipping")
} else {
db.Exec(fmt.Sprintf("SET memory_limit='%s'", config.MemoryLimit))
}
```
Severity
Medium — no direct data access risk, but validates untrusted config input before SQL use.