annotate src/http/v2/ngx_http_v2_encode.c @ 7710:097f578a4a8f

HTTP/2: fixed segfault on DATA frames after 400 errors. If 400 errors were redirected to an upstream server using the error_page directive, DATA frames from the client might cause segmentation fault due to null pointer dereference. The bug had appeared in 6989:2c4dbcd6f2e4 (1.13.0). Fix is to skip such frames in ngx_http_v2_state_read_data() (similarly to 7561:9f1f9d6e056a). With the fix, behaviour of 400 errors in HTTP/2 is now similar to one in HTTP/1.x, that is, nginx doesn't try to read the request body. Note that proxying 400 errors, as well as other early stage errors, to upstream servers might not be a good idea anyway. These errors imply that reading and processing of the request (and the request headers) wasn't complete, and proxying of such incomplete request might lead to various errors. Reported by Chenglong Zhang.
author Maxim Dounin <mdounin@mdounin.ru>
date Wed, 23 Sep 2020 19:50:49 +0300
parents 87e9e4aabf1b
children 336084ff943b
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
7229
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
1
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
2 /*
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
3 * Copyright (C) Nginx, Inc.
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
4 * Copyright (C) Valentin V. Bartenev
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
5 */
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
6
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
7
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
8 #include <ngx_config.h>
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
9 #include <ngx_core.h>
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
10 #include <ngx_http.h>
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
11
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
12
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
13 static u_char *ngx_http_v2_write_int(u_char *pos, ngx_uint_t prefix,
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
14 ngx_uint_t value);
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
15
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
16
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
17 u_char *
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
18 ngx_http_v2_string_encode(u_char *dst, u_char *src, size_t len, u_char *tmp,
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
19 ngx_uint_t lower)
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
20 {
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
21 size_t hlen;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
22
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
23 hlen = ngx_http_v2_huff_encode(src, len, tmp, lower);
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
24
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
25 if (hlen > 0) {
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
26 *dst = NGX_HTTP_V2_ENCODE_HUFF;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
27 dst = ngx_http_v2_write_int(dst, ngx_http_v2_prefix(7), hlen);
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
28 return ngx_cpymem(dst, tmp, hlen);
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
29 }
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
30
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
31 *dst = NGX_HTTP_V2_ENCODE_RAW;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
32 dst = ngx_http_v2_write_int(dst, ngx_http_v2_prefix(7), len);
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
33
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
34 if (lower) {
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
35 ngx_strlow(dst, src, len);
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
36 return dst + len;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
37 }
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
38
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
39 return ngx_cpymem(dst, src, len);
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
40 }
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
41
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
42
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
43 static u_char *
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
44 ngx_http_v2_write_int(u_char *pos, ngx_uint_t prefix, ngx_uint_t value)
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
45 {
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
46 if (value < prefix) {
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
47 *pos++ |= value;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
48 return pos;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
49 }
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
50
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
51 *pos++ |= prefix;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
52 value -= prefix;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
53
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
54 while (value >= 128) {
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
55 *pos++ = value % 128 + 128;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
56 value /= 128;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
57 }
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
58
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
59 *pos++ = (u_char) value;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
60
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
61 return pos;
87e9e4aabf1b HTTP/2: externalized various constants and interfaces.
Maxim Dounin <mdounin@mdounin.ru>
parents:
diff changeset
62 }