feat(parser): strict Transfer-Encoding framing; unknown coding -> 501
The TE arm set chunked whenever the token appeared anywhere in the value, so 'chunked, gzip' (chunked not final) was accepted and an unknown coding like 'bogus' was treated as no-body (h1spec #18/#19 -> 404). Collect the ordered coding list across all TE headers and decide post-loop: TE on HTTP/1.0 or TE+Content-Length -> 400 (the CL check now covers ANY TE, not just chunked, closing the old TE:unknown + CL smuggling gap); chunked present but not final -> 400; any coding other than chunked -> 501 via a new UnknownTransferCoding variant (emit_error_response gains the 501 arm); only a sole final chunked sets the flag. Tests cover each branch. Note: the dead Unsupported/411 variant is left as-is (separate cleanup).
This commit is contained in:
@@ -773,6 +773,8 @@ fn emit_error_response(fd: RawFd, err: &ParseError, deadline: Instant) {
|
||||
b"HTTP/1.1 400 Bad Request\r\ncontent-length: 0\r\nconnection: close\r\n\r\n",
|
||||
ParseError::Unsupported =>
|
||||
b"HTTP/1.1 411 Length Required\r\ncontent-length: 0\r\nconnection: close\r\n\r\n",
|
||||
ParseError::UnknownTransferCoding =>
|
||||
b"HTTP/1.1 501 Not Implemented\r\ncontent-length: 0\r\nconnection: close\r\n\r\n",
|
||||
// Incomplete and Malformed both lead here; Incomplete shouldn't
|
||||
// appear (read_head loops on it).
|
||||
_ =>
|
||||
|
||||
Reference in New Issue
Block a user