From 19887831698e18149a45a8b9563e8fdcdaaea211 Mon Sep 17 00:00:00 2001 From: Maxim Dounin Date: Fri, 12 Jul 2019 15:34:37 +0300 Subject: Perl: protection against duplicate $r->sleep() calls. Duplicate $r->sleep() and/or $r->has_request_body() calls result in undefined behaviour (in practice, connection leaks were observed). To prevent this, croak() added in appropriate places. --- src/http/modules/perl/nginx.xs | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'src/http/modules') diff --git a/src/http/modules/perl/nginx.xs b/src/http/modules/perl/nginx.xs index 104def1e8..e9db2f7d6 100644 --- a/src/http/modules/perl/nginx.xs +++ b/src/http/modules/perl/nginx.xs @@ -400,6 +400,10 @@ has_request_body(r, next) ngx_http_perl_set_request(r, ctx); + if (ctx->next) { + croak("has_request_body(): another handler active"); + } + if (r->headers_in.content_length_n <= 0 && !r->headers_in.chunked) { XSRETURN_UNDEF; } @@ -1093,6 +1097,10 @@ sleep(r, sleep, next) ngx_http_perl_set_request(r, ctx); + if (ctx->next) { + croak("sleep(): another handler active"); + } + sleep = (ngx_msec_t) SvIV(ST(1)); ngx_log_debug1(NGX_LOG_DEBUG_HTTP, r->connection->log, 0, -- cgit