Question: how to deal with Regexp::Timeout in _decode_uri_component?
まだ誰も着手していません。
評価
調査の方向性
lib/uri/common.rb の参照されている _decode_uri_component パスから始め、大きなパーセントエンコード済みペイロードで Regexp::TimeoutError を再現します。maintainers と望ましい URI の動作について議論して定義し、その後 timeout のケースのカバレッジを追加して、選択したアプローチが報告された入力を処理できることを確認します。
索引モデルが issue の本文から書いたものです。
説明
Hi folks, thanks for maintaining the URI gem!
I faced the following issue with a 65MB mime-body payload and over 13 million percent-encoded characters:
Regexp::TimeoutError POST /rails/action_mailbox/mailgun/inbound_emails/mime
vendor/bundle/ruby/3.3.0/gems/uri-0.13.3/lib/uri/common.rb:400:in `match?': regexp match timeout (Regexp::TimeoutError)
from vendor/bundle/ruby/3.3.0/gems/uri-0.13.3/lib/uri/common.rb:400:in `_decode_uri_component'
Ref:
- https://github.com/ruby/uri/blob/v0.13.3/lib/uri/common.rb#L400
- https://github.com/ruby/uri/blob/v1.1.1/lib/uri/common.rb#L464
My workaround was to monkey patch the decode_www_form_component to avoid the Regexp code path if it times out:
module URIFormComponentLinearDecode
ORIGINAL_DECODE_WWW_FORM_COMPONENT = URI.method(:decode_www_form_component)
DECODE_TABLE = URI.const_get(:TBLDECWWWCOMP_)
def decode_www_form_component(str, enc = Encoding::UTF_8)
ORIGINAL_DECODE_WWW_FORM_COMPONENT.call(str, enc)
rescue Regexp::TimeoutError
raise unless str.is_a?(String)
Rails.logger.info("[URIFormComponentLinearDecode] bytesize=#{str.bytesize}")
linear_decode_www_form_component(str, enc)
end
private
def linear_decode_www_form_component(str, enc)
source = str.b
output = String.new(capacity: source.bytesize).b
index = 0
while index < source.bytesize
byte = source.getbyte(index)
case byte
when 37 # "%"
raise ArgumentError, "invalid %-encoding (#{str})" unless index + 2 < source.bytesize
encoded = source.byteslice(index, 3)
decoded = DECODE_TABLE[encoded]
raise ArgumentError, "invalid %-encoding (#{str})" unless decoded
output << decoded
index += 3
when 43 # "+"
output << DECODE_TABLE["+"]
index += 1
else
output << byte
index += 1
end
end
output.force_encoding(enc)
end
end
URI.singleton_class.prepend(URIFormComponentLinearDecode)
I was wondering:
- Did you guys face this problem before?
- Do you have a better approach to it?
- Do you think a solution to this issue belongs in the URI codebase?
- Do you think it would make sense to use a native function in this case?
I'm happy to contribute with a PR if you would like me to. Please let me know if you have any thoughts.
Thanks.
- 主要言語
- Ruby
- スター
- 125
- フォーク
- 65
- 平均マージ
- 6時間 4分
- マージ済み PR(30日)
- 2
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
ruby/uri のほかの issue
-
難易度 3/5 1〜2日 初心者へのやさしさ 48/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 25/100
-
難易度 3/5 1〜2日 初心者へのやさしさ 68/100
-
難易度 3/5 1〜2日 初心者へのやさしさ 52/100
-
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
bug
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
riscv/riscv-unified-db#2626 ·
-
Component: GLib
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
ds-drift
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
we-promise/sure#3693 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
simp/pupmod-simp-simp#395 ·