mirror of
https://github.com/rakshasa/rtorrent.git
synced 2026-10-05 13:49:21 +00:00
Answer an oversized RPC response with a fault
Cap XML-RPC and JSON-RPC output at the SCGI response limit before handing it over.
This commit is contained in:
@@ -8,12 +8,18 @@
|
||||
#include "globals.h"
|
||||
#include "command_helpers.h"
|
||||
#include "rpc/command_map.h"
|
||||
#include "rpc/scgi_task.h"
|
||||
|
||||
CPPUNIT_TEST_SUITE_REGISTRATION(TestJsonrpc);
|
||||
|
||||
torrent::Object
|
||||
jsonrpc_cmd_test_reflect([[maybe_unused]] rpc::target_type t, const torrent::Object& obj) { return obj; }
|
||||
|
||||
torrent::Object
|
||||
jsonrpc_cmd_test_oversized([[maybe_unused]] rpc::target_type t, [[maybe_unused]] const torrent::Object& obj) {
|
||||
return torrent::Object(std::string(rpc::SCgiTask::max_response_size + (1 << 20), 'a'));
|
||||
}
|
||||
|
||||
void initialize_command_dynamic();
|
||||
|
||||
// Name, Request, Expected response
|
||||
@@ -130,6 +136,10 @@ TestJsonrpc::setUp() {
|
||||
if (rpc::commands.find("jsonrpc_reflect") == rpc::commands.end()) {
|
||||
CMD2_ANY("jsonrpc_reflect", &jsonrpc_cmd_test_reflect);
|
||||
}
|
||||
|
||||
if (rpc::commands.find("jsonrpc_oversized") == rpc::commands.end()) {
|
||||
CMD2_ANY("jsonrpc_oversized", &jsonrpc_cmd_test_oversized);
|
||||
}
|
||||
}
|
||||
|
||||
void
|
||||
@@ -145,3 +155,21 @@ TestJsonrpc::test_basics() {
|
||||
CPPUNIT_ASSERT_EQUAL_MESSAGE(std::get<0>(test), std::get<2>(test), output);
|
||||
}
|
||||
}
|
||||
|
||||
// A command whose result does not fit in the SCGI response buffer must be
|
||||
// answered with a fault, not handed to the writer. SCgiTask::receive_write
|
||||
// treats an oversized body as an internal_error, which is not caught by any
|
||||
// RPC handler and terminates the process.
|
||||
void
|
||||
TestJsonrpc::test_response_size_limit() {
|
||||
const std::string request = R"({"jsonrpc": "2.0", "method": "jsonrpc_oversized", "params": [""], "id": 1})";
|
||||
const std::string expected = R"({"error":{"code":-32000,"message":"response size exceeds maximum RPC limit"},"id":1,"jsonrpc":"2.0"})";
|
||||
|
||||
std::string output;
|
||||
m_jsonrpc.process(request.c_str(), request.size(), [&output](const char* c, uint32_t l) { output.append(c, l); return true; });
|
||||
|
||||
CPPUNIT_ASSERT_MESSAGE("response handed to the writer is " + std::to_string(output.size()) +
|
||||
" bytes, over the " + std::to_string(rpc::SCgiTask::max_response_size) + " byte SCGI limit",
|
||||
output.size() <= rpc::SCgiTask::max_response_size);
|
||||
CPPUNIT_ASSERT_EQUAL(expected, output);
|
||||
}
|
||||
|
||||
@@ -8,6 +8,7 @@ class TestJsonrpc : public test_fixture {
|
||||
CPPUNIT_TEST_SUITE(TestJsonrpc);
|
||||
|
||||
CPPUNIT_TEST(test_basics);
|
||||
CPPUNIT_TEST(test_response_size_limit);
|
||||
|
||||
CPPUNIT_TEST_SUITE_END();
|
||||
|
||||
@@ -16,6 +17,7 @@ public:
|
||||
void tearDown();
|
||||
|
||||
void test_basics();
|
||||
void test_response_size_limit();
|
||||
|
||||
private:
|
||||
std::unique_ptr<TestMainThread> m_test_main_thread;
|
||||
|
||||
@@ -8,6 +8,7 @@
|
||||
#include "globals.h"
|
||||
#include "command_helpers.h"
|
||||
#include "rpc/command_map.h"
|
||||
#include "rpc/scgi_task.h"
|
||||
|
||||
