mirror of
https://git.gnunet.org/libmicrohttpd.git
synced 2026-10-04 04:03:18 +03:00
This patch isn't purely about the subject matter, but rather have some tiny
small stuff that concerns other things so keep an eye for those. Also have to
say that documentation is included, including updated example and update unit test.
As for the performance part to it, its so complex to fully test it performance
wise, but it seems to work just fine, although keep an eye on how it does search
for the nonce to see if it is an attack or not, or if it is a whole new nonce
that needs to be added to the array, also have an eye for the rw-locks, I think
they are very useful and add a lot to the performance.
Thanks,
Amr Ali
End of signed message
latest_nc_mhd.patch
Note that the actual changes do not include the rw-locks (not as portable, no real
benefit in this context anyway) and I also made some other minor changes. Original
patch follows.
diff --git a/doc/microhttpd.texi b/doc/microhttpd.texi
index a86a59a..cc7f7a8 100644
--- a/doc/microhttpd.texi
+++ b/doc/microhttpd.texi
@@ -458,12 +458,31 @@ specified, ``NORMAL'' is used.
@cindex random
Digest Authentication nonce's seed.
This option must be followed by an "const char *" argument
-specifying a NULL terminated array of randomly generated values
-to be used in generating the server nonce when using digest authentication.
-It is a MUST to supply these values before utilizing any of MHD
-digest authentication functions, as otherwise, it will read from
-an arbitrary address in memory which results in an undefined behavior.
-
+an array of randomly generated values to be used in generating
+the server nonce when using digest authentication.
+It is a MUST to supply these values if MHD is compiled with
+Digest Authentication enabled (default).
+
+@item MHD_OPTION_DIGEST_AUTH_RAND_SIZE
+@cindex digest auth
+@cindex random
+Digest Authentication random seed size.
+This option must be followed by a "unsigned int" argument
+that have the size (number of elements) of the random seed
+array. This helps so that the seed might have zero bytes
+so it won't have a problem with string functions that
+depend on null terminated character arrays.
+
+@item MHD_OPTION_NONCE_NC_SIZE
+@cindex digest auth
+@cindex replay attack
+Size of an array of nonce and nonce counter map.
+This option must be followed by an "unsigned int" argument
+that have the size (number of elements) of a map of
+a nonce and a nonce-counter. This option MUST be
+specified if MHD is compiled with
+Digest Authentication enabled (default).
+
@item MHD_OPTION_LISTEN_SOCKET
@cindex systemd
Listen socket to use. Pass a listen socket for MHD to use
diff --git a/src/daemon/daemon.c b/src/daemon/daemon.c
index f68b9fb..8f0583c 100644
--- a/src/daemon/daemon.c
+++ b/src/daemon/daemon.c
@@ -1376,6 +1376,12 @@ parse_options_va (struct MHD_Daemon *daemon,
case MHD_OPTION_DIGEST_AUTH_RANDOM:
daemon->digest_auth_random = va_arg (ap, const char *);
break;
+ case MHD_OPTION_DIGEST_AUTH_RAND_SIZE:
+ daemon->digest_auth_rand_size = va_arg (ap, unsigned int);
+ break;
+ case MHD_OPTION_NONCE_NC_SIZE:
+ daemon->nonce_nc_size = va_arg (ap, unsigned int);
+ break;
#endif
case MHD_OPTION_LISTEN_SOCKET:
daemon->socket_fd = va_arg (ap, int);
@@ -1407,6 +1413,8 @@ parse_options_va (struct MHD_Daemon *daemon,
return MHD_NO;
break;
/* all options taking 'unsigned int' */
+ case MHD_OPTION_NONCE_NC_SIZE:
+ case MHD_OPTION_DIGEST_AUTH_RAND_SIZE:
case MHD_OPTION_CONNECTION_LIMIT:
case MHD_OPTION_CONNECTION_TIMEOUT:
case MHD_OPTION_PER_IP_CONNECTION_LIMIT:
@@ -1578,6 +1586,63 @@ MHD_start_daemon_va (unsigned int options,
return NULL;
}
+#ifdef DAUTH_SUPPORT
+ if (retVal->nonce_nc_size == 0)
+ {
+#if HAVE_MESSAGES
+ fprintf (stderr,
+ "MHD nonce-nc map size cannot be 0\n");
+#endif
+ free (retVal);
+ return NULL;
+ }
+ else
+ {
+ retVal->nnc = calloc(retVal->nonce_nc_size, sizeof(struct MHD_NonceNc));
+
+ if (!retVal->nnc)
+ {
+#if HAVE_MESSAGES
+ fprintf (stderr,
+ "An error has occured while allocating nonce-nc map\n");
+#endif
+ free (retVal);
+ return NULL;
+ }
+ }
+
+ if (retVal->digest_auth_rand_size == 0)
+ {
+#if HAVE_MESSAGES
+ fprintf(stderr,
+ "MHD Digest Auth random seed array size must be > 0\n");
+#endif
+ free (retVal);
+ return NULL;
+ }
+
+ if (retVal->digest_auth_random == NULL)
+ {
+#if HAVE_MESSAGES
+ fprintf (stderr,
+ "MHD requires `digest_auth_random' to point to a char array"
+ " of random values\n");
+#endif
+ free (retVal);
+ return NULL;
+ }
+
+ if (pthread_rwlock_init(&retVal->nnc_lock, NULL))
+ {
+#if HAVE_MESSAGES
+ fprintf (stderr,
+ "Failed to initialize nonce-nc lock\n");
+#endif
+ free (retVal);
+ return NULL;
+ }
+#endif
+
/* poll support currently only works with MHD_USE_THREAD_PER_CONNECTION */
if ( (0 != (options & MHD_USE_POLL)) &&
(0 == (options & MHD_USE_THREAD_PER_CONNECTION)) ) {
@@ -2012,6 +2077,11 @@ MHD_stop_daemon (struct MHD_Daemon *daemon)
}
}
#endif
+
+#ifdef DAUTH_SUPPORT
+ free (daemon->nnc);
+ pthread_rwlock_destroy (&daemon->nnc_lock);
+#endif
pthread_mutex_destroy (&daemon->per_ip_connection_mutex);
free (daemon);
}
diff --git a/src/daemon/digestauth.c b/src/daemon/digestauth.c
index 591538e..ad63b79 100644
--- a/src/daemon/digestauth.c
+++ b/src/daemon/digestauth.c
@@ -23,6 +23,7 @@
* @author Amr Ali
*/
+#include "platform.h"
#include "internal.h"
#include "md5.h"
@@ -82,12 +83,12 @@ cvthex(const unsigned char *bin,
* calculate H(A1) as per RFC2617 spec and store the
* result in 'sessionkey'.
