# HG changeset patch # User Igor Sysoev # Date 1193415437 0 # Node ID e27930ae2b8fed1551da7f2d85a77aa36c6aaf4e # Parent 36458723242967c8f65c728a9d037e2d47d2d887 divide special response handling into several functions fix "?" escaping introduced in r1467 diff --git a/src/http/ngx_http_special_response.c b/src/http/ngx_http_special_response.c --- a/src/http/ngx_http_special_response.c +++ b/src/http/ngx_http_special_response.c @@ -10,14 +10,21 @@ #include -static u_char error_full_tail[] = +static ngx_int_t ngx_http_send_error_page(ngx_http_request_t *r, + ngx_http_err_page_t *err_page); +static ngx_int_t ngx_http_send_special_response(ngx_http_request_t *r, + ngx_http_core_loc_conf_t *clcf, ngx_uint_t err); +static ngx_int_t ngx_http_send_refresh(ngx_http_request_t *r); + + +static u_char ngx_http_error_full_tail[] = "
" NGINX_VER "
" CRLF "" CRLF "" CRLF ; -static u_char error_tail[] = +static u_char ngx_http_error_tail[] = "
nginx
" CRLF "" CRLF "" CRLF @@ -42,7 +49,7 @@ static u_char ngx_http_msie_refresh_tail "\">" CRLF; -static char error_301_page[] = +static char ngx_http_error_301_page[] = "" CRLF "301 Moved Permanently" CRLF "" CRLF @@ -50,7 +57,7 @@ static char error_301_page[] = ; -static char error_302_page[] = +static char ngx_http_error_302_page[] = "" CRLF "302 Found" CRLF "" CRLF @@ -58,7 +65,7 @@ static char error_302_page[] = ; -static char error_400_page[] = +static char ngx_http_error_400_page[] = "" CRLF "400 Bad Request" CRLF "" CRLF @@ -66,7 +73,7 @@ static char error_400_page[] = ; -static char error_401_page[] = +static char ngx_http_error_401_page[] = "" CRLF "401 Authorization Required" CRLF "" CRLF @@ -74,7 +81,7 @@ static char error_401_page[] = ; -static char error_402_page[] = +static char ngx_http_error_402_page[] = "" CRLF "402 Payment Required" CRLF "" CRLF @@ -82,7 +89,7 @@ static char error_402_page[] = ; -static char error_403_page[] = +static char ngx_http_error_403_page[] = "" CRLF "403 Forbidden" CRLF "" CRLF @@ -90,7 +97,7 @@ static char error_403_page[] = ; -static char error_404_page[] = +static char ngx_http_error_404_page[] = "" CRLF "404 Not Found" CRLF "" CRLF @@ -98,7 +105,7 @@ static char error_404_page[] = ; -static char error_405_page[] = +static char ngx_http_error_405_page[] = "" CRLF "405 Not Allowed" CRLF "" CRLF @@ -106,7 +113,7 @@ static char error_405_page[] = ; -static char error_406_page[] = +static char ngx_http_error_406_page[] = "" CRLF "406 Not Acceptable" CRLF "" CRLF @@ -114,7 +121,7 @@ static char error_406_page[] = ; -static char error_408_page[] = +static char ngx_http_error_408_page[] = "" CRLF "408 Request Time-out" CRLF "" CRLF @@ -122,7 +129,7 @@ static char error_408_page[] = ; -static char error_409_page[] = +static char ngx_http_error_409_page[] = "" CRLF "409 Conflict" CRLF "" CRLF @@ -130,7 +137,7 @@ static char error_409_page[] = ; -static char error_410_page[] = +static char ngx_http_error_410_page[] = "" CRLF "410 Gone" CRLF "" CRLF @@ -138,7 +145,7 @@ static char error_410_page[] = ; -static char error_411_page[] = +static char ngx_http_error_411_page[] = "" CRLF "411 Length Required" CRLF "" CRLF @@ -146,7 +153,7 @@ static char error_411_page[] = ; -static char error_412_page[] = +static char ngx_http_error_412_page[] = "" CRLF "412 Precondition Failed" CRLF "" CRLF @@ -154,7 +161,7 @@ static char error_412_page[] = ; -static char error_413_page[] = +static char ngx_http_error_413_page[] = "" CRLF "413 Request Entity Too Large" CRLF "" CRLF @@ -162,7 +169,7 @@ static char error_413_page[] = ; -static char error_414_page[] = +static char ngx_http_error_414_page[] = "" CRLF "414 Request-URI Too Large" CRLF "" CRLF @@ -170,7 +177,7 @@ static char error_414_page[] = ; -static char error_415_page[] = +static char ngx_http_error_415_page[] = "" CRLF "415 Unsupported Media Type" CRLF "" CRLF @@ -178,7 +185,7 @@ static char error_415_page[] = ; -static char error_416_page[] = +static char ngx_http_error_416_page[] = "" CRLF "416 Requested Range Not Satisfiable" CRLF "" CRLF @@ -186,7 +193,7 @@ static char error_416_page[] = ; -static char error_495_page[] = +static char ngx_http_error_495_page[] = "" CRLF "400 The SSL certificate error" CRLF @@ -196,7 +203,7 @@ CRLF ; -static char error_496_page[] = +static char ngx_http_error_496_page[] = "" CRLF "400 No required SSL certificate was sent" CRLF @@ -206,7 +213,7 @@ CRLF ; -static char error_497_page[] = +static char ngx_http_error_497_page[] = "" CRLF "400 The plain HTTP request was sent to HTTPS port" CRLF @@ -216,7 +223,7 @@ CRLF ; -static char error_500_page[] = +static char ngx_http_error_500_page[] = "" CRLF "500 Internal Server Error" CRLF "" CRLF @@ -224,7 +231,7 @@ static char error_500_page[] = ; -static char error_501_page[] = +static char ngx_http_error_501_page[] = "" CRLF "501 Method Not Implemented" CRLF "" CRLF @@ -232,7 +239,7 @@ static char error_501_page[] = ; -static char error_502_page[] = +static char ngx_http_error_502_page[] = "" CRLF "502 Bad Gateway" CRLF "" CRLF @@ -240,7 +247,7 @@ static char error_502_page[] = ; -static char error_503_page[] = +static char ngx_http_error_503_page[] = "" CRLF "503 Service Temporarily Unavailable" CRLF "" CRLF @@ -248,7 +255,7 @@ static char error_503_page[] = ; -static char error_504_page[] = +static char ngx_http_error_504_page[] = "" CRLF "504 Gateway Time-out" CRLF "" CRLF @@ -256,7 +263,7 @@ static char error_504_page[] = ; -static char error_507_page[] = +static char ngx_http_error_507_page[] = "" CRLF "507 Insufficient Storage" CRLF "" CRLF @@ -264,53 +271,53 @@ static char error_507_page[] = ; -static ngx_str_t error_pages[] = { +static ngx_str_t ngx_http_error_pages[] = { - ngx_null_string, /* 201, 204 */ + ngx_null_string, /* 201, 204 */ #define NGX_HTTP_LEVEL_200 1 - /* ngx_null_string, */ /* 300 */ - ngx_string(error_301_page), - ngx_string(error_302_page), - ngx_null_string, /* 303 */ + /* ngx_null_string, */ /* 300 */ + ngx_string(ngx_http_error_301_page), + ngx_string(ngx_http_error_302_page), + ngx_null_string, /* 303 */ #define NGX_HTTP_LEVEL_300 3 - ngx_string(error_400_page), - ngx_string(error_401_page), - ngx_string(error_402_page), - ngx_string(error_403_page), - ngx_string(error_404_page), - ngx_string(error_405_page), - ngx_string(error_406_page), - ngx_null_string, /* 407 */ - ngx_string(error_408_page), - ngx_string(error_409_page), - ngx_string(error_410_page), - ngx_string(error_411_page), - ngx_string(error_412_page), - ngx_string(error_413_page), - ngx_string(error_414_page), - ngx_string(error_415_page), - ngx_string(error_416_page), + ngx_string(ngx_http_error_400_page), + ngx_string(ngx_http_error_401_page), + ngx_string(ngx_http_error_402_page), + ngx_string(ngx_http_error_403_page), + ngx_string(ngx_http_error_404_page), + ngx_string(ngx_http_error_405_page), + ngx_string(ngx_http_error_406_page), + ngx_null_string, /* 407 */ + ngx_string(ngx_http_error_408_page), + ngx_string(ngx_http_error_409_page), + ngx_string(ngx_http_error_410_page), + ngx_string(ngx_http_error_411_page), + ngx_string(ngx_http_error_412_page), + ngx_string(ngx_http_error_413_page), + ngx_string(ngx_http_error_414_page), + ngx_string(ngx_http_error_415_page), + ngx_string(ngx_http_error_416_page), #define NGX_HTTP_LEVEL_400 17 - ngx_string(error_495_page), /* 495, https certificate error */ - ngx_string(error_496_page), /* 496, https no certificate */ - ngx_string(error_497_page), /* 497, http to https */ - ngx_string(error_404_page), /* 498, invalid host name */ - ngx_null_string, /* 499, client had closed connection */ + ngx_string(ngx_http_error_495_page), /* 495, https certificate error */ + ngx_string(ngx_http_error_496_page), /* 496, https no certificate */ + ngx_string(ngx_http_error_497_page), /* 497, http to https */ + ngx_string(ngx_http_error_404_page), /* 498, invalid host name */ + ngx_null_string, /* 499, client has closed connection */ - ngx_string(error_500_page), - ngx_string(error_501_page), - ngx_string(error_502_page), - ngx_string(error_503_page), - ngx_string(error_504_page), - ngx_null_string, /* 505 */ - ngx_null_string, /* 506 */ - ngx_string(error_507_page) + ngx_string(ngx_http_error_500_page), + ngx_string(ngx_http_error_501_page), + ngx_string(ngx_http_error_502_page), + ngx_string(ngx_http_error_503_page), + ngx_string(ngx_http_error_504_page), + ngx_null_string, /* 505 */ + ngx_null_string, /* 506 */ + ngx_string(ngx_http_error_507_page) }; @@ -320,14 +327,8 @@ static ngx_str_t ngx_http_get_name = { ngx_int_t ngx_http_special_response_handler(ngx_http_request_t *r, ngx_int_t error) { - u_char *p; - size_t msie_refresh; - uintptr_t escape; ngx_int_t rc; - ngx_buf_t *b; - ngx_str_t *uri, *location; - ngx_uint_t i, n, err, msie_padding; - ngx_chain_t *out, *cl; + ngx_uint_t i, err; ngx_http_err_page_t *err_page; ngx_http_core_loc_conf_t *clcf; @@ -378,68 +379,20 @@ ngx_http_special_response_handler(ngx_ht err_page = clcf->error_pages->elts; for (i = 0; i < clcf->error_pages->nelts; i++) { - if (err_page[i].status == error) { - r->err_status = err_page[i].overwrite; - - r->method = NGX_HTTP_GET; - r->method_name = ngx_http_get_name; - - uri = &err_page[i].uri; - - if (err_page[i].uri_lengths) { - if (ngx_http_script_run(r, uri, - err_page[i].uri_lengths->elts, 0, - err_page[i].uri_values->elts) - == NULL) - { - return NGX_ERROR; - } - - if (r->zero_in_uri) { - for (n = 0; n < uri->len; n++) { - if (uri->data[n] == '\0') { - goto zero; - } - } - - r->zero_in_uri = 