Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Range::bytes and ContentRange::bytes do unchecked u64 arithmetic on bounds

Đang mở
#231 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

@youdie006 đang làm issue này rồi.

Từ ngày 14/8/2026.

  • #235 của @youdie006 — đang mở

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
78/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
rust
Lĩnh vực
api

Hướng nghiên cứu

Start with src/common/range.rs and src/common/content_range.rs at the reported arithmetic lines, then run the supplied reproducer in debug and release profiles. Done means empty or unrepresentable bounds return InvalidRange or InvalidContentRange rather than panic or emit wrapped HTTP ranges.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Range::bytes and ContentRange::bytes convert range bounds with unchecked u64 arithmetic. Debug builds panic with "attempt to subtract with overflow". Release builds wrap to u64::MAX and emit headers describing a 2^64-byte span, and empty ranges with a non-zero start emit bytes=N-(N-1) in both profiles.

Crate version: headers 0.4.1, no feature flags.

Reproducer

use headers::{ContentRange, Header, HeaderValue, Range};

fn encode<H: Header>(h: &H) -> String {
    let mut values: Vec<HeaderValue> = Vec::new();
    h.encode(&mut values);
    values[0].to_str().unwrap().to_owned()
}

fn main() {
    println!("{}", encode(&Range::bytes(0u64..0u64).unwrap()));
    println!("{}", encode(&Range::bytes(3u64..3u64).unwrap()));
    println!("{}", encode(&ContentRange::bytes(0u64..0u64, 500u64).unwrap()));
    println!("{}", encode(&ContentRange::bytes(0u64.., 0u64).unwrap()));
    println!("{}", encode(&ContentRange::bytes(3u64..3u64, 100u64).unwrap()));
}

Observed

cargo run --release prints:

bytes=0-18446744073709551615
bytes=3-2
bytes 0-18446744073709551615/500
bytes 0-18446744073709551615/0
bytes 3-2/100

cargo run in debug panics on the first call at src/common/range.rs:56, so the program prints nothing. Run on their own in a debug build, ContentRange::bytes(0u64..0u64, 500u64) panics at src/common/content_range.rs:66 and ContentRange::bytes(0u64.., 0u64) panics at src/common/content_range.rs:68.

Expected

All five calls should return Err(InvalidRange) or Err(InvalidContentRange). Both constructors return a Result so unrepresentable bounds can be rejected. RFC 7233 section 2.1 requires last-byte-pos >= first-byte-pos in a byte-range-spec, so bytes=3-2 is invalid. RFC 7233 section 4.2 adds last-byte-pos < complete-length, which rules out bytes 0-18446744073709551615/0.

Root cause

  • src/common/range.rs:56: format!("bytes={}-{}", start, end - 1)
  • src/common/content_range.rs:66: Bound::Excluded(&e) => e - 1,
  • src/common/content_range.rs:68: Some(max) => max - 1,
  • src/common/content_range.rs:60: Bound::Excluded(&s) => s + 1,, the mirrored addition on an excluded start bound. Not exercised here.

Scope

Any empty half-open range N..N passed to either constructor. Any ContentRange::bytes call with an unbounded end and complete_length == 0. Those 0..0 and zero-length forms panic in debug and wrap in release. The non-zero empty forms are silent in both.

Ngôn ngữ chính
Rust
Star
200
Fork
108
Merge trung bình
3 ngày 2 giờ
Pull request đã merge (30 ngày)
2

Chuẩn bị môi trường

Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của hyperium/headers

Tất cả issue của hyperium/headers

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.