*
- * @param alg FIXME: document
- * @param username FIXME: document
- * @param realm FIXME: document
- * @param password FIXME: document
- * @param nonce FIXME: document
- * @param cnonce FIXME: document
+ * @param alg The hash algorithm used, can be "md5" or "md5-sess"
+ * @param username A `char *' pointer to the username value
+ * @param realm A `char *' pointer to the realm value
+ * @param password A `char *' pointer to the password value
+ * @param nonce A `char *' pointer to the nonce value
+ * @param cnonce A `char *' pointer to the cnonce value
* @param sessionkey pointer to buffer of HASH_MD5_HEX_LEN+1 bytes
*/
static void
@@ -275,6 +276,69 @@ lookup_sub_value(char *dest,
return 0;
}
+/**
+ * Check nonce-nc map array with either new nonce counter
+ * or a whole new nonce.
+ *
+ * @param connection The MHD connection structure
+ * @param nonce A pointer that referenced a zero-terminated array of nonce
+ * @param nc The nonce counter
+ * @return 1 if successful, 0 if invalid
+ */
+static int
+check_nonce_nc(
+ struct MHD_Connection *connection,
+ const char *nonce,
+ unsigned int nc)
+{
+ static unsigned int pos = 0;
+ int i;
+
+ /*
+ * Look for the nonce, if it does exist and its corresponding
+ * nonce counter is less than the current nonce counter by 1,
+ * then only increase the nonce counter by one.
+ */
+
+ pthread_rwlock_rdlock(&connection->daemon->nnc_lock);
+
+ for (i = 0; i < connection->daemon->nonce_nc_size; ++i) {
+ if (0 == strcmp(connection->daemon->nnc[i].nonce, nonce)) {
+ if (nc - 1 == connection->daemon->nnc[i].nc) {
+ pthread_rwlock_unlock(&connection->daemon->nnc_lock);
+ pthread_rwlock_wrlock(&connection->daemon->nnc_lock);
+ ++connection->daemon->nnc[i].nc;
+ pthread_rwlock_unlock(&connection->daemon->nnc_lock);
+ return 1;
+ } else {
+ /*
+ * Nonce is found but its nonce counter is invalid.
+ */
+ pthread_rwlock_unlock(&connection->daemon->nnc_lock);
+ pthread_rwlock_wrlock(&connection->daemon->nnc_lock);
+ connection->daemon->nnc[i].nc = -1;
+ pthread_rwlock_unlock(&connection->daemon->nnc_lock);
+ return 0;
+ }
+ }
+ }
+
+ pthread_rwlock_unlock(&connection->daemon->nnc_lock);
+
+ /*
+ * nonce is not found and will be added to the array.
+ */
+
+ pthread_rwlock_wrlock(&connection->daemon->nnc_lock);
+ strncpy(connection->daemon->nnc[pos].nonce, nonce, strlen(nonce));
+ connection->daemon->nnc[pos].nc = 1;
+
+ pos = pos >= connection->daemon->nonce_nc_size ? 0 : pos + 1;
+
+ pthread_rwlock_unlock(&connection->daemon->nnc_lock);
+
+ return 1;
+}
/**
* Get the username from the authorization header sent by the client
@@ -316,6 +380,7 @@ MHD_digest_auth_get_username(struct MHD_Connection *connection)
* @param nonce_time The amount of time in seconds for a nonce to be invalid
* @param method HTTP method
* @param rnd A pointer to a character array for the random seed
+ * @param rnd_size The size of the random seed array
* @param uri HTTP URI
* @param realm A string of characters that describes the realm of auth.
