Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve httpd string value fetching efficiency (IDFGH-14524) #15288

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

Adam5Wu
Copy link

@Adam5Wu Adam5Wu commented Jan 26, 2025

Description

  • Avoid using strlcpy() when source is not null-terminated;
  • Also avoid duplicate strlen() when strlcpy() is used.

strlcpy() will implicitly perform a strlen() and report the size of source string as return value [1].
This means calling strlcpy() when source string is no null-terminated (for the intended scope) will incur a high penalty.

For example, query key-values are delimited by &, but calling strlcpy() will always have to traverse to the very end of all query key-values. Similarly for cookies.

Additionally, although not 100% positive, the use of strlcpy() in verify_url() could be unsafe -- as the entire buffer may not be null terminated, which could lead to crash if strlcpy() scans beyond certain memory region boundaries...

[1] https://linux.die.net/man/3/strlcpy

Related

Testing

Just performance improvements, no externally obverable behavioral differences.


Checklist

Before submitting a Pull Request, please ensure the following:

  • 🚨 This PR does not introduce breaking changes.
  • All CI checks (GH Actions) pass.
  • [n/a] Documentation is updated as needed.
  • [n/a] Tests are updated or added as necessary.
  • Code is well-commented, especially in complex areas.
  • Git history is clean — commits are squashed to the minimum necessary.

@CLAassistant
Copy link

CLAassistant commented Jan 26, 2025

CLA assistant check
All committers have signed the CLA.

Copy link

github-actions bot commented Jan 26, 2025

Messages
📖 🎉 Good Job! All checks are passing!

👋 Hello Adam5Wu, we appreciate your contribution to this project!


📘 Please review the project's Contributions Guide for key guidelines on code, documentation, testing, and more.

🖊️ Please also make sure you have read and signed the Contributor License Agreement for this project.

Click to see more instructions ...


This automated output is generated by the PR linter DangerJS, which checks if your Pull Request meets the project's requirements and helps you fix potential issues.

DangerJS is triggered