Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

A `\:` route and a `:param` route at the same position make `ServeHTTP` panic or return 404

未关闭
#3,111 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
65/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
技术栈
go
领域
api, backend

调研方向

Start by running the supplied Go reproducer and tracing the route matching reached through ServeHTTP. Add focused regression coverage for both registration orders, with /name:verb/x served by /name:verb/x and /name1 served by /name:id with id=1, without a panic; both routes should remain reachable.

由索引模型根据 Issue 内容生成。

描述

Issue Description

Registering a route with an escaped colon (/name\:verb/x) together with a route that has a
parameter at the same position (/name:id) makes one of them unreachable, depending on the order:
registered in that order, GET /name:verb/x panics inside ServeHTTP with index out of range [-1] and GET /name1 is a 404; registered the other way round, GET /name:verb/x is a 404. Each
route on its own is served as expected.

Working code to debug
package main

import (
	"fmt"
	"net/http"
	"net/http/httptest"
	"strings"

	"github.com/labstack/echo/v5"
)

func get(e *echo.Echo, path string) (out string) {
	defer func() {
		if r := recover(); r != nil {
			out = fmt.Sprintf("panic: %v", r)
		}
	}()
	rec := httptest.NewRecorder()
	e.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, path, nil))
	return fmt.Sprintf("%d %s", rec.Code, strings.TrimSpace(rec.Body.String()))
}

func main() {
	handler := func(c *echo.Context) error {
		return c.String(http.StatusOK, "route "+c.RouteInfo().Path+" id="+c.Param("id"))
	}
	for _, routes := range [][]string{
		{`/name\:verb/x`},
		{`/name\:verb/x`, `/name:id`},
		{`/name:id`, `/name\:verb/x`},
	} {
		e := echo.New()
		for _, p := range routes {
			e.GET(p, handler)
		}
		fmt.Printf("routes %s\n", routes)
		for _, path := range []string{"/name:verb/x", "/name1"} {
			fmt.Printf("  GET %-13s -> %s\n", path, get(e, path))
		}
	}
}

Output:

routes [/name\:verb/x]
  GET /name:verb/x  -> 200 route /name\:verb/x id=
  GET /name1        -> 404 {"message":"Not Found"}
routes [/name\:verb/x /name:id]
  GET /name:verb/x  -> panic: runtime error: index out of range [-1]
  GET /name1        -> 404 {"message":"Not Found"}
routes [/name:id /name\:verb/x]
  GET /name:verb/x  -> 404 {"message":"Not Found"}
  GET /name1        -> 200 route /name:id id=1

The recover in get is only there to keep the program going: without it the panic propagates
out of e.ServeHTTP, and with a real server the client gets a closed connection instead of a
response. I expected both routes to be served in either order of registration, as each is when
registered alone: GET /name:verb/x by /name\:verb/x and GET /name1 by /name:id with
id=1.

Version/commit

echo v5.3.1 and current master (3d084be), Go 1.27.1.

BTW, this was found by an automated program that writes property-based tests for various open source projects using hegel (but it has been reviewed by hand before reporting). We've also potentially found (but not yet hand validated) 12 other bugs in echo. You can see the tests at https://github.com/hegeldev/hegel-zoo/tree/main/targets/go/echo. Let us know if you would like us to file the other bugs found and/or contribute the tests. NB the tests are currently LLM generated and probably not yet suitable for inclusion as is, but we're happy to help get them into a better state if you want them.

主要语言
Go
星标
32.7k
派生
2.8k
平均合并
9 小时 39 分钟
30 天内合并 PR
6

贡献指南

这个仓库没有索引到贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

labstack/echo 的其他 Issue

查看 labstack/echo 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。