* @param nonce A pointer to a character array for the nonce to put in
@@ -324,6 +389,7 @@ static void
calculate_nonce (uint32_t nonce_time,
const char *method,
const char *rnd,
+ unsigned int rnd_size,
const char *uri,
const char *realm,
char *nonce)
@@ -342,7 +408,7 @@ calculate_nonce (uint32_t nonce_time,
MD5Update(&md5, ":", 1);
MD5Update(&md5, method, strlen(method));
MD5Update(&md5, ":", 1);
- MD5Update(&md5, rnd, strlen(rnd));
+ MD5Update(&md5, rnd, rnd_size);
MD5Update(&md5, ":", 1);
MD5Update(&md5, uri, strlen(uri));
MD5Update(&md5, ":", 1);
@@ -436,7 +502,7 @@ MHD_digest_auth_check(struct MHD_Connection *connection,
return MHD_NO;
/* 8 = 4 hexadecimal numbers for the timestamp */
- nonce_time = strtoul(nonce + len - 8, 0, 16);
+ nonce_time = strtoul(nonce + len - 8, (char **)NULL, 16);
t = (uint32_t) time(NULL);
/*
* First level vetting for the nonce validity
@@ -449,14 +515,15 @@ MHD_digest_auth_check(struct MHD_Connection *connection,
calculate_nonce (nonce_time,
connection->method,
connection->daemon->digest_auth_random,
+ connection->daemon->digest_auth_rand_size,
uri,
realm,
noncehashexp);
/*
* Second level vetting for the nonce validity
* if the timestamp attached to the nonce is valid
- * and possibility fabricated (in case of an attack)
- * the attacker must also know the password to be
+ * and possibly fabricated (in case of an attack)
+ * the attacker must also know the random seed to be
* able to generate a "sane" nonce, which if he does
* not, the nonce fabrication process going to be
* very hard to achieve.
@@ -471,6 +538,15 @@ MHD_digest_auth_check(struct MHD_Connection *connection,
(0 == lookup_sub_value(nc, sizeof (nc), header, "nc")) ||
(0 == lookup_sub_value(response, sizeof (response), header, "response")) )
return MHD_NO;
+
+ /*
+ * Checking if that combination of nonce and nc is sound
+ * and not a replay attack attempt. Also adds the nonce
+ * to the nonce-nc map if it does not exist there.
+ */
+
+ if (! check_nonce_nc(connection, nonce, strtoul(nc, (char **)NULL, 16)) )
+ return MHD_NO;
digest_calc_ha1("md5",
username,
@@ -519,6 +595,7 @@ MHD_queue_auth_fail_response(struct MHD_Connection *connection,
calculate_nonce ((uint32_t) time(NULL),
connection->method,
connection->daemon->digest_auth_random,
+ connection->daemon->digest_auth_rand_size,
connection->url,
realm,
nonce);
diff --git a/src/daemon/internal.h b/src/daemon/internal.h
index 3887b27..9308355 100644
--- a/src/daemon/internal.h
+++ b/src/daemon/internal.h
@@ -93,6 +93,24 @@ struct MHD_Pollfd {
enum MHD_PollActions events;
};
+#ifdef DAUTH_SUPPORT
+/**
+ * A structure representing the internal holder of the
+ * nonce-nc map.
+ */
+struct MHD_NonceNc {
+ /**
+ * Nonce value: 32(MD5 Hex) + 8(Timestamp Hex) + 1(NULL)
+ */
+ char nonce[41];
+
+ /**
+ * Nonce counter, a value that increases for each subsequent
+ * request for the same nonce.
+ */
+ int nc;
+};
+#endif
#if HAVE_MESSAGES
/**
@@ -866,12 +884,34 @@ struct MHD_Daemon
#endif
#ifdef DAUTH_SUPPORT
+
/**
* Character array of random values.
*/
const char *digest_auth_random;
+ /**
+ * Size of `digest_auth_random.
+ */
+ unsigned int digest_auth_rand_size;
+
+ /**
+ * Size of the nonce-nc array.
+ */
+ unsigned int nonce_nc_size;
+
+ /**
+ * An array that contains the map nonce-nc.
+ */
+ struct MHD_NonceNc *nnc;
+
+ /**
+ * A rw-lock for synchronizing access to `nnc'.
+ */
+ pthread_rwlock_t nnc_lock;
+
#endif
+
/**
* Pointer to master daemon (NULL if this is the master)
*/
diff --git a/src/examples/digest_auth_example.c b/src/examples/digest_auth_example.c
index 51c81b8..9ead210 100644
--- a/src/examples/digest_auth_example.c
+++ b/src/examples/digest_auth_example.c
@@ -90,7 +90,7 @@ int
main (int argc, char *const *argv)
{
int fd;
- char rnd[9];
+ char rnd[8];
size_t len;
size_t off;
struct MHD_Daemon *d;
@@ -123,11 +123,12 @@ main (int argc, char *const *argv)
off += len;
}
(void) close(fd);
- rnd[8] = '\0';
d = MHD_start_daemon (MHD_USE_THREAD_PER_CONNECTION | MHD_USE_DEBUG,
atoi (argv[1]),
NULL, NULL, &ahc_echo, PAGE,
MHD_OPTION_DIGEST_AUTH_RANDOM, rnd,
+ MHD_OPTION_DIGEST_AUTH_RAND_SIZE, sizeof(rnd),
+ MHD_OPTION_NONCE_NC_SIZE, 300,
MHD_OPTION_END);
if (d == NULL)
return 1;
diff --git a/src/include/microhttpd.h b/src/include/microhttpd.h
index a74bf55..45d49f0 100644
--- a/src/include/microhttpd.h
+++ b/src/include/microhttpd.h
@@ -527,8 +527,22 @@ enum MHD_OPTION
* Auth module. This option should be followed by an "const char *"
* argument.
