Repository navigation
Conversation
…erflow Check that shifting `_size` left by 4 bits does not overflow a signed 64-bit integer in `_Sink._decode`, throwing a `FormatException` when a chunk size exceeds `0x7fffffffffffffff` instead of overflowing to a negative bound or wrapping to zero. Also compute `math.min(end - start, _size)` in `_State.body` so `start + _size` cannot overflow on valid large chunk sizes.
PR HealthCoverage ✔️
This check for test coverage is informational (issues shown here will not fail the PR). This check can be disabled by tagging the PR with License Headers ✔️
All source files should start with a license header. Unrelated files missing license headers
This check can be disabled by tagging the PR with Breaking changes ✔️
This check can be disabled by tagging the PR with Unused Dependencies ✔️
For details on how to fix these, see dependency_validator. This check can be disabled by tagging the PR with API leaks ✔️The following packages contain symbols visible in the public API, but not exported by the library. Export these symbols or remove them from your publicly visible API.
This check can be disabled by tagging the PR with Changelog Entry ✔️
Changes to files need to be accounted for in their respective changelogs. This check can be disabled by tagging the PR with |
…ype.toString Include `\` in `_escapedChar` so quoted parameter values containing backslashes round-trip through `MediaType.parse(mediaType.toString())` without corrupting escaped characters or leaving a trailing unescaped quote, and quote empty parameter values (`value.isEmpty`) as `""` instead of emitting a bare `=`. Also remove unused `name` and `toString()` members from private `enum _State` in `chunked_coding/decoder.dart`.
…ctly Avoid passing `List<int>.addAll` tear-offs into `ByteConversionSink.withCallback`, which triggers a `dart2wasm` TFA `RuntimeError: unreachable` trap when `Uint8Buffer.addAll` is present in the same compilation unit.
Rationale
ChunkedCodingDecoder(_Sink._decode): Chunk sizes were accumulated via_size = (_size << 4) + digitwithout checking for integer overflow, and chunk body bounds were computed asmath.min(end, start + _size). A 16-digit hexadecimal chunk size>= 0x8000000000000000(orstart + _sizewhenstart > 0) overflowed signed 64-bitintto a negative index and threwRangeErrorinUint8Buffer.addAllinstead ofFormatException, while 17+ hex digits truncated the declared chunk size.MediaType.toString(): In4.1.2,_quotedStringinscan.dartwas tightened to disallow unescaped\inqdtext, but_escapedCharinmedia_type.dartremainedRegExp(r'["\x00-\x1F\x7F]')(missing\\). Any parameter value containing\(foo="bar\\baz"ortrail="end\\") was serialized without escaping\, corruptingbar\baztobarbazon re-parse and turning trailing backslashes (trail="end\\") into an unterminated quoted string (trail="end\") that threwFormatExceptioninMediaType.parse(). Empty parameter values (foo="") also failednonToken.hasMatch("")and serialized asfoo=, throwingFormatExceptionon re-parse.Summary of Changes
pkgs/http_parser/lib/src/chunked_coding/decoder.dart: Checkif (_size > _maxSizeBeforeShift)before accumulating_size = (_size * 16) + digitin_State.size, throwingFormatException('Chunk size is too large.', bytes, start), computefinal bytesToRead = math.min(end - start, _size)in_State.body, and remove unusedname/toString()members on privateenum _State.pkgs/http_parser/lib/src/media_type.dart: Add\\to_escapedChar(RegExp(r'["\x00-\x1F\x7F\\]')) and quote empty parameter values (if (value.isEmpty || nonToken.hasMatch(value))).pkgs/http_parser/test/chunked_coding_test.dart,pkgs/http_parser/test/media_type_test.dart, &pkgs/http_parser/CHANGELOG.md: Add regression tests for 64-bit chunk size overflows andMediaType.toString()/MediaType.parse()round-tripping (159tests passing), and document under4.1.3-wip.Verification
dart analyze --fatal-infos: exit0dart format --output=none --set-exit-if-changed .: exit0dart test -p vm -c source&dart test -p node: exit0(159 tests passed)