git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v7 1/2] http-backend: respect CONTENT_LENGTH as specified by rfc3875

From
Max Kirillov <max@max630.net>
Date
Jun 2, 2018, 21:27 UTC
Message-ID
<20180602212749.21324-2-max@max630.net>
In-Reply-To
<20180602212749.21324-1-max@max630.net>

http-backend reads whole input until EOF. However, the RFC 3875 specifies that a script must read only as many bytes as specified by CONTENT_LENGTH environment variable. Web server may exercise the specification by not closing the script's standard input after writing content. In that case http-backend would hang waiting for the input. The issue is known to happen with IIS/Windows, for example.

Make http-backend read only CONTENT_LENGTH bytes, if it's defined, rather than the whole input until EOF. If the variable is not defined, keep older behavior of reading until EOF because it is used to support chunked transfer-encoding.

Signed-off-by: Florian Manschwetus <manschwetus@cs-software-gmbh.de>
[mk: fixed trivial build failures and polished style issues]
Helped-by: Junio C Hamano <gitster@pobox.com>
Signed-off-by: Max Kirillov <max@max630.net>
---
 config.c       |  2 +-
 config.h       |  1 +
 http-backend.c | 43 ++++++++++++++++++++++++++++++++++++++++++-
 3 files changed, 44 insertions(+), 2 deletions(-)
diff --git a/config.c b/config.c
index c698988f5e..4148a3529d 100644
--- a/config.c
+++ b/config.c
@@ -853,7 +853,7 @@ int git_parse_ulong(const char *value, unsigned long *ret)
 	return 1;
 }
 
-static int git_parse_ssize_t(const char *value, ssize_t *ret)
+int git_parse_ssize_t(const char *value, ssize_t *ret)
 {
 	intmax_t tmp;
 	if (!git_parse_signed(value, &tmp, maximum_signed_value_of_type(ssize_t)))
diff --git a/config.h b/config.h
index ef70a9cac1..c143a1b634 100644
--- a/config.h
+++ b/config.h
@@ -48,6 +48,7 @@ extern void git_config(config_fn_t fn, void *);
 extern int config_with_options(config_fn_t fn, void *,
 			       struct git_config_source *config_source,
 			       const struct config_options *opts);
+extern int git_parse_ssize_t(const char *, ssize_t *);
 extern int git_parse_ulong(const char *, unsigned long *);
 extern int git_parse_maybe_bool(const char *);
 extern int git_config_int(const char *, const char *);
diff --git a/http-backend.c b/http-backend.c
index 88d2a9bc40..3066697a24 100644
--- a/http-backend.c
+++ b/http-backend.c
@@ -283,7 +283,7 @@ static struct rpc_service *select_service(struct strbuf *hdr, const char *name)
  * hit max_request_buffer we die (we'd rather reject a
  * maliciously large request than chew up infinite memory).
  */
-static ssize_t read_request(int fd, unsigned char **out)
+static ssize_t read_request_eof(int fd, unsigned char **out)
 {
 	size_t len = 0, alloc = 8192;
 	unsigned char *buf = xmalloc(alloc);
@@ -320,6 +320,47 @@ static ssize_t read_request(int fd, unsigned char **out)
 	}
 }
 
+static ssize_t read_request_fixed_len(int fd, ssize_t req_len, unsigned char **out)
+{
+	unsigned char *buf = NULL;
+	ssize_t cnt = 0;
+
+	if (max_request_buffer < req_len) {
+		die("request was larger than our maximum size (%lu): "
+		    "%" PRIuMAX "; try setting GIT_HTTP_MAX_REQUEST_BUFFER",
+		    max_request_buffer, (uintmax_t)req_len);
+	}
+
+	buf = xmalloc(req_len);
+	cnt = read_in_full(fd, buf, req_len);
+	if (cnt < 0) {
+		free(buf);
+		return -1;
+	}
+	*out = buf;
+	return cnt;
+}
+
+static ssize_t get_content_length(void)
+{
+	ssize_t val = -1;
+	const char *str = getenv("CONTENT_LENGTH");
+
+	if (str && !git_parse_ssize_t(str, &val))
+		die("failed to parse CONTENT_LENGTH: %s", str);
+	return val;
+}
+
+static ssize_t read_request(int fd, unsigned char **out)
+{
+	ssize_t req_len = get_content_length();
+
+	if (req_len < 0)
+		return read_request_eof(fd, out);
+	else
+		return read_request_fixed_len(fd, req_len, out);
+}
+
 static void inflate_request(const char *prog_name, int out, int buffer_input)
 {
 	git_zstream stream;
-- 
2.17.0.1185.g782057d875
Previous: Max KirillovNext: Jeff King
Message 2 of 31 in “http-backend: respect CONTENT_LENGTH as specified by rfc3875”
  1. 0/2 http-backend: respect CONTENT_LENGTH as specified by rfc3875Max Kirillov, Jun 2, 2018
  2. 1/2 http-backend: respect CONTENT_LENGTH as specified by rfc3875Max Kirillov, Jun 2, 2018
  3. Jeff KingJun 4, 2018
  4. 2/2 http-backend: respect CONTENT_LENGTH for receive-packMax Kirillov, Jun 2, 2018
  5. Junio C HamanoJun 4, 2018
  6. Max KirillovJun 4, 2018
  7. Ramsay JonesJun 5, 2018
  8. Jeff KingJun 4, 2018
  9. Max KirillovJun 4, 2018
  10. Max KirillovJun 10, 2018
  11. Jeff KingJun 11, 2018
  12. Jeff KingJun 11, 2018
  13. Max KirillovJun 10, 2018
  14. Jeff KingJun 11, 2018
  15. 0/3 http-backend: respect CONTENT_LENGTH as specified by rfc3875Max Kirillov, Jun 10, 2018
  16. 1/3 http-backend: cleanup writing to child processMax Kirillov, Jun 10, 2018
  17. 2/3 http-backend: respect CONTENT_LENGTH as specified by rfc3875Max Kirillov, Jun 10, 2018
  18. 3/3 http-backend: respect CONTENT_LENGTH for receive-packMax Kirillov, Jun 10, 2018
  19. SZEDER GáborJul 25, 2018
  20. Max KirillovJul 25, 2018
  21. SZEDER GáborJul 25, 2018
  22. Max KirillovJul 26, 2018
  23. 0/3 http-backend: respect CONTENT_LENGTH as specified by rfc3875Max Kirillov, Jul 27, 2018
  24. 1/3 http-backend: cleanup writing to child processMax Kirillov, Jul 27, 2018
  25. 2/3 http-backend: respect CONTENT_LENGTH as specified by rfc3875Max Kirillov, Jul 27, 2018
  26. Duy NguyenAug 4, 2018
  27. Max KirillovAug 4, 2018
  28. Junio C HamanoAug 4, 2018
  29. 3/3 http-backend: respect CONTENT_LENGTH for receive-packMax Kirillov, Jul 27, 2018
  30. Max KirillovJul 27, 2018
  31. Junio C HamanoJul 27, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.