Merge commit from fork

avoid OOB reads in path_is_sane
This commit is contained in:
Sergio R. Caprile
2026-06-23 13:05:25 -03:00
committed by GitHub
3 changed files with 31 additions and 13 deletions
+9 -6
View File
@@ -25256,13 +25256,16 @@ int mg_check_ip_acl(struct mg_str acl, struct mg_addr *remote_ip) {
bool mg_path_is_sane(const struct mg_str path) {
const char *s = path.buf;
size_t n = path.len;
if (path.buf[0] == '~') return false; // Starts with ~
if (path.buf[0] == '.' && path.buf[1] == '.') return false; // Starts with ..
for (; s[0] != '\0' && n > 0; s++, n--) {
if ((s[0] == '/' || s[0] == '\\') && n >= 2) { // Subdir?
if (s[1] == '.' && s[2] == '.') return false; // Starts with ..
}
if (n == 0 || path.buf[0] == '\0') return true;
if (s[0] == '~') return false; // Starts with ~
if (s[0] == '.' && n > 1 && s[1] == '.')
return false; // Starts with ..
for (; n > 0 && s[0] != '\0'; s++, n--) {
if ((s[0] == '/' || s[0] == '\\') && n >= 2 && s[1] == '.' && n > 2 &&
s[2] == '.')
return false; // Subdir starts with ..
}
if (n > 0) return false; // embedded nul (terminator not counted in len)
return true;
}
+9 -6
View File
@@ -143,13 +143,16 @@ int mg_check_ip_acl(struct mg_str acl, struct mg_addr *remote_ip) {
bool mg_path_is_sane(const struct mg_str path) {
const char *s = path.buf;
size_t n = path.len;
if (path.buf[0] == '~') return false; // Starts with ~
if (path.buf[0] == '.' && path.buf[1] == '.') return false; // Starts with ..
for (; s[0] != '\0' && n > 0; s++, n--) {
if ((s[0] == '/' || s[0] == '\\') && n >= 2) { // Subdir?
if (s[1] == '.' && s[2] == '.') return false; // Starts with ..
}
if (n == 0 || path.buf[0] == '\0') return true;
if (s[0] == '~') return false; // Starts with ~
if (s[0] == '.' && n > 1 && s[1] == '.')
return false; // Starts with ..
for (; n > 0 && s[0] != '\0'; s++, n--) {
if ((s[0] == '/' || s[0] == '\\') && n >= 2 && s[1] == '.' && n > 2 &&
s[2] == '.')
return false; // Subdir starts with ..
}
if (n > 0) return false; // embedded nul (terminator not counted in len)
return true;
}
+13 -1
View File
@@ -2554,7 +2554,18 @@ static void test_str(void) {
ASSERT(strcmp(buf, "[164:2100:0:0:0:0:0:0]:3 7") == 0);
}
ASSERT(mg_path_is_sane(mg_str(".")) == true);
{
char s[1] = ".";
ASSERT(mg_path_is_sane(mg_str_n(s, 1)) == true);
}
{
char s[2] = "/.";
ASSERT(mg_path_is_sane(mg_str_n(s, 2)) == true);
}
{
char s[3] = "a/.";
ASSERT(mg_path_is_sane(mg_str_n(s, 3)) == true);
}
ASSERT(mg_path_is_sane(mg_str("")) == true);
ASSERT(mg_path_is_sane(mg_str("a.b")) == true);
ASSERT(mg_path_is_sane(mg_str("a..b")) == true);
@@ -2570,6 +2581,7 @@ static void test_str(void) {
ASSERT(mg_path_is_sane(mg_str("a/../b")) == false);
ASSERT(mg_path_is_sane(mg_str_n("a/..", 2)) == true);
ASSERT(mg_path_is_sane(mg_str_n("a/../b", 2)) == true);
ASSERT(mg_path_is_sane(mg_str_n("a\0/../b", 7)) == false);
}
static void fn1(struct mg_connection *c, int ev, void *ev_data) {