git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] http-backend: treat empty CONTENT_LENGTH as zero

From
Jonathan Nieder <jrnieder@gmail.com>
Date
Sep 11, 2018, 04:03 UTC
Message-ID
<20180911040343.GC20518@aiede.svl.corp.google.com>
In-Reply-To
<20180911034227.GB20518@aiede.svl.corp.google.com>
Kicking off the reviews: ;-)
Jonathan Nieder wrote:
Show 5 quoted lines
> --- a/http-backend.c
> +++ b/http-backend.c
> @@ -350,10 +350,25 @@ static ssize_t read_request_fixed_len(int fd, ssize_t req_len, unsigned char **o
>  
>  static ssize_t get_content_length(void)
[...]
Show 5 quoted lines
> +		/*
> +		 * According to RFC 3875, an empty or missing
> +		 * CONTENT_LENGTH means "no body", but RFC 3875
> +		 * precedes HTTP/1.1 and chunked encoding. Apache and
> +		 * its imitators leave CONTENT_LENGTH unset for
Which imitators?  Maybe this should just say "Apache leaves [...]".
Show 5 quoted lines
> +		 * chunked requests, for which we should use EOF to
> +		 * detect the end of the request.
> +		 */
> +		str = getenv("HTTP_TRANSFER_ENCODING");
> +		if (str && !strcmp(str, "chunked"))

RFC 2616 says Transfer-Encoding is a list of transfer-codings applied, in the order that they were applied, and that "chunked" is always applied last. That means a transfer-encoding like

	Transfer-Encoding: identity chunked
would be permitted, or e.g.
	Transfer-Encoding: gzip chunked
Does that means we should be using a check like
	str && (!strcmp(str, "chunked") || ends_with(str, " chunked"))
?

That said, a quick search of codesearch.debian.net mostly finds examples using straight comparison, so maybe the patch is fine as-is.

Thanks, Jonathan

Previous: Jonathan NiederNext: Junio C Hamano
Message 32 of 39 in “Re: CONTENT_LENGTH can no longer be empty”
  1. Jonathan NiederSep 6, 2018
  2. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 6, 2018
  3. Junio C HamanoSep 6, 2018
  4. Max KirillovSep 7, 2018
  5. Jeff KingSep 7, 2018
  6. Max KirillovSep 7, 2018
  7. Max KirillovSep 7, 2018
  8. Junio C HamanoSep 7, 2018
  9. Max KirillovSep 8, 2018
  10. Max KirillovSep 9, 2018
  11. Jonathan NiederSep 6, 2018
  12. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 7, 2018
  13. Jonathan NiederSep 8, 2018
  14. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 8, 2018
  15. Jonathan NiederSep 10, 2018
  16. Max KirillovSep 10, 2018
  17. Jonathan NiederSep 11, 2018
  18. http-backend test: make empty CONTENT_LENGTH test more realisticMax Kirillov, Sep 11, 2018
  19. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 8, 2018
  20. http-backend: allow empty CONTENT_LENGTHMax Kirillov, Sep 9, 2018
  21. Jonathan NiederSep 10, 2018
  22. Jeff KingSep 10, 2018
  23. Junio C HamanoSep 10, 2018
  24. Jeff KingSep 10, 2018
  25. http-backend: Treat empty CONTENT_LENGTH as zeroMax Kirillov, Sep 10, 2018
  26. Jonathan NiederSep 10, 2018
  27. Jeff KingSep 11, 2018
  28. Jonathan NiederSep 11, 2018
  29. Jeff KingSep 11, 2018
  30. Jeff KingSep 11, 2018
  31. http-backend: treat empty CONTENT_LENGTH as zeroJonathan Nieder, Sep 11, 2018
  32. Jonathan NiederSep 11, 2018
  33. Junio C HamanoSep 11, 2018
  34. Junio C HamanoSep 11, 2018
  35. Jeff KingSep 12, 2018
  36. Jonathan NiederSep 12, 2018
  37. Junio C HamanoSep 12, 2018
  38. Junio C HamanoSep 11, 2018
  39. Jonathan NiederSep 11, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.