BindHeaders panics on nil or empty header value slices
メンテナーはふだん 1 日以内に返信
評価
調査の方向性
bind.go から始め、BindHeaders を bindData 経由でたどり、issue で示されたスカラー map とタグ付き struct の経路を確認してください。提供されたインプロセスの再現コードを使って、nil および空のヘッダー値スライスを確認し、その後、3 つすべての対象型と指定された対照ケースを調べてください。バインドで panic が発生しなくなり、選択した動作が回帰テストでカバーされていれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Issue Description
BindHeaders panics when an in-process request header contains a key whose value is a nil or zero-length []string. This is different from []string{""}, which binds without a panic.
On current master, BindHeaders passes the header map to bindData. The scalar-map paths read v[0], and the tagged struct path reads inputValue[0], without checking the slice length. With Header["X-Empty"] = nil or []string{}, these paths panic with index out of range [0] with length 0 instead of returning normally/an error.
This reproduction constructs the request in-process. I have not demonstrated a way for a raw incoming HTTP header to produce this map state, and I am not claiming a remotely exploitable denial of service.
Working code to debug
package echo_test
import (
"net/http"
"net/http/httptest"
"testing"
"github.com/labstack/echo/v5"
)
func TestEmptyHeaderValues(t *testing.T) {
for _, values := range [][]string{nil, {}} {
func() {
defer func() {
if p := recover(); p != nil {
t.Errorf("BindHeaders panicked: %v", p)
}
}()
e := echo.New()
req := httptest.NewRequest(http.MethodGet, "/", nil)
req.Header["X-Empty"] = values
c := e.NewContext(req, httptest.NewRecorder())
var dst struct { Value string `header:"X-Empty"` }
if err := echo.BindHeaders(c, &dst); err != nil {
t.Errorf("BindHeaders: %v", err)
}
}()
}
}
I also reproduced the panic for ordinary *map[string]string and *map[string]any targets. A private table test against unchanged master produced 6 failing panic cases (nil/empty slices × three targets) and 6 passing no-panic controls (normal value/one empty string × three targets). Package go vet passed; no full-suite, race, other Go-version or OS run is claimed.
Proposed narrow follow-up
Would skipping entries with no values be the preferred treatment, or should binding return a specific error? I can prepare a narrow bind.go/regression follow-up after confirming this policy and coordination with #3150, which changes adjacent map assignment code but still indexes v[0]. This would not alter named-map conversions, first-value versus all-values behavior, []string{""} semantics, or existing custom multi-value unmarshalling without agreement. #2778's empty-string-to-nil-pointer proposal is a different input case.
Version/commit
- master
3882266a3641a36fc2111b48cd597adab1c1ecea, modulegithub.com/labstack/echo/v5 - Go 1.27.1, Linux/arm64; synthetic requests, no running application/provider
- OpenAI Codex assisted with source tracing and the reproduction. No production fix/PR has been submitted.
- 主要言語
- Go
- スター
- 32.8k
- フォーク
- 4.2k
- 平均マージ
- 8時間 54分
- マージ済み PR(30日)
- 32
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
labstack/echo のほかの issue
-
Group routes does not work without leading slash対応中かも @team-humaki が 21 日前に担当しました。 オープンenhancement router v5
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
labstack/echo#3099 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
enhancement v5
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
labstack/echo#3066 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
Rate limit middleware doesn't set headers or provide metadata via interface.対応中かも @AdamMagued が 2 日前に担当しました。 オープンenhancement middleware
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
labstack/echo#2961 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
enhancement router
難易度 4/5 3〜5日 初心者へのやさしさ 42/100
labstack/echo#2895 · コメント 16 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 3/5 1〜2日 初心者へのやさしさ 45/100
labstack/echo#2803 · コメント 4 件 ·
メンテナーはふだん 1 日以内に返信
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 66/100
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
signal18/replication-manager#1981 ·
メンテナーはふだん 1 日以内に返信
-
Battery UI: German word "Speicher"対応中かも @github-actions が今日担当しました。 オープンux
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
evcc-io/evcc#34716 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
ready-for-agent
難易度 2/5 1〜3時間 初心者へのやさしさ 83/100
jasonfen/terminal-space-program#611 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
prime-radiant-inc/evener#4329 ·
メンテナーはふだん 1 日以内に返信