*/
- MHD_OPTION_DIGEST_AUTH_RANDOM = 17
+ MHD_OPTION_DIGEST_AUTH_RANDOM = 17,
+ /**
+ * Size of Digest Auth random seed. This option should be followed
+ * by an "unsigned int" argument. It is needed as the random seed array
+ * may contain values of zero, which would cause problems for
+ * string functions.
+ */
+ MHD_OPTION_DIGEST_AUTH_RAND_SIZE = 18,
+
+ /**
+ * Size of the internal array holding the map of the nonce and
+ * the nonce counter. This option should be followed by a "unsigend int"
+ * argument.
+ */
+ MHD_OPTION_NONCE_NC_SIZE = 19
};
diff --git a/src/testcurl/daemontest_digestauth.c b/src/testcurl/daemontest_digestauth.c
index e05d857..86ea305 100644
--- a/src/testcurl/daemontest_digestauth.c
+++ b/src/testcurl/daemontest_digestauth.c
@@ -129,7 +129,7 @@ testDigestAuth ()
size_t len;
size_t off = 0;
char buf[2048];
- char rnd[9];
+ char rnd[8];
cbc.buf = buf;
cbc.size = 2048;
@@ -156,10 +156,11 @@ testDigestAuth ()
off += len;
}
(void) close(fd);
- rnd[8] = '\0';
d = MHD_start_daemon (MHD_USE_SELECT_INTERNALLY | MHD_USE_DEBUG,
1337, NULL, NULL, &ahc_echo, PAGE,
MHD_OPTION_DIGEST_AUTH_RANDOM, rnd,
+ MHD_OPTION_DIGEST_AUTH_RAND_SIZE, sizeof(rnd),
+ MHD_OPTION_NONCE_NC_SIZE, 300,
MHD_OPTION_END);
if (d == NULL)
return 1;
498 lines
17 KiB
Plaintext
498 lines
17 KiB
Plaintext
Fri Sep 10 14:29:37 CEST 2010
|
|
Adding proper nonce counter checking for digest authentication. -CG/AA
|
|
|
|
Sat Sep 4 21:55:52 CEST 2010
|
|
Digest authentication now seems to be working. -CG/AA
|
|
|
|
Wed Sep 1 13:59:16 CEST 2010
|
|
Added ability to specify external unescape function.
|
|
"microhttpd.h" now includes the right headers for GNU/Linux
|
|
systems unless MHD_PLATFORM_H is defined (in which case it
|
|
is assumed that the right headers were already determined by
|
|
some configure-like process). -CG
|
|
|
|
Tue Aug 31 15:39:25 CEST 2010
|
|
Fixed bug with missing call to response cleanup in case of
|
|
connection handling error (for example, after getting a SIGPIPE). -CG
|
|
|
|
Tue Aug 24 11:39:25 CEST 2010
|
|
Fixed bug in handling EAGAIN from GnuTLS (caused
|
|
needlessly dropped SSL connections). -CG
|
|
|
|
Sun Aug 22 16:49:13 CEST 2010
|
|
Initial draft for digest authentication. -AA
|
|
|
|
Thu Aug 19 14:15:01 CEST 2010
|
|
Changed code to enable error messages and HTTPS by default;
|
|
added option to disable post processor API (use
|
|
breaks binary compatibility, should only be done
|
|
for embedded systems that require minimal footprint). -CG
|
|
|
|
Thu Aug 19 13:26:00 CEST 2010
|
|
Patches for Windows to ease compilation trouble. -GT/CG
|
|
|
|
Sat Aug 14 15:43:30 CEST 2010
|
|
Fixed small, largely hypothetical leaks.
