Content-Length: 278686 | pFad | https://github.com/h2o/h2o/pull/1502

70 fix offset overflow of SCRIPT_INFO and PATH_INFO by i110 · Pull Request #1502 · h2o/h2o · GitHub
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix offset overflow of SCRIPT_INFO and PATH_INFO #1502

Merged
merged 5 commits into from
Nov 21, 2017
Merged

Conversation

i110
Copy link
Contributor

@i110 i110 commented Nov 20, 2017

There are several bugs in calculating PATH_INFO and SCRIPT_NAME in mruby handlers.

  1. PATH_INFO gets broken when confpath_len_wo_slash is zero and path normalization happens . This is caused by keep mruby's PATH_INFO undecoded #1480
  2. also SCRIPT_NAME can be broken when req->pathconf->path.len is zero and index overflow happens (here). This is a long standing bug, maybe
  3. both of them can be broken when req->path doesn't have a leading slash. This is caused by keep mruby's PATH_INFO undecoded #1480

Especially 1. and 2. may leeds ArgumentError: string size is too big error in mruby layer. This PR fixes these issues.

Thank you for finding and reporting the bug @ykzts

@utrenkner
Copy link
Contributor

Wow, it looks like this could actually fix the problems I am experiencing. I will give it a shot, once it is merged.

@kazuho
Copy link
Member

kazuho commented Nov 21, 2017

note:

  1. also SCRIPT_NAME can be broken when req->pathconf->path.len is zero and index overflow happens (here). This is a long standing bug, maybe

We have agreed that this is a configuration issue, and #1506 has been created to forbid such misconfiguration.

@kazuho kazuho merged commit 48b6402 into master Nov 21, 2017
@kazuho
Copy link
Member

kazuho commented Nov 21, 2017

Thank you for the fixes!

kazuho added a commit that referenced this pull request Dec 7, 2017
fix possible offset overflow of SCRIPT_INFO and PATH_INFO
@kazuho kazuho changed the title fix possible offset overflow of SCRIPT_INFO and PATH_INFO fix offset overflow of SCRIPT_INFO and PATH_INFO Dec 14, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants








ApplySandwichStrip

pFad - (p)hone/(F)rame/(a)nonymizer/(d)eclutterfier!      Saves Data!


--- a PPN by Garber Painting Akron. With Image Size Reduction included!

Fetched URL: https://github.com/h2o/h2o/pull/1502

Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy