Repository navigation
Enforce max_line_size on fragmented request target and reason in C parser - #12826
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #12826 +/- ##
==========================================
+ Coverage 98.94% 99.14% +0.20%
==========================================
Files 131 128 -3
Lines 47099 46424 -675
Branches 2435 2435
==========================================
- Hits 46600 46027 -573
+ Misses 376 274 -102
Partials 123 123
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. |
PR Review — Enforce max_line_size on fragmented request target and reason in C parserCorrect, minimal fix that closes a real bypass of
Checklist
Automated review by Kōan (Claude) |
Merging this PR will not alter performance
Comparing Footnotes
|
Backport to 3.14: 💔 cherry-picking failed — conflicts found❌ Failed to cleanly apply 36df6c1 on top of patchback/backports/3.14/36df6c138d10c5776a25c69b698c41153d84d571/pr-12826 Backporting merged PR #12826 into master
🤖 @patchback |
Backport to 3.15: 💔 cherry-picking failed — conflicts found❌ Failed to cleanly apply 36df6c1 on top of patchback/backports/3.15/36df6c138d10c5776a25c69b698c41153d84d571/pr-12826 Backporting merged PR #12826 into master
🤖 @patchback |
…ed request target and reason in C parser (#12838)
…ed request target and reason in C parser (#12837)
What do these changes do?
The C HTTP parser receives the request target and response reason phrase through
on_urlandon_statuscallbacks, which can fire multiple times for a single line when it is split across reads. Each callback only compared its own fragment againstmax_line_size, so a line split into small enough pieces could accumulate past the limit without raisingLineTooLong. This checks the accumulated buffer length plus the new fragment instead, so the limit is enforced on the whole line, matching the pure-Python parser.Are there changes in behavior for the user?
A request target or response reason phrase that exceeds
max_line_sizeis now rejected withLineTooLongeven when it arrives split across multiple reads; previously the C parser accepted it. Lines within the limit are unaffected.Is it a substantial burden for the maintainers to support this?
No.
Related issue number
N/A
Checklist
CONTRIBUTORS.txtN/A, already listedCHANGES/folder