Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Range::bytes and ContentRange::bytes do unchecked u64 arithmetic on bounds

オープン
#231 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

@youdie006 がすでに取り組んでいます。

2026年8月14日 から。

  • #235 @youdie006 による — オープン

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
78/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
静か
技術スタック
rust
領域
api

調査の方向性

Start with src/common/range.rs and src/common/content_range.rs at the reported arithmetic lines, then run the supplied reproducer in debug and release profiles. Done means empty or unrepresentable bounds return InvalidRange or InvalidContentRange rather than panic or emit wrapped HTTP ranges.

索引モデルが issue の本文から書いたものです。

説明

Range::bytes and ContentRange::bytes convert range bounds with unchecked u64 arithmetic. Debug builds panic with "attempt to subtract with overflow". Release builds wrap to u64::MAX and emit headers describing a 2^64-byte span, and empty ranges with a non-zero start emit bytes=N-(N-1) in both profiles.

Crate version: headers 0.4.1, no feature flags.

Reproducer

use headers::{ContentRange, Header, HeaderValue, Range};

fn encode<H: Header>(h: &H) -> String {
    let mut values: Vec<HeaderValue> = Vec::new();
    h.encode(&mut values);
    values[0].to_str().unwrap().to_owned()
}

fn main() {
    println!("{}", encode(&Range::bytes(0u64..0u64).unwrap()));
    println!("{}", encode(&Range::bytes(3u64..3u64).unwrap()));
    println!("{}", encode(&ContentRange::bytes(0u64..0u64, 500u64).unwrap()));
    println!("{}", encode(&ContentRange::bytes(0u64.., 0u64).unwrap()));
    println!("{}", encode(&ContentRange::bytes(3u64..3u64, 100u64).unwrap()));
}

Observed

cargo run --release prints:

bytes=0-18446744073709551615
bytes=3-2
bytes 0-18446744073709551615/500
bytes 0-18446744073709551615/0
bytes 3-2/100

cargo run in debug panics on the first call at src/common/range.rs:56, so the program prints nothing. Run on their own in a debug build, ContentRange::bytes(0u64..0u64, 500u64) panics at src/common/content_range.rs:66 and ContentRange::bytes(0u64.., 0u64) panics at src/common/content_range.rs:68.

Expected

All five calls should return Err(InvalidRange) or Err(InvalidContentRange). Both constructors return a Result so unrepresentable bounds can be rejected. RFC 7233 section 2.1 requires last-byte-pos >= first-byte-pos in a byte-range-spec, so bytes=3-2 is invalid. RFC 7233 section 4.2 adds last-byte-pos < complete-length, which rules out bytes 0-18446744073709551615/0.

Root cause

  • src/common/range.rs:56: format!("bytes={}-{}", start, end - 1)
  • src/common/content_range.rs:66: Bound::Excluded(&e) => e - 1,
  • src/common/content_range.rs:68: Some(max) => max - 1,
  • src/common/content_range.rs:60: Bound::Excluded(&s) => s + 1,, the mirrored addition on an excluded start bound. Not exercised here.

Scope

Any empty half-open range N..N passed to either constructor. Any ContentRange::bytes call with an unbounded end and complete_length == 0. Those 0..0 and zero-length forms panic in debug and wrap in release. The non-zero empty forms are silent in both.

主要言語
Rust
スター
200
フォーク
108
平均マージ
3日 2時間
マージ済み PR(30日)
2

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

hyperium/headers のほかの issue

hyperium/headers の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。