git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] http-backend: allow empty CONTENT_LENGTH

From
Jeff King <peff@peff.net>
Date
Sep 7, 2018, 03:38 UTC
Message-ID
<20180907033831.GB1383@sigill.intra.peff.net>
In-Reply-To
<20180907032740.GA20545@jessie.local>
On Fri, Sep 07, 2018 at 06:27:40AM +0300, Max Kirillov wrote:
Show 32 quoted lines
> On Thu, Sep 06, 2018 at 02:54:18PM -0700, Junio C Hamano wrote:
> > Max Kirillov <max@max630.net> writes:
> >> This should fix it. I'm not sure should it treat it as 0 or "-1"
> >> At least the tests mentioned by Jeff fails if I try to treat missing CONTENT_LENGTH as "-1"
> >> So keep the existing behavior as much as possible
> > 
> > I am not sure what you mean by the above, between 0 and -1.  The
> > code signals the caller of get_content_length() that req_len is -1
> > which is used as a sign to read through to the EOF, so it appears to
> > me that the code treats missing content-length (i.e. str == NULL
> > case) as "-1".
> 
> I made a mistake in this, it should be "if I try to treat missing
> CONTENT_LENGTH as 0". This, as far as I understand, what the
> RFC specifies.
> 
> That is, after the following change, the test "large fetch-pack
> requests can be split across POSTs" from t5551 starts faliing:
> 
> -- >8 --
> @@ -353,8 +353,12 @@ static ssize_t get_content_length(void)
>         ssize_t val = -1;
>         const char *str = getenv("CONTENT_LENGTH");
>  
> -       if (str && *str && !git_parse_ssize_t(str, &val))
> -               die("failed to parse CONTENT_LENGTH: %s", str);
> +       if (str && *str) {
> +               if (!git_parse_ssize_t(str, &val))
> +                       die("failed to parse CONTENT_LENGTH: %s", str);
> +       } else
> +               val = 0;
> +

Right, I'm pretty sure it is a problem if you treat a missing CONTENT_LENGTH as "present, but zero". Because chunked encodings from apache really do want us to read until EOF.

My understanding from Jelmer's report is that a present-but-empty variable should be counted as "0" to mean "do not read any body bytes". That matches my reading of RFC 3875, which says:

  If no data is attached, then NULL (or unset).

(and earlier they explicitly define NULL as the empty string). That said, we do not do what they say for the "unset" case. And cannot without breaking chunked encoding from apache. So I don't know how much we want to follow that rfc to the letter, but at least it makes sense to me to revert this case back to what Git used to do, and what the rfc says.

In other words, I think the logic we want is:
  if (!str) {
	/*
	 * RFC3875 says this must mean "no body", but in practice we
	 * receive chunked encodings with no CONTENT_LENGTH. Tell the
	 * caller to read until EOF.
	 */
	val = -1;
  } else if (!*str) {
	/*
	 * An empty length should be treated as "no body" according to
	 * RFC3875, and this seems to hold in practice.
	 */
	val = 0;
  } else {
	/*
	 * We have a CONTENT_LENGTH; trust what's in it as long as it
	 * can be parsed.
	 */
	if (!git_parse_ssize_t(str, &val))
	        die(...);
  }
-Peff
Previous: Max KirillovNext: Max Kirillov
Message 5 of 39 in “Re: CONTENT_LENGTH can no longer be empty”
  1. Jonathan NiederSep 6, 2018
  2. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 6, 2018
  3. Junio C HamanoSep 6, 2018
  4. Max KirillovSep 7, 2018
  5. Jeff KingSep 7, 2018
  6. Max KirillovSep 7, 2018
  7. Max KirillovSep 7, 2018
  8. Junio C HamanoSep 7, 2018
  9. Max KirillovSep 8, 2018
  10. Max KirillovSep 9, 2018
  11. Jonathan NiederSep 6, 2018
  12. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 7, 2018
  13. Jonathan NiederSep 8, 2018
  14. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 8, 2018
  15. Jonathan NiederSep 10, 2018
  16. Max KirillovSep 10, 2018
  17. Jonathan NiederSep 11, 2018
  18. http-backend test: make empty CONTENT_LENGTH test more realisticMax Kirillov, Sep 11, 2018
  19. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 8, 2018
  20. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 9, 2018
  21. Jonathan NiederSep 10, 2018
  22. Jeff KingSep 10, 2018
  23. Junio C HamanoSep 10, 2018
  24. Jeff KingSep 10, 2018
  25. http-backend: Treat empty CONTENT_LENGTH as zeroMax Kirillov, Sep 10, 2018
  26. Jonathan NiederSep 10, 2018
  27. Jeff KingSep 11, 2018
  28. Jonathan NiederSep 11, 2018
  29. Jeff KingSep 11, 2018
  30. Jeff KingSep 11, 2018
  31. http-backend: treat empty CONTENT_LENGTH as zeroJonathan Nieder, Sep 11, 2018
  32. Jonathan NiederSep 11, 2018
  33. Junio C HamanoSep 11, 2018
  34. Junio C HamanoSep 11, 2018
  35. Jeff KingSep 12, 2018
  36. Jonathan NiederSep 12, 2018
  37. Junio C HamanoSep 12, 2018
  38. Junio C HamanoSep 11, 2018
  39. Jonathan NiederSep 11, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.