0; - } - - } else { - r->zero_in_uri = 0; - } - - zero: - - if (uri->data[0] == '/') { - return ngx_http_internal_redirect(r, uri, NULL); - } - - if (uri->data[0] == '@') { - return ngx_http_named_location(r, uri); - } - - r->headers_out.location = - ngx_list_push(&r->headers_out.headers); - - if (r->headers_out.location) { - error = NGX_HTTP_MOVED_TEMPORARILY; - - r->err_status = NGX_HTTP_MOVED_TEMPORARILY; - - r->headers_out.location->hash = 1; - r->headers_out.location->key.len = sizeof("Location") - 1; - r->headers_out.location->key.data = (u_char *) "Location"; - r->headers_out.location->value = *uri; - - } else { - return NGX_ERROR; - } + return ngx_http_send_error_page(r, &err_page[i]); } } } + if (clcf->msie_refresh + && r->headers_in.msie + && (error == NGX_HTTP_MOVED_PERMANENTLY + || error == NGX_HTTP_MOVED_TEMPORARILY)) + { + return ngx_http_send_refresh(r); + } + if (error == NGX_HTTP_CREATED) { /* 201 */ err = 0; @@ -468,30 +421,150 @@ ngx_http_special_response_handler(ngx_ht case NGX_HTTPS_CERT_ERROR: case NGX_HTTPS_NO_CERT: r->err_status = NGX_HTTP_BAD_REQUEST; - error = NGX_HTTP_BAD_REQUEST; break; } } + return ngx_http_send_special_response(r, clcf, err); +} + + +static ngx_int_t +ngx_http_send_error_page(ngx_http_request_t *r, ngx_http_err_page_t *err_page) +{ + u_char ch, *p, *last; + ngx_str_t *uri, *args, u, a; + ngx_table_elt_t *location; + ngx_http_core_loc_conf_t *clcf; + + r->err_status = err_page->overwrite; + + r->method = NGX_HTTP_GET; + r->method_name = ngx_http_get_name; + + r->zero_in_uri = 0; + + args = NULL; + + if (err_page->uri_lengths) { + if (ngx_http_script_run(r, &u, err_page->uri_lengths->elts, 0, + err_page->uri_values->elts) + == NULL) + { + return NGX_ERROR; + } + + p = u.data; + uri = &u; + + if (*p == '/') { + + last = p + uri->len; + + while (p < last) { + + ch = *p++; + + if (ch == '?') { + a.len = last - p; + a.data = p; + args = &a; + + u.len = p - 1 - u.data; + + while (p < last) { + if (*p++ == '\0') { + r->zero_in_uri = 1; + break; + } + } + + break; + } + + if (ch == '\0') { + r->zero_in_uri = 1; + continue; + } + } + } + + } else { + uri = &err_page->uri; + } + + if (uri->data[0] == '/') { + return ngx_http_internal_redirect(r, uri, args); + } + + if (uri->data[0] == '@') { + return ngx_http_named_location(r, uri); + } + + location = ngx_list_push(&r->headers_out.headers); + + if (location == NULL) { + return NGX_ERROR; + } + + r->err_status = NGX_HTTP_MOVED_TEMPORARILY; + + location->hash = 1; + location->key.len = sizeof("Location") - 1; + location->key.data = (u_char *) "Location"; + location->value = *uri; + + r->headers_out.location = location; + + clcf = ngx_http_get_module_loc_conf(r, ngx_http_core_module); + + if (clcf->msie_refresh && r->headers_in.msie) { + return ngx_http_send_refresh(r); + } + + return ngx_http_send_special_response(r, clcf, NGX_HTTP_MOVED_TEMPORARILY + - NGX_HTTP_MOVED_PERMANENTLY + + NGX_HTTP_LEVEL_200); +} + + +static ngx_int_t +ngx_http_send_special_response(ngx_http_request_t *r, + ngx_http_core_loc_conf_t *clcf, ngx_uint_t err) +{ + u_char *tail; + size_t len; + ngx_int_t rc; + ngx_buf_t *b; + ngx_uint_t msie_padding; + ngx_chain_t out[3]; + + if (clcf->server_tokens) { + len = sizeof(ngx_http_error_full_tail) - 1; + tail = ngx_http_error_full_tail; + + } else { + len = sizeof(ngx_http_error_tail) - 1; + tail = ngx_http_error_tail; + } + msie_padding = 0; if (!r->zero_body) { - if (error_pages[err].len) { - r->headers_out.content_length_n = error_pages[err].len - + (clcf->server_tokens ? sizeof(error_full_tail) - 1: - sizeof(error_tail) - 1); - + if (ngx_http_error_pages[err].len) { + r->headers_out.content_length_n = ngx_http_error_pages[err].len + + len; if (clcf->msie_padding && r->headers_in.msie && r->http_version >= NGX_HTTP_VERSION_10 - && error >= NGX_HTTP_BAD_REQUEST - && error != NGX_HTTP_REQUEST_URI_TOO_LARGE) + && err >= NGX_HTTP_LEVEL_300) { r->headers_out.content_length_n += sizeof(ngx_http_msie_stub) - 1; msie_padding = 1; } + r->headers_out.content_type_len = sizeof("text/html") - 1; r->headers_out.content_type.len = sizeof("text/html") - 1; r->headers_out.content_type.data = (u_char *) "text/html"; @@ -509,31 +582,102 @@ ngx_http_special_response_handler(ngx_ht r->headers_out.content_length = NULL; } - if (clcf->msie_refresh - && r->headers_in.msie - && (error == NGX_HTTP_MOVED_PERMANENTLY - || error == NGX_HTTP_MOVED_TEMPORARILY)) - { + ngx_http_clear_accept_ranges(r); + ngx_http_clear_last_modified(r); + + rc = ngx_http_send_header(r); + + if (rc == NGX_ERROR || r->header_only) { + return rc; + } + + if (ngx_http_error_pages[err].len == 0) { + return NGX_OK; + } + + b = ngx_calloc_buf(r->pool); + if (b == NULL) { + return NGX_ERROR; + } + + b->memory = 1; + b->pos = ngx_http_error_pages[err].data; + b->last = ngx_http_error_pages[err].data + ngx_http_error_pages[err].len; - location = &r->headers_out.location->value; + out[0].buf = b; + out[0].next = &out[1]; + + b = ngx_calloc_buf(r->pool); + if (b == NULL) { + return NGX_ERROR; + } + + b->memory = 1; + + b->pos = tail; + b->last = tail + len; - escape = 2 * ngx_escape_uri(NULL, location->data, location->len, - NGX_ESCAPE_REFRESH); + out[1].buf = b; + out[1].next = NULL;; + + if (msie_padding) { + b = ngx_calloc_buf(r->pool); + if (b == NULL) { + return NGX_ERROR; + } + + b->memory = 1; + b->pos = ngx_http_msie_stub; + b->last = ngx_http_msie_stub + sizeof(ngx_http_msie_stub) - 1; - msie_refresh = sizeof(ngx_http_msie_refresh_head) - 1 - + escape + location->len - + sizeof(ngx_http_msie_refresh_tail) - 1; + out[1].next = &out[2]; + out[2].buf = b; + out[2].next = NULL;; + } + + if (r == r->main) { + b->last_buf = 1; + } + + b->last_in_chain = 1; + + return ngx_http_output_filter(r, &out[0]); +} + - r->err_status = NGX_HTTP_OK; - r->headers_out.content_type_len = sizeof("text/html") - 1; - r->headers_out.content_length_n = msie_refresh; - r->headers_out.location->hash = 0; - r->headers_out.location = NULL; +static ngx_int_t +ngx_http_send_refresh(ngx_http_request_t *r) +{ + u_char *p, *location; + size_t len, size; + uintptr_t escape; + ngx_int_t rc; + ngx_buf_t *b; + ngx_chain_t out; + + len = r->headers_out.location->value.len; + location = r->headers_out.location->value.data; + + escape = 2 * ngx_escape_uri(NULL, location, len, NGX_ESCAPE_REFRESH); - } else { - location = NULL; - escape = 0; - msie_refresh = 0; + size = sizeof(ngx_http_msie_refresh_head) - 1 + + escape + len + + sizeof(ngx_http_msie_refresh_tail) - 1; + + r->err_status = NGX_HTTP_OK; + + r->headers_out.content_type_len = sizeof("text/html") - 1; + r->headers_out.content_type.len = sizeof("text/html") - 1; + r->headers_out.content_type.data = (u_char *) "text/html"; + + r->headers_out.location->hash = 0; + r->headers_out.location = NULL; + + r->headers_out.content_length_n = size; + + if (r->headers_out.content_length) { + r->headers_out.content_length->hash = 0; + r->headers_out.content_length = NULL; } ngx_http_clear_accept_ranges(r); @@ -545,109 +689,29 @@ ngx_http_special_response_handler(ngx_ht return rc; } - - if (msie_refresh == 0) { - - if (error_pages[err].len == 0) { - return NGX_OK; - } - - b = ngx_calloc_buf(r->pool); - if (b == NULL) { - return NGX_ERROR; - } - - b->memory = 1; - b->pos = error_pages[err].data; - b->last = error_pages[err].data + error_pages[err].len; - - cl = ngx_alloc_chain_link(r->pool); - if (cl == NULL) { - return NGX_ERROR; - } - - cl->buf = b; - out = cl; - - - b = ngx_calloc_buf(r->pool); - if (b == NULL) { - return NGX_ERROR; - } - - b->memory = 1; + b = ngx_create_temp_buf(r->pool, size); + if (b == NULL) { + return NGX_ERROR; + } - if (clcf->server_tokens) { - b->pos = error_full_tail; - b->last = error_full_tail + sizeof(error_full_tail) - 1; - } else { - b->pos = error_tail; - b->last = error_tail + sizeof(error_tail) - 1; - } - - cl->next = ngx_alloc_chain_link(r->pool); - if (cl->next == NULL) { - return NGX_ERROR; - } - - cl = cl->next; - cl->buf = b; + p = ngx_cpymem(b->pos, ngx_http_msie_refresh_head, + sizeof(ngx_http_msie_refresh_head) - 1); - if (msie_padding) { - b = ngx_calloc_buf(r->pool); - if (b == NULL) { - return NGX_ERROR; - } - - b->memory = 1; - b->pos = ngx_http_msie_stub; - b->last = ngx_http_msie_stub + sizeof(ngx_http_msie_stub) - 1; - - cl->next = ngx_alloc_chain_link(r->pool); - if (cl->next == NULL) { - return NGX_ERROR; - } - - cl = cl->next; - cl->buf = b; - } + if (escape == 0) { + p = ngx_cpymem(p, location, len); } else { - b = ngx_create_temp_buf(r->pool, msie_refresh); - if (b == NULL) { - return NGX_ERROR; - } - - p = ngx_cpymem(b->pos, ngx_http_msie_refresh_head, - sizeof(ngx_http_msie_refresh_head) - 1); - - if (escape == 0) { - p = ngx_cpymem(p, location->data, location->len); - - } else { - p = (u_char *) ngx_escape_uri(p, location->data, location->len, - NGX_ESCAPE_REFRESH); - } - - b->last = ngx_cpymem(p, ngx_http_msie_refresh_tail, - sizeof(ngx_http_msie_refresh_tail) - 1); - - cl = ngx_alloc_chain_link(r->pool); - if (cl == NULL) { - return NGX_ERROR; - } - - cl->buf = b; - out = cl; + p = (u_char *) ngx_escape_uri(p, location, len, NGX_ESCAPE_REFRESH); } - if (r == r->main) { - b->last_buf = 1; - } + b->last = ngx_cpymem(p, ngx_http_msie_refresh_tail, + sizeof(ngx_http_msie_refresh_tail) - 1); + b->last_buf = 1; b->last_in_chain = 1; - cl->next = NULL; + out.buf = b; + out.next = NULL; - return ngx_http_output_filter(r, out); + return ngx_http_output_filter(r, &out); }