yahns Ruby server user/dev discussion
 help / color / Atom feed
* [PATCH] extras/try_gzip_static: do not show backtrace on syscall errors
@ 2016-06-05 23:30 Eric Wong
  0 siblings, 0 replies; only message in thread
From: Eric Wong @ 2016-06-05 23:30 UTC (permalink / raw)
  To: yahns-public

On ENAMETOOLONG and perhaps other system errors which we can do
nothing about, we should not spew a giant backtrace which could
be used as an easy DoS vector.
---
 extras/try_gzip_static.rb           |  2 +-
 test/test_extras_try_gzip_static.rb | 12 ++++++++++++
 2 files changed, 13 insertions(+), 1 deletion(-)

diff --git a/extras/try_gzip_static.rb b/extras/try_gzip_static.rb
index 0d5d63b..31c1aa1 100644
--- a/extras/try_gzip_static.rb
+++ b/extras/try_gzip_static.rb
@@ -203,7 +203,7 @@ def r(code, exc = nil, env = nil)
       msg = msg.dump if /[[:cntrl:]]/ =~ msg # prevent code injection
       logger.warn("#{env['REQUEST_METHOD']} #{env['PATH_INFO']} " \
                   "#{code} #{msg}")
-      if exc.respond_to?(:backtrace)
+      if exc.respond_to?(:backtrace) && !(SystemCallError === exc)
         exc.backtrace.each { |line| logger.warn(line) }
       end
     end
diff --git a/test/test_extras_try_gzip_static.rb b/test/test_extras_try_gzip_static.rb
index c6c8cef..4d20b5a 100644
--- a/test/test_extras_try_gzip_static.rb
+++ b/test/test_extras_try_gzip_static.rb
@@ -34,6 +34,18 @@ def test_gzip_static
       end
     end
 
+    Net::HTTP.start(host, port) do |http|
+      uri = "/COPYING/foo" + ('-' * 4096)
+      begin
+        res = http.request(Net::HTTP::Get.new(uri))
+      end while res.code.to_i == 414 && uri.chop!
+      res = http.request(Net::HTTP::Get.new("/COPYING/foo"))
+      assert_equal 404, res.code.to_i
+      lines = File.readlines(err.path)
+      File.truncate(err.path, 0)
+      assert_operator lines.size, :<, 3, lines.map! { |s| s[0,64] }.inspect
+    end
+
     begin # setup
       gpl = "#{tmpdir}/COPYING"
       gplgz = "#{tmpdir}/COPYING.gz"

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, back to index

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-06-05 23:30 [PATCH] extras/try_gzip_static: do not show backtrace on syscall errors Eric Wong

yahns Ruby server user/dev discussion

Archives are clonable:
	git clone --mirror https://yhbt.net/yahns-public
	git clone --mirror http://ou63pmih66umazou.onion/yahns-public

Newsgroups are available over NNTP:
	nntp://news.public-inbox.org/inbox.comp.lang.ruby.yahns
	nntp://ou63pmih66umazou.onion/inbox.comp.lang.ruby.yahns

 note: .onion URLs require Tor: https://www.torproject.org/

AGPL code for this site: git clone https://public-inbox.org/ public-inbox