-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Verifying ContentRange on response from GetObject #3604
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 1 commit
7416dbf
feb6137
e451630
0e3db48
a1f9c72
de95b1e
1e629c7
a0854dd
f0d5a14
2dccd34
6949aff
f13b091
19a91b3
6a1226c
a529ad0
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -825,6 +825,33 @@ namespace Aws | |
| return rangeStream.str(); | ||
| } | ||
|
|
||
| static bool VerifyContentRange(const Aws::String& requestedRange, const Aws::String& responseContentRange) | ||
| { | ||
| if (requestedRange.empty() || responseContentRange.empty()) | ||
| { | ||
| return false; | ||
| } | ||
|
|
||
| if (requestedRange.find("bytes=") != 0) | ||
| { | ||
| return false; | ||
| } | ||
| Aws::String requestRange = requestedRange.substr(6); | ||
|
|
||
| if (responseContentRange.find("bytes ") != 0) | ||
|
||
| { | ||
| return false; | ||
| } | ||
| Aws::String responseRange = responseContentRange.substr(6); | ||
| size_t slashPos = responseRange.find('/'); | ||
| if (slashPos != Aws::String::npos) | ||
| { | ||
| responseRange = responseRange.substr(0, slashPos); | ||
| } | ||
|
|
||
| return requestRange == responseRange; | ||
| } | ||
|
|
||
| void TransferManager::DoSinglePartDownload(const std::shared_ptr<TransferHandle>& handle) | ||
| { | ||
| auto queuedParts = handle->GetQueuedParts(); | ||
|
|
@@ -1091,7 +1118,6 @@ namespace Aws | |
| const std::shared_ptr<const Aws::Client::AsyncCallerContext>& context) | ||
| { | ||
| AWS_UNREFERENCED_PARAM(client); | ||
| AWS_UNREFERENCED_PARAM(request); | ||
|
|
||
| std::shared_ptr<TransferHandleAsyncContext> transferContext = | ||
| std::const_pointer_cast<TransferHandleAsyncContext>(std::static_pointer_cast<const TransferHandleAsyncContext>(context)); | ||
|
|
@@ -1110,6 +1136,37 @@ namespace Aws | |
| } | ||
| else | ||
| { | ||
| if (request.RangeHasBeenSet()) | ||
sbiscigl marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
|
||
| { | ||
| const auto& requestedRange = request.GetRange(); | ||
| const auto& responseContentRange = outcome.GetResult().GetContentRange(); | ||
|
|
||
| if (!responseContentRange.empty()) | ||
|
||
| { | ||
| if (!VerifyContentRange(requestedRange, responseContentRange)) | ||
| { | ||
| Aws::Client::AWSError<Aws::S3::S3Errors> error(Aws::S3::S3Errors::INTERNAL_FAILURE, | ||
| "ContentRangeMismatch", | ||
| "ContentRange in response does not match requested range", | ||
| false); | ||
| AWS_LOGSTREAM_ERROR(CLASS_TAG, "Transfer handle [" << handle->GetId() | ||
| << "] ContentRange mismatch. Requested: [" << requestedRange | ||
| << "] Received: [" << responseContentRange << "]"); | ||
| handle->ChangePartToFailed(partState); | ||
| handle->SetError(error); | ||
| TriggerErrorCallback(handle, error); | ||
| handle->Cancel(); | ||
|
|
||
| if(partState->GetDownloadBuffer()) | ||
| { | ||
| m_bufferManager.Release(partState->GetDownloadBuffer()); | ||
| partState->SetDownloadBuffer(nullptr); | ||
| } | ||
| return; | ||
| } | ||
| } | ||
| } | ||
|
|
||
| if(handle->ShouldContinue()) | ||
| { | ||
| Aws::IOStream* bufferStream = partState->GetDownloadPartStream(); | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
substr(6)seems like a "magic number", can we make this based on a search? a hardcoded index seems like it could break if anything changesThere was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
okay
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I've updated the code to use strlen(requestPrefix) instead of the hardcoded value