|
|
Reduced calls to strlen for header processing. -CG
|
|
|
|
Fri Aug 6 12:51:59 CEST 2010
|
|
Fixing (small) memory leak on daemon-shutdown with
|
|
SSL enabled. -CG/PG
|
|
|
|
Thu Aug 5 22:24:37 CEST 2010
|
|
Fixing timeout bug on systems that think it's still
|
|
1970 (can happen if system time not initialized). -CG
|
|
|
|
Mon Jul 26 10:46:57 CEST 2010
|
|
Releasing libmicrohttpd 0.9.0. -CG
|
|
|
|
Sun Jul 25 14:57:47 CEST 2010
|
|
Adding support for sendfile on Linux. Adding support
|
|
for systemd-style passing of an existing listen socket
|
|
as an option. IPv6 sockets now only bind to IPv6
|
|
(if platform supports this). -CG
|
|
|
|
Sun Jul 25 11:10:45 CEST 2010
|
|
Changed code to use external libgnutls code instead of
|
|
the "fork". Minor API changes for setting TLS options. -CG
|
|
|
|
Sun Jun 13 10:52:34 CEST 2010
|
|
Cleaned up example code. -CG
|
|
|
|
Fri Apr 23 09:56:37 CEST 2010
|
|
Do not return HTTP headers for requests without version
|
|
numbers. Do return HTTP version 1.0 if client requested
|
|
HTTP version 1.1 (previously, we returned HTTP/1.1 even
|
|
if the client specified HTTP/1.0). -GM/CG
|
|
|
|
Sat Mar 13 09:41:01 CET 2010
|
|
Releasing libmicrohttpd 0.4.6. -CG
|
|
|
|
Wed Mar 10 13:18:26 CET 2010
|
|
Fixing bug in 100 CONTINUE replacement when handling POSTs
|
|
(see report on mailinglist), with testcase. -CG/MC
|
|
|
|
Tue Feb 23 09:16:15 CET 2010
|
|
Added configure check for endianness to define WORDS_BIGENDIAN
|
|
which fixes SSL support on big endian architectures. -JA/CG
|
|
|
|
Sat Feb 20 10:01:09 CET 2010
|
|
Added check for inconsistent options (MHD_OPTION_PROTOCOL_VERSION
|
|
without MHD_USE_SSL) causing instant segfault. -JA/CG
|
|
|
|
Tue Feb 9 20:31:51 CET 2010
|
|
Fixed issue with poll doing busy waiting. -BK/CG
|
|
|
|
Thu Jan 28 21:28:56 CET 2010
|
|
Releasing libmicrohttpd 0.4.5. -CG
|
|
|
|
Thu Jan 28 20:35:48 CET 2010
|
|
Make sure addresses returned by memory pool are
|
|
aligned (fixes bus errors on Sparc). -CG
|
|
|
|
Thu Dec 17 20:26:52 CET 2009
|
|
poll.h is not stricly required anymore. -ND
|
|
|
|
Fri Dec 4 13:17:50 CET 2009
|
|
Adding MHD_OPTION_ARRAY. -CG
|
|
|
|
Mon Nov 16 14:41:26 CET 2009
|
|
Fixed busy-loop in internal select mode for inactive
|
|
clients with infinite connection timeout. -CG
|
|
|
|
Thu Nov 12 16:19:14 CET 2009
|
|
Adding support for setting a custom error handler for
|
|
fatal errors (previously, the implementation always
|
|
called 'abort' in these cases). -CG/ND
|
|
|
|
Wed Nov 11 12:54:16 CET 2009
|
|
Adding support for poll (alternative to select allowing
|
|
for more than FD_SETSIZE parallel connections). -JM
|
|
|
|
Wed Oct 28 20:26:00 CET 2009
|
|
Releasing libmicrohttpd 0.4.4. -CG
|
|
|
|
Wed Oct 14 14:37:37 CEST 2009
|
|
Fixing (rare) deadlock due to SELECT missing SIGALRM by
|
|
making all SELECT calls block for at most 1s. While this
|
|
can in (rare) situations delay the shutdown by 1s, I think
|
|
this is preferable (both performance and possibly portability-wise)
|
|
over using a pipe for the signal. -CG
|
|
|
|
Sun Oct 11 14:57:29 CEST 2009
|
|
Adding eCos license as an additional license for the
|
|
non-HTTPS code of MHD. -CG
|
|
|
|
Sun Oct 11 11:24:27 CEST 2009
|
|
Adding support for Symbian. -MR
|
|
|
|
Fri Oct 9 15:21:29 CEST 2009
|
|
Check for error codes from pthread operations (to help with
|
|
error diagnostics) and abort if something went wrong. -CG
|
|
|
|
Thu Oct 8 10:43:02 CEST 2009
|
|
Added check for sockets being '< FD_SETSIZE' (just to be safe). -CG
|
|
|
|
Mon Oct 5 21:17:26 CEST 2009
|
|
Adding "COOKIE" header string #defines. -CG
|
|
|
|
Mon Oct 5 08:29:06 CEST 2009
|
|
Documenting default values. -CG
|
|
|
|
Fri Aug 28 22:56:47 CEST 2009
|
|
Releasing libmicrohttpd 0.4.3. -CG
|
|
|
|
Sun Aug 23 16:21:35 UTC 2009
|
|
Allow MHD_get_daemon_info to return the daemon's listen socket.
