Skip to content

Commit

Permalink
HTTP/2: backed out 16905ecbb49e (ticket #822).
Browse files Browse the repository at this point in the history
It caused inconsistency between setting "in_closed" flag and the moment when
the last DATA frame was actually read.  As a result, the body buffer might not
be initialized properly in ngx_http_v2_init_request_body(), which led to a
segmentation fault in ngx_http_v2_state_read_data().  Also it might cause
start processing of incomplete body.

This issue could be triggered when the processing of a request was delayed,
e.g. in the limit_req or auth_request modules.
  • Loading branch information
VBart committed Nov 5, 2015
1 parent f9cce38 commit b22c0e0
Showing 1 changed file with 5 additions and 3 deletions.
8 changes: 5 additions & 3 deletions src/http/v2/ngx_http_v2.c
Original file line number Diff line number Diff line change
Expand Up @@ -870,8 +870,6 @@ ngx_http_v2_state_data(ngx_http_v2_connection_t *h2c, u_char *pos, u_char *end)
return ngx_http_v2_state_skip_padded(h2c, pos, end);
}

stream->in_closed = h2c->state.flags & NGX_HTTP_V2_END_STREAM_FLAG;

h2c->state.stream = stream;

return ngx_http_v2_state_read_data(h2c, pos, end);
Expand Down Expand Up @@ -899,6 +897,8 @@ ngx_http_v2_state_read_data(ngx_http_v2_connection_t *h2c, u_char *pos,
}

if (stream->skip_data) {
stream->in_closed = h2c->state.flags & NGX_HTTP_V2_END_STREAM_FLAG;

ngx_log_debug1(NGX_LOG_DEBUG_HTTP, h2c->connection->log, 0,
"skipping http2 DATA frame, reason: %d",
stream->skip_data);
Expand Down Expand Up @@ -988,7 +988,9 @@ ngx_http_v2_state_read_data(ngx_http_v2_connection_t *h2c, u_char *pos,
ngx_http_v2_state_read_data);
}

if (stream->in_closed) {
if (h2c->state.flags & NGX_HTTP_V2_END_STREAM_FLAG) {
stream->in_closed = 1;

if (r->headers_in.content_length_n < 0) {
r->headers_in.content_length_n = rb->rest;

Expand Down

0 comments on commit b22c0e0

Please sign in to comment.