diff options
| author | Sergey Kandaurov <pluknet@nginx.com> | 2016-07-07 21:03:21 +0300 |
|---|---|---|
| committer | Sergey Kandaurov <pluknet@nginx.com> | 2016-07-07 21:03:21 +0300 |
| commit | 586ef968f98c379153fea0e7e80119b149380dc8 (patch) | |
| tree | 61bb087febe6965c6564b25e74d2f4ededac5cde /src/misc/ngx_cpp_test_module.cpp | |
| parent | 6299f5e9149483251bbbcc8ad26cf29b6109e75c (diff) | |
| download | nginx-586ef968f98c379153fea0e7e80119b149380dc8.tar.gz nginx-586ef968f98c379153fea0e7e80119b149380dc8.tar.bz2 | |
HTTP/2: avoid left-shifting signed integer into the sign bit.
On non-aligned platforms, properly cast argument before left-shifting it in
ngx_http_v2_parse_uint32 that is used with u_char. Otherwise it propagates
to int to hold the value and can step over the sign bit. Usually, on known
compilers, this results in negation. Furthermore, a subsequent store into a
wider type, that is ngx_uint_t on 64-bit platforms, results in sign-extension.
In practice, this can be observed in debug log as a very large exclusive bit
value, when client sent PRIORITY frame with exclusive bit set:
: *14 http2 PRIORITY frame sid:5 on 1 excl:8589934591 weight:17
Found with UndefinedBehaviorSanitizer.
Diffstat (limited to 'src/misc/ngx_cpp_test_module.cpp')
0 files changed, 0 insertions, 0 deletions