|
|
Includes a test case that uses this functionality to bind a server to
|
|
an OS-assigned port, look the port up with getsockname, and curl it. -DR
|
|
|
|
Tue Aug 4 00:14:04 CEST 2009
|
|
Fixing double-call to read from content-reader callback for first
|
|
data segment (as reported by Alex on the mailinglist). -CG
|
|
|
|
Thu Jul 29 21:41:52 CEST 2009
|
|
Fixed issue with the code not using the "block_size" argument
|
|
given to MHD_create_response_from_callback causing inefficiencies
|
|
for values < 2048 and segmentation faults for values > 2048
|
|
(as reported by Andre Colomb on the mailinglist). -CG
|
|
|
|
Sun May 17 03:29:46 MDT 2009
|
|
Releasing libmicrohttpd 0.4.2. -CG
|
|
|
|
Fri May 15 11:00:20 MDT 2009
|
|
Grow reserved read buffer more aggressively so that we are not
|
|
needlessly stuck reading only a handfull of bytes in each iteration. -CG
|
|
|
|
Thu May 14 21:20:30 MDT 2009
|
|
Fixed issue where the "NOTIFY_COMPLETED" handler could be called
|
|
twice (if a socket error or timeout occured for a pipelined
|
|
connection after successfully completing a request and before
|
|
the next request was successfully transmitted). This could
|
|
confuse applications not expecting to see a connection "complete"
|
|
that they were never aware of in the first place. -CG
|
|
|
|
Mon May 11 13:01:16 MDT 2009
|
|
Fixed issue where error code on timeout was "TERMINATED_WITH_ERROR"
|
|
instead of "TERMINATED_TIMEOUT_REACHED". -CG
|
|
|
|
Wed Apr 1 21:33:05 CEST 2009
|
|
Added MHD_get_version(). -ND
|
|
|
|
Wed Mar 18 22:59:07 MDT 2009
|
|
Releasing libmicrohttpd 0.4.1. -CG
|
|
|
|
Wed Mar 18 17:46:58 MDT 2009
|
|
Always RECV/SEND with MSG_DONTWAIT to (possibly) address
|
|
strange deadlock reported by Erik on the mailinglist ---
|
|
and/or issues with blocking read after select on GNU/Linux
|
|
(see select man page under bugs). -CG
|
|
|
|
Tue Mar 17 01:19:50 MDT 2009
|
|
Added support for thread-pools. -CG/RA
|
|
|
|
Mon Mar 2 23:44:08 MST 2009
|
|
Fixed problem with 64-bit upload and download sizes and
|
|
"-1" being used to indicate "unknown" by introducing
|
|
new 64-bit constant "MHD_SIZE_UNKNOWN". -CG/DC
|
|
|
|
Wed Feb 18 08:13:56 MST 2009
|
|
Added missing #include for build on arm-linux-uclibc. -CG/CC
|
|
|
|
Mon Feb 16 21:12:21 MST 2009
|
|
Moved MHD_get_connection_info so that it is always defined,
|
|
even if HTTPS support is not enabled. -CG
|
|
|
|
Sun Feb 8 21:15:30 MST 2009
|
|
Releasing libmicrohttpd 0.4.0. -CG
|
|
|
|
Thu Feb 5 22:43:45 MST 2009
|
|
Incompatible API change to allow 64-bit uploads and downloads.
|
|
Clients must use "uint64_t" for the "pos"
|
|
argument (MHD_ContentReaderCallback) and the "off"
|
|
argument (MHD_PostDataIterator) and the "size"
|
|
argument (MHD_create_response_from_callback) now.
|
|
Also, "unsigned int" was changed to "size_t" for
|
|
the "upload_data_size" argument (MHD_AccessHandlerCallback),
|
|
the argument to MHD_OPTION_CONNECTION_MEMORY_LIMIT,
|
|
the "block_size" argument (MHD_create_response_from_callback),
|
|
the "buffer_size" argument (MHD_create_post_processor) and
|
|
the "post_data_len" argument (MHD_post_process). You may
|
|
need to #include <stdint.h> before <microhttpd.h> from now on. -CG
|
|
|
|
Thu Feb 5 20:21:08 MST 2009
|
|
Allow getting address information about the connecting
|
|
client after the accept call. -CG
|
|
|
|
Mon Feb 2 22:21:48 MST 2009
|
|
Fixed missing size adjustment for offsets for %-encoded
|
|
arguments processed by the post processor (Mantis #1447). -CG/SN
|
|
|
|
Fri Jan 23 16:57:21 MST 2009
|
|
Support charset specification (ignore) after content-type
|
|
when post-processing HTTP POST requests (Mantis #1443). -CG/SN
|
|
|
|
Fri Dec 26 23:08:04 MST 2008
|
|
Fixed broken check for identical connection address. -CG
|
|
Making cookie parser more RFC2109 compliant (handle
|
|
spaces around key, allow value to be optional). -CG
|
|
|
|
Sat Dec 6 18:36:17 MST 2008
|
|
Added configure option to disable checking for CURL support.
|
|
Added MHD_OPTION to allow specification of custom logger. -CG
|
|
|
|
Tue Nov 18 01:19:53 MST 2008
|
|
Removed support for untested and/or broken SSL features
|
|
and (largely useless) options. -CG
|
|
|
|
Sun Nov 16 16:54:54 MST 2008
|
|
Added option to get unparsed URI via callback.
|
|
Releasing GNU libmicrohttpd 0.4.0pre1. -CG
|
|
|
|
Sun Nov 16 02:48:14 MST 2008
|
|
Removed tons of dead code. -CG
|
|
|
|
Sat Nov 15 17:34:24 MST 2008
|
|
Added build support for code coverage analysis. -CG
|
|
|
|
Sat Nov 15 00:31:33 MST 2008
|
|
Removing (broken) support for HTTPS servers with
|
|
anonymous (aka "no") certificates as well as
|
|
various useless dead code. -CG
|
|
|
|
Sat Nov 8 02:18:42 MST 2008
|
|
Unset TCP_CORK at the end of transmitting a response
|
|
to improve performance (on systems where this is
|
|
supported). -MM
|
|
|
|
Tue Sep 30 16:48:08 MDT 2008
|
|
Make MHD useful to Cygwin users; detect IPv6 headers
|
|
in configure.
