mirror of
https://git.gnunet.org/libmicrohttpd.git
synced 2026-09-25 04:09:31 +03:00
libmicrohttpd] bug in MHD_create_response_from_fd_at_offset()
From: Eivind Sarto <ivan@espial.com> To: "libmicrohttpd@gnu.org" <libmicrohttpd@gnu.org> Date: Today 09:32:21 pm Spam Status: Spamassassin 0% probability of being spam. Full report: Probability=No, score=-2.6 required=7.0 tests=BAYES_00 autolearn=ham version=3.2.5-tuminfo_1 There appears to be a bug in MHD_create_response_from_fd_at_offset(). Calling this function with anything other than a zero offset will cause wrong data or no data (sendfile fails if length < 0). If you use this call with any application that uses ranges, this bug will trigger. In src/daemon/daemon.c: send_param_adapter() ..... /* can use sendfile */ offset = (off_t) connection->response_write_position + connection->response->fd_off; #ifdef BUGFIX /* correct */ left = connection->response->total_size - connection->response_write_position; #else left = connection->response->total_size - offset; #endif if (left > SSIZE_MAX) left = SSIZE_MAX; /* cap at return value limit */ ret = sendfile (connection->socket_fd, fd, &offset, left); -eivind
This commit is contained in:
@@ -29,6 +29,7 @@ Piotr Grzybowski <narsil.pl@gmail.com>
|
||||
Gerrit Telkamp <g.telkamp@domologic.de>
|
||||
Erik Slagter <erik@slagter.name>
|
||||
Andreas Wehrmann <a.wehrmann@centersystems.com>
|
||||
Eivind Sarto <ivan@espial.com>
|
||||
|
||||
Documentation contributions also came from:
|
||||
Marco Maggi <marco.maggi-ipsu@poste.it>
|
||||
|
||||
@@ -1,3 +1,6 @@
|
||||
Fri Mar 11 22:25:29 CET 2011
|
||||
Fixing bug in MHD_create_response_from_fd_at_offset with non-zero offsets. -ES
|
||||
|
||||
Sat Mar 5 22:00:36 CET 2011
|
||||
Do not use POLLRDHUP, which causes build errors on OS X / OpenSolaris
|
||||
(#1667). -CG
|
||||
|
||||
+1
-1
@@ -746,7 +746,7 @@ send_param_adapter (struct MHD_Connection *connection,
|
||||
{
|
||||
/* can use sendfile */
|
||||
offset = (off_t) connection->response_write_position + connection->response->fd_off;
|
||||
left = connection->response->total_size - offset;
|
||||
left = connection->response->total_size - connection->response_write_position;
|
||||
if (left > SSIZE_MAX)
|
||||
left = SSIZE_MAX; /* cap at return value limit */
|
||||
ret = sendfile (connection->socket_fd,
|
||||
|
||||
Reference in New Issue
Block a user