Remove total_bytes_limit from pure PHP CodedInputStream.

This limit has no public api to override to a different limit: it is only ever set to the 'default' of 32 MB but has actually just not applied at all in many cases.

If we 'fix the bug' by making it so this limit does apply, it would break any users who may be successfully parsing data arbitrarily larger than 32 MB with no issue today due to hitting a case where limit is consistently not applied. By contrast, removing this doesn't formally break any preexisting users, and realigns the behavior to match PHP-upb as well as the default behavior in all of our other supported runtimes.

Note that gRPC-PHP will also already enforce a 4mb limit by default before passing the data to Protobuf, so the only people who could be exposed to this topic either way would need to be either intentionally bumping up the gRPC limit or not using gRPC at all.

In general the need to have a limit within CodedInputStream is very weak in this case compared to other languages: since PHP only parses off of a string and not a stream, it trivial for application code to apply a limit with an if before the parse starts.

PiperOrigin-RevId: 950914431
2 files changed
tree: 3bf48e0a4c03dec0f7a0ac3529f59b1be50044fb
  1. .bazelci/
  2. .bcr/
  3. .github/
  4. bazel/
  5. benchmarks/
  6. build_defs/
  7. ci/
  8. cmake/
  9. compatibility/
  10. conformance/
  11. csharp/
  12. docs/
  13. editions/
  14. editors/
  15. examples/
  16. go/
  17. google3/
  18. hpb/
  19. hpb_generator/
  20. java/
  21. lua/
  22. objectivec/
  23. patches/
  24. php/
  25. pkg/
  26. python/
  27. ruby/
  28. rust/
  29. src/
  30. third_party/
  31. toolchain/
  32. upb/
  33. upb_generator/
  34. .bazelignore
  35. .bazeliskrc
  36. .bazelrc
  37. .clang-format
  38. .gitattributes
  39. .gitignore
  40. .gitmodules
  41. .readthedocs.yml
  42. appveyor.bat
  43. appveyor.yml
  44. BUILD.bazel
  45. CMakeLists.txt
  46. CODE_OF_CONDUCT.md
  47. CONTRIBUTING.md
  48. CONTRIBUTORS.txt
  49. Disable_bundle_install.patch
  50. fix_permissions.sh
  51. generate_descriptor_proto.sh
  52. global.json
  53. google3_export_generated_files.sh
  54. LICENSE
  55. maven_dev_install.json
  56. maven_install.json
  57. MODULE.bazel
  58. PrivacyInfo.xcprivacy
  59. protobuf.bzl
  60. Protobuf.podspec
  61. protobuf_deps.bzl
  62. protobuf_release.bzl
  63. protobuf_version.bzl
  64. README.md
  65. regenerate_stale_files.sh
  66. SECURITY.md
  67. version.json
  68. WORKSPACE
  69. WORKSPACE.bzlmod
README.md

Protocol Buffers - Google's data interchange format

OpenSSF Scorecard

Copyright 2008 Google LLC

Overview

Protocol Buffers (a.k.a., protobuf) are Google's language-neutral, platform-neutral, extensible mechanism for serializing structured data. You can learn more about it in protobuf's documentation.

This README file contains protobuf installation instructions. To install protobuf, you need to install the protocol compiler (used to compile .proto files) and the protobuf runtime for your chosen programming language.

Working With Protobuf Source Code

Most users will find working from supported releases to be the easiest path.

If you choose to work from the head revision of the main branch your build will occasionally be broken by source-incompatible changes and insufficiently-tested (and therefore broken) behavior.

If you are using C++ or otherwise need to build protobuf from source as a part of your project, you should pin to a release commit on a release branch.

This is because even release branches can experience some instability in between release commits.

Bazel with Bzlmod

Protobuf supports Bzlmod with Bazel 8 +. Users should specify a dependency on protobuf in their MODULE.bazel file as follows.

bazel_dep(name = "protobuf", version = <VERSION>)

Users can optionally override the repo name, such as for compatibility with WORKSPACE.

bazel_dep(name = "protobuf", version = <VERSION>, repo_name = "com_google_protobuf")

Bazel with WORKSPACE

Users can also add the following to their legacy WORKSPACE file.

Note that with the release of 30.x there are a few more load statements to properly set up rules_java and rules_python.

http_archive(
    name = "com_google_protobuf",
    strip_prefix = "protobuf-VERSION",
    sha256 = ...,
    url = ...,
)

load("@com_google_protobuf//:protobuf_deps.bzl", "protobuf_deps")

protobuf_deps()

load("@rules_java//java:rules_java_deps.bzl", "rules_java_dependencies")

rules_java_dependencies()

load("@rules_java//java:repositories.bzl", "rules_java_toolchains")

rules_java_toolchains()

load("@rules_python//python:repositories.bzl", "py_repositories")

py_repositories()

Protobuf Compiler Installation

The protobuf compiler is written in C++. If you are using C++, please follow the C++ Installation Instructions to install protoc along with the C++ runtime.

For non-C++ users, the simplest way to install the protocol compiler is to download a pre-built binary from our GitHub release page.

In the downloads section of each release, you can find pre-built binaries in zip packages: protoc-$VERSION-$PLATFORM.zip. It contains the protoc binary as well as a set of standard .proto files distributed along with protobuf.

If you are looking for an old version that is not available in the release page, check out the Maven repository.

These pre-built binaries are only provided for released versions. If you want to use the github main version at HEAD, or you need to modify protobuf code, or you are using C++, it's recommended to build your own protoc binary from source.

If you would like to build protoc binary from source, see the C++ Installation Instructions.

Protobuf Runtime Installation

Protobuf supports several different programming languages. For each programming language, you can find instructions in the corresponding source directory about how to install protobuf runtime for that specific language:

LanguageSource
C++ (include C++ runtime and protoc)src
Javajava
Pythonpython
Objective-Cobjectivec
C#csharp
Rubyruby
Goprotocolbuffers/protobuf-go
PHPphp
Dartdart-lang/protobuf
JavaScriptprotocolbuffers/protobuf-javascript

Quick Start

The best way to learn how to use protobuf is to follow the tutorials in our developer guide.

If you want to learn from code examples, take a look at the examples in the examples directory.

Documentation

The complete documentation is available at the Protocol Buffers doc site.

Support Policy

Read about our version support policy to stay current on support timeframes for the language libraries.

Developer Community

To be alerted to upcoming changes in Protocol Buffers and connect with protobuf developers and users, join the Google Group.