|
|
|
|
Sun Sep 28 14:57:46 MDT 2008
|
|
Unescape URIs (convert "%ef%e4%45" to "$BCf9q(B"). -CG
|
|
|
|
Wed Sep 10 22:43:59 MDT 2008
|
|
Releasing GNU libmicrohttpd 0.4.0pre0. -CG
|
|
|
|
Wed Sep 10 21:36:06 MDT 2008
|
|
Fixed data race on closing sockets during
|
|
shutdown (in one-thread-per-connection mode). -CG
|
|
|
|
Thu Sep 4 23:37:18 MDT 2008
|
|
Fixed some boundary issues with processing
|
|
chunked requests; removed memmove from a
|
|
number of spots, in favor of using an index into
|
|
the current buffer instead. -GS
|
|
|
|
Sun Aug 24 13:05:41 MDT 2008
|
|
Now handling clients returning 0 from response callback
|
|
as specified in the documentation (abort if internal
|
|
select is used, retry immediately if a thread per
|
|
connection is used). -CG
|
|
|
|
Sun Aug 24 12:44:43 MDT 2008
|
|
Added missing reason phrase. -SG
|
|
|
|
Sun Aug 24 10:33:22 MDT 2008
|
|
Fixed bug where MHD failed to transmit the response when
|
|
the client decided not to send "100 CONTINUE" during
|
|
a PUT/POST request. -CG
|
|
|
|
Wed Jul 16 18:54:03 MDT 2008
|
|
Fixed bug generating chunked responses with chunk sizes
|
|
greater than 0xFFFFFF (would cause protocol violations). -CG
|
|
|
|
Mon May 26 13:28:57 MDT 2008
|
|
Updated and improved documentation.
|
|
Releasing GNU libmicrohttpd 0.3.1. -CG
|
|
|
|
Fri May 23 16:54:41 MDT 2008
|
|
Fixed issue with postprocessor not handling URI-encoded
|
|
values of more than 1024 bytes correctly. -CG
|
|
|
|
Mon May 5 09:18:29 MDT 2008
|
|
Fixed date header (was off by 1900 years). -JP
|
|
|
|
Sun Apr 13 01:06:20 MDT 2008
|
|
Releasing GNU libmicrohttpd 0.3.0. -CG
|
|
|
|
Sat Apr 12 21:34:26 MDT 2008
|
|
Generate an internal server error if the programmer fails
|
|
to handle upload data correctly. Tweaked testcases to
|
|
avoid running into the problem in the testcases.
|
|
Completed zzuf-based fuzzing testcases. -CG
|
|
|
|
Sat Apr 12 15:14:05 MDT 2008
|
|
Restructured the code (curl-testcases and zzuf testcases
|
|
are now in different directories; code examples are in
|
|
src/examples/).
|
|
Fixed a problem (introduced in 0.2.3) with handling very
|
|
large requests (the code did not return proper error code).
|
|
If "--enable-messages" is specified, the code now includes
|
|
reasonable default HTML webpages for various build-in
|
|
errors (such as request too large and malformed requests).
|
|
Without that flag, the webpages returned will still be
|
|
empty.
|
|
Started to add zzuf-based fuzzing-testcases (these require
|
|
the zzuf and socat binaries to be installed). -CG
|
|
|
|
Fri Apr 11 20:20:34 MDT 2008
|
|
I hereby dub libmicrohttpd a GNU package. -Richard Stallman
|
|
|
|
Sat Mar 29 22:36:09 MDT 2008
|
|
Fixed bugs in handling of malformed HTTP requests
|
|
(causing either NULL dereferences or connections to
|
|
persist until time-out, if any). -CG
|
|
|
|
Updated and integrated TexInfo documentation. -CG
|
|
|
|
Tue Mar 25 13:40:53 MDT 2008
|
|
Prevent multi-part post-processor from going to error
|
|
state when the input buffer is full and current token
|
|
just changes processor state without consuming any data.
|
|
Also, the original implementation would not consume any
|
|
input in process_value_to_boundary if there is no new
|
|
line character in sight. -AS
|
|
|
|
Remove checks for request method after it finished writing
|
|
response footers as it's only _pipelined_ requests that
|
|
should not be allowed after POST or PUT requests. Reusing
|
|
the existing connection is perfectly ok though. And there
|
|
is no reliable way to detect pipelining on server side
|
|
anyway so it is the client's responsibility to not send new
|
|
data before it gets a response after a POST operation. -AS
|
|
|
|
Clarified license in man page. Releasing
|
|
libmicrohttpd 0.2.3 -CG
|
|
|
|
Sat Mar 22 01:12:38 MDT 2008
|
|
Releasing libmicrohttpd 0.2.2. -CG
|
|
|
|
Mon Feb 25 19:13:53 MST 2008
|
|
Fixed a problem with sockets closed for reading ending up
|
|
in the read set under certain circumstances. -CG
|
|
|
|
Wed Jan 30 23:15:44 MST 2008
|
|
Added support for nested multiparts to post processor.
