Range::bytes and ContentRange::bytes do unchecked u64 arithmetic on bounds
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 78/100
Hướng nghiên cứu
Start with src/common/range.rs and src/common/content_range.rs at the reported arithmetic lines, then run the supplied reproducer in debug and release profiles. Done means empty or unrepresentable bounds return InvalidRange or InvalidContentRange rather than panic or emit wrapped HTTP ranges.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Range::bytes and ContentRange::bytes convert range bounds with unchecked u64 arithmetic. Debug builds panic with "attempt to subtract with overflow". Release builds wrap to u64::MAX and emit headers describing a 2^64-byte span, and empty ranges with a non-zero start emit bytes=N-(N-1) in both profiles.
Crate version: headers 0.4.1, no feature flags.
Reproducer
use headers::{ContentRange, Header, HeaderValue, Range};
fn encode<H: Header>(h: &H) -> String {
let mut values: Vec<HeaderValue> = Vec::new();
h.encode(&mut values);
values[0].to_str().unwrap().to_owned()
}
fn main() {
println!("{}", encode(&Range::bytes(0u64..0u64).unwrap()));
println!("{}", encode(&Range::bytes(3u64..3u64).unwrap()));
println!("{}", encode(&ContentRange::bytes(0u64..0u64, 500u64).unwrap()));
println!("{}", encode(&ContentRange::bytes(0u64.., 0u64).unwrap()));
println!("{}", encode(&ContentRange::bytes(3u64..3u64, 100u64).unwrap()));
}
Observed
cargo run --release prints:
bytes=0-18446744073709551615
bytes=3-2
bytes 0-18446744073709551615/500
bytes 0-18446744073709551615/0
bytes 3-2/100
cargo run in debug panics on the first call at src/common/range.rs:56, so the program prints nothing. Run on their own in a debug build, ContentRange::bytes(0u64..0u64, 500u64) panics at src/common/content_range.rs:66 and ContentRange::bytes(0u64.., 0u64) panics at src/common/content_range.rs:68.
Expected
All five calls should return Err(InvalidRange) or Err(InvalidContentRange). Both constructors return a Result so unrepresentable bounds can be rejected. RFC 7233 section 2.1 requires last-byte-pos >= first-byte-pos in a byte-range-spec, so bytes=3-2 is invalid. RFC 7233 section 4.2 adds last-byte-pos < complete-length, which rules out bytes 0-18446744073709551615/0.
Root cause
src/common/range.rs:56:format!("bytes={}-{}", start, end - 1)src/common/content_range.rs:66:Bound::Excluded(&e) => e - 1,src/common/content_range.rs:68:Some(max) => max - 1,src/common/content_range.rs:60:Bound::Excluded(&s) => s + 1,, the mirrored addition on an excluded start bound. Not exercised here.
Scope
Any empty half-open range N..N passed to either constructor. Any ContentRange::bytes call with an unbounded end and complete_length == 0. Those 0..0 and zero-length forms panic in debug and wrap in release. The non-zero empty forms are silent in both.
- Ngôn ngữ chính
- Rust
- Star
- 200
- Fork
- 108
- Merge trung bình
- 3 ngày 2 giờ
- Pull request đã merge (30 ngày)
- 2
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của hyperium/headers
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
-
From<SystemTime> for HttpDate panics on times before 1970 or after year 9999Có thể đã có người làm @SAY-5 đã nhận 76 ngày trước. Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
-
Link supportĐang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 38/100
-
Access-Control-Request-Headers should not use a space when combiningCó thể đã có người làm @youdie006 đã nhận 53 ngày trước. Đang mởeasy
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 50/100
Tất cả issue của hyperium/headers
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
chroma-core/chroma#7879 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
priority middle
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 72/100
KATO-Hiro/AtCoderClans#12838 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
clap_complete env (PowerShell): values after a space don't complete in Windows PowerShell 5.1Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
Maintainer thường phản hồi trong vòng 1 ngày