Pull requests / #1583
#1583 fix(server): reject incomplete chunked request trailers
open · @hulkbig · 0 评论 · 在 GitHub 查看
描述
## Summary
Reject incomplete chunked request framing before applying the decoded body. `_read_chunked` currently accepts EOF or whitespace as a terminal blank line and returns successfully when its trailer-read limit is exhausted. An otherwise valid JSON body can therefore change `/settings` despite incomplete framing.
## What changed
- Require the actual terminal `\r\n`, complete CRLF-terminated trailer lines, and a terminator within the existing 64-read cap.
- Add raw-socket regressions for missing, partial and malformed terminators, overlong trailers, and cap exhaustion; assert HTTP 400 and unchanged settings.
- Preserve valid chunk extensions and trailers, including 63 trailer lines plus the final blank line.
Reproduction: send a chunked `/settings` POST containing `{"defaults":{"temperature":0.5}}`, end after `0\r\n` without the final blank line, and half-close the sending side. The baseline applies the settings with HTTP 200; this change returns 400 without applying them.
## Validation
- 9 new failing cases/subcases reproduced on the baseline; 41 focused tests pass with the fix.
- Independent review reran all 12 `serve.test_chunked_body` tests successfully.
- Full tracked suite: 597 tests on this branch versus 593 on the base; both have the same telemetry environment error (`disk_io_counters()` returns `None`) and 11 skips. The full suite is not green in this environment.
- `py_compile` and `git diff --check` pass.
## Scope
This complements #1126 by fixing chunked trailer parsing. The Content-Length `_body` path is unchanged to avoid duplicating its ongoing validation work.站内延伸阅读
链到安装、模型与版本说明,便于 SEO/GEO,非官方 issue 正文。