|
|
Made sure that MHD does not allow pipelining for methods
|
|
other than HEAD and GET (and of course still also only
|
|
allows it for http 1.1). Releasing libmicrohttpd 0.2.1. -CG
|
|
|
|
Mon Jan 21 11:59:46 MST 2008
|
|
Added option to limit number of concurrent connections
|
|
accepted from the same IP address. -CG
|
|
|
|
Fri Jan 4 16:02:08 MST 2008
|
|
Fix to properly close connection if application signals
|
|
problem handling the request. - AS
|
|
|
|
Wed Jan 2 16:41:05 MST 2008
|
|
Improvements and bugfixes to post processor implementation. - AS
|
|
|
|
Wed Dec 19 21:12:04 MST 2007
|
|
Implemented chunked (HTTP 1.1) downloads (including
|
|
sending of HTTP footers). Also allowed queuing of
|
|
a response early to suppress the otherwise automatic
|
|
"100 CONTINUE" response. Removed the mostly useless
|
|
"(un)register handler" methods from the API. Changed
|
|
the internal implementation to use a finite state
|
|
machine (cleaner code, slightly less memory consumption).
|
|
Releasing libmicrohttpd 0.2.0. - CG
|
|
|
|
Sun Dec 16 03:24:13 MST 2007
|
|
Implemented handling of chunked (HTTP 1.1) uploads.
|
|
Note that the upload callback must be able to
|
|
process chunks in the size uploaded by the client,
|
|
MHD will not "join" small chunks into a big
|
|
contiguous block of memory (even if buffer space
|
|
would be available). - CG
|
|
|
|
Wed Dec 5 21:39:35 MST 2007
|
|
Fixed race in multi-threaded server mode.
|
|
Fixed handling of POST data when receiving a
|
|
"Connection: close" header (#1296).
|
|
Releasing libmicrohttpd 0.1.2. - CG
|
|
|
|
Sat Nov 17 00:55:24 MST 2007
|
|
Fixed off-by-one in error message string matching.
|
|
Added code to avoid generating SIGPIPE on platforms
|
|
where this is possible (everywhere else, the main
|
|
application should install a handler for SIGPIPE).
|
|
|
|
Thu Oct 11 11:02:06 MDT 2007
|
|
Releasing libmicrohttpd 0.1.1. - CG
|
|
|
|
Thu Oct 11 10:09:12 MDT 2007
|
|
Fixing response to include HTTP status message. - EG
|
|
|
|
Thu Sep 27 10:19:46 MDT 2007
|
|
Fixing parsing of "%xx" in URLs with GET arguments. - eglaysher
|
|
|
|
Sun Sep 9 14:32:23 MDT 2007
|
|
Added option to compile debug/warning messages;
|
|
error messages are now disabled by default.
|
|
Modified linker option for GNU LD to not export
|
|
non-public symbols (further reduces binary size).
|
|
Releasing libmicrohttpd 0.1.0. - CG
|
|
|
|
Sat Sep 8 21:54:04 MDT 2007
|
|
Extended API to allow for incremental POST
|
|
processing. The new API is binary-compatible
|
|
as long as the app does not handle POSTs, but
|
|
since that maybe the case, we're strictly speaking
|
|
breaking backwards compatibility (since url-encoded
|
|
POST data is no longer obtained the same way). - CG
|
|
|
|
Thu Aug 30 00:59:24 MDT 2007
|
|
Improving API to allow clients to associate state
|
|
with a connection and to be notified about request
|
|
termination (this is a binary-compatible change). - CG
|
|
Fixed compile errors under OS X. - HL
|
|
|
|
Sun Aug 26 03:11:46 MDT 2007
|
|
Added MHD_USE_PEDANTIC_CHECKS option which enforces
|
|
receiving a "Host:" header in HTTP 1.1 (and sends a
|
|
HTTP 400 status back if this is violated). - CG
|
|
|
|
Tue Aug 21 01:01:46 MDT 2007
|
|
Fixing assertion failure that occured when a client
|
|
closed the connection after sending some data but
|
|
not the full headers. - CG
|
|
|
|
Sat Aug 18 03:06:09 MDT 2007
|
|
Check for out of memory when adding headers to
|
|
responses. Check for NULL key when looking
|
|
for headers. If a content reader callback
|
|
for a response returns zero (has no data yet),
|
|
do not possibly fall into busy waiting when
|
|
using external select (with internal selects
|
|
we have no choice). - CG
|
|
|
|
Wed Aug 15 01:46:44 MDT 2007
|
|
Extending API to allow timeout of connections.
|
|
Changed API (MHD_create_response_from_callback) to
|
|
allow user to specify IO buffer size.
|
|
Improved error handling.
|
|
Released libmicrohttpd 0.0.3. - CG
|
|
|
|
Tue Aug 14 19:45:49 MDT 2007
|
|
Changed license to LGPL (with consent from all contributors).
|
|
Released libmicrohttpd 0.0.2. - CG
|
|
|
|
Sun Aug 12 00:09:26 MDT 2007
|
|
Released libmicrohttpd 0.0.1. - CG
|
|
|
|
Fri Aug 10 17:31:23 MDT 2007
|
|
Fixed problems with handling of responses created from
|
|
callbacks. Allowing accept policy callback to be NULL
|
|
(to accept from all). Added minimal fileserver example.
|
|
Only send 100 continue header when specifically requested. - CG
|
|
|
|
Wed Aug 8 01:46:06 MDT 2007
|
|
Added pool allocation and connection limitations (total
|
|
number and memory size). Released libmicrohttpd 0.0.0. - CG
|
|
|
|
Tue Jan 9 20:52:48 MST 2007
|
|
Created project build files and updated API. - CG
|