git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v4] http-backend: allow empty CONTENT_LENGTH

From
Jeff King <peff@peff.net>
Date
Sep 10, 2018, 13:17 UTC
Message-ID
<20180910131724.GA5233@sigill.intra.peff.net>
In-Reply-To
<20180910052558.GB55941@aiede.svl.corp.google.com>
On Sun, Sep 09, 2018 at 10:25:58PM -0700, Jonathan Nieder wrote:
Show 28 quoted lines
> > --- a/http-backend.c
> > +++ b/http-backend.c
> > @@ -353,8 +353,28 @@ static ssize_t get_content_length(void)
> >  	ssize_t val = -1;
> >  	const char *str = getenv("CONTENT_LENGTH");
> >  
> > -	if (str && !git_parse_ssize_t(str, &val))
> > -		die("failed to parse CONTENT_LENGTH: %s", str);
> > +	if (!str) {
> > +		/*
> > +		 * RFC3875 says this must mean "no body", but in practice we
> > +		 * receive chunked encodings with no CONTENT_LENGTH. Tell the
> > +		 * caller to read until EOF.
> > +		 */
> > +		val = -1;
> > +	} else if (!*str) {
> > +		/*
> > +		 * An empty length should be treated as "no body" according to
> > +		 * RFC3875, and this seems to hold in practice.
> > +		 */
> > +		val = 0;
> 
> Are there example callers that this version fixes?  Where can I read
> more, or what can I run to experience it?
> 
> For example, v2.19.0-rc0~45^2~2 (http-backend: respect CONTENT_LENGTH
> as specified by rfc3875, 2018-06-10) mentions IIS/Windows; does IIS
> make use of this distinction?

So this code is what I recommended based on my reading of the RFC, and based on my understanding of the Debian bug. But I admit I'm confused.

I thought the complaint was that this:
  CONTENT_LENGTH= git http-backend

was reading a body, when it shouldn't be. And so setting it to 0 here made sense.

But that couldn't have been what older versions were doing, since they never looked at CONTENT_LENGTH at all, and instead always read to EOF. So presumably the original problem wasn't that we tried to read a body, but that the empty string caused git_parse_ssize_t to report failure, and we called die(). Which probably should be explained by 574c513e8d (http-backend: allow empty CONTENT_LENGTH, 2018-09-07), but it's too late for that.

So after that patch, we really do have the original behavior, and that's enough for v2.19.

But the remaining question then is: what should clients expect on an empty variable? We know what the RFC says, and we know what dulwich expected, but I'm not sure we have real world cases beyond that. So it might actually make sense to punt until we see one, though I don't mind doing what the rfc says in the meantime. And then the explanation in the commit message would be "do what the rfc says", and any test probably ought to be feeding a non-empty empty and confirming that we don't read it.

-Peff
Previous: Jonathan NiederNext: Junio C Hamano
Message 22 of 39 in “Re: CONTENT_LENGTH can no longer be empty”
  1. Jonathan NiederSep 6, 2018
  2. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 6, 2018
  3. Junio C HamanoSep 6, 2018
  4. Max KirillovSep 7, 2018
  5. Jeff KingSep 7, 2018
  6. Max KirillovSep 7, 2018
  7. Max KirillovSep 7, 2018
  8. Junio C HamanoSep 7, 2018
  9. Max KirillovSep 8, 2018
  10. Max KirillovSep 9, 2018
  11. Jonathan NiederSep 6, 2018
  12. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 7, 2018
  13. Jonathan NiederSep 8, 2018
  14. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 8, 2018
  15. Jonathan NiederSep 10, 2018
  16. Max KirillovSep 10, 2018
  17. Jonathan NiederSep 11, 2018
  18. http-backend test: make empty CONTENT_LENGTH test more realisticMax Kirillov, Sep 11, 2018
  19. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 8, 2018
  20. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 9, 2018
  21. Jonathan NiederSep 10, 2018
  22. Jeff KingSep 10, 2018
  23. Junio C HamanoSep 10, 2018
  24. Jeff KingSep 10, 2018
  25. http-backend: Treat empty CONTENT_LENGTH as zeroMax Kirillov, Sep 10, 2018
  26. Jonathan NiederSep 10, 2018
  27. Jeff KingSep 11, 2018
  28. Jonathan NiederSep 11, 2018
  29. Jeff KingSep 11, 2018
  30. Jeff KingSep 11, 2018
  31. http-backend: treat empty CONTENT_LENGTH as zeroJonathan Nieder, Sep 11, 2018
  32. Jonathan NiederSep 11, 2018
  33. Junio C HamanoSep 11, 2018
  34. Junio C HamanoSep 11, 2018
  35. Jeff KingSep 12, 2018
  36. Jonathan NiederSep 12, 2018
  37. Junio C HamanoSep 12, 2018
  38. Junio C HamanoSep 11, 2018
  39. Jonathan NiederSep 11, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.