CPPUNIT_TEST_SUITE_REGISTRATION(TestXmlrpc);
|
||||
|
||||
@@ -21,6 +22,11 @@ xmlrpc_cmd_test_reflect_string([[maybe_unused]] rpc::target_type t, const std::s
|
||||
return obj;
|
||||
}
|
||||
|
||||
torrent::Object
|
||||
xmlrpc_cmd_test_oversized([[maybe_unused]] rpc::target_type t, [[maybe_unused]] const torrent::Object& obj) {
|
||||
return torrent::Object(std::string(rpc::SCgiTask::max_response_size + (1 << 20), 'a'));
|
||||
}
|
||||
|
||||
void initialize_command_dynamic();
|
||||
|
||||
#if defined(HAVE_XMLRPC_TINYXML2) && !defined(HAVE_XMLRPC_C)
|
||||
@@ -127,6 +133,9 @@ TestXmlrpc::setUp() {
|
||||
|
||||
if (rpc::commands.find("xmlrpc_reflect_string") == rpc::commands.end())
|
||||
CMD2_ANY_STRING("xmlrpc_reflect_string", &xmlrpc_cmd_test_reflect_string);
|
||||
|
||||
if (rpc::commands.find("xmlrpc_oversized") == rpc::commands.end())
|
||||
CMD2_ANY("xmlrpc_oversized", &xmlrpc_cmd_test_oversized);
|
||||
}
|
||||
|
||||
void
|
||||
@@ -165,11 +174,30 @@ TestXmlrpc::test_size_limit() {
|
||||
CPPUNIT_ASSERT_EQUAL(expected, output);
|
||||
}
|
||||
|
||||
// A command whose result does not fit in the SCGI response buffer must be
|
||||
// answered with a fault, not handed to the writer. SCgiTask::receive_write
|
||||
// treats an oversized body as an internal_error, which is not caught by any
|
||||
// RPC handler and terminates the process.
|
||||
void
|
||||
TestXmlrpc::test_response_size_limit() {
|
||||
std::string input = "<?xml version=\"1.0\"?><methodCall><methodName>xmlrpc_oversized</methodName><params><param><value><string></string></value></param></params></methodCall>";
|
||||
std::string expected = "<?xml version=\"1.0\"?><methodResponse><fault><value><struct><member><name>faultCode</name><value><i8>-509</i8></value></member><member><name>faultString</name><value><string>Response size exceeds maximum XML-RPC limit</string></value></member></struct></value></fault></methodResponse>";
|
||||
std::string output;
|
||||
|
||||
m_xmlrpc.process(input.c_str(), input.size(), [&output](const char* c, uint32_t l){ output.append(c, l); return true;});
|
||||
|
||||
CPPUNIT_ASSERT_MESSAGE("response handed to the writer is " + std::to_string(output.size()) +
|
||||
" bytes, over the " + std::to_string(rpc::SCgiTask::max_response_size) + " byte SCGI limit",
|
||||
output.size() <= rpc::SCgiTask::max_response_size);
|
||||
CPPUNIT_ASSERT_EQUAL(expected, output);
|
||||
}
|
||||
|
||||
#else
|
||||
|
||||
void TestXmlrpc::test_invalid_utf8() {}
|
||||
void TestXmlrpc::test_basics() {}
|
||||
void TestXmlrpc::test_size_limit() {}
|
||||
void TestXmlrpc::test_response_size_limit() {}
|
||||
void TestXmlrpc::setUp() {}
|
||||
void TestXmlrpc::tearDown() {}
|
||||
|
||||
|
||||
@@ -10,6 +10,7 @@ class TestXmlrpc : public test_fixture {
|
||||
CPPUNIT_TEST(test_basics);
|
||||
CPPUNIT_TEST(test_invalid_utf8);
|
||||
CPPUNIT_TEST(test_size_limit);
|
||||
CPPUNIT_TEST(test_response_size_limit);
|
||||
|
||||
CPPUNIT_TEST_SUITE_END();
|
||||
|
||||
@@ -22,6 +23,7 @@ public:
|
||||
void test_basics();
|
||||
void test_invalid_utf8();
|
||||
void test_size_limit();
|
||||
void test_response_size_limit();
|
||||
|
||||
private:
|
||||
std::unique_ptr<TestMainThread> m_test_main_thread;
|
||||
|
||||
Reference in New Issue
Block a user