Mercurial > hg > nginx
annotate conf/fastcgi_params @ 7667:1ece2ac2555a
OCSP: fixed use-after-free on error.
When validating second and further certificates, ssl callback could be called
twice to report the error. After the first call client connection is
terminated and its memory is released. Prior to the second call and in it
released connection memory is accessed.
Errors triggering this behavior:
- failure to create the request
- failure to start resolving OCSP responder name
- failure to start connecting to the OCSP responder
The fix is to rearrange the code to eliminate the second call.
author | Roman Arutyunyan <arut@nginx.com> |
---|---|
date | Mon, 15 Jun 2020 20:17:16 +0300 |
parents | 62869a9b2e7d |
children |
rev | line source |
---|---|
537 | 1 |
2 fastcgi_param QUERY_STRING $query_string; | |
3 fastcgi_param REQUEST_METHOD $request_method; | |
4 fastcgi_param CONTENT_TYPE $content_type; | |
5 fastcgi_param CONTENT_LENGTH $content_length; | |
6 | |
7 fastcgi_param SCRIPT_NAME $fastcgi_script_name; | |
8 fastcgi_param REQUEST_URI $request_uri; | |
9 fastcgi_param DOCUMENT_URI $document_uri; | |
10 fastcgi_param DOCUMENT_ROOT $document_root; | |
11 fastcgi_param SERVER_PROTOCOL $server_protocol; | |
6168
62869a9b2e7d
Added the REQUEST_SCHEME parameter.
Maxim Dounin <mdounin@mdounin.ru>
parents:
4333
diff
changeset
|
12 fastcgi_param REQUEST_SCHEME $scheme; |
4333
352a7b025f2e
Added HTTPS param with Apache-like behaviour to fastcgi/scgi/uwsgi_params (fixes #38).
Valentin Bartenev <vbart@nginx.com>
parents:
1330
diff
changeset
|
13 fastcgi_param HTTPS $https if_not_empty; |
537 | 14 |
15 fastcgi_param GATEWAY_INTERFACE CGI/1.1; | |
1330 | 16 fastcgi_param SERVER_SOFTWARE nginx/$nginx_version; |
537 | 17 |
18 fastcgi_param REMOTE_ADDR $remote_addr; | |
19 fastcgi_param REMOTE_PORT $remote_port; | |
20 fastcgi_param SERVER_ADDR $server_addr; | |
21 fastcgi_param SERVER_PORT $server_port; | |
22 fastcgi_param SERVER_NAME $server_name; | |
23 | |
24 # PHP only, required if PHP was built with --enable-force-cgi-redirect | |
25 fastcgi_param REDIRECT_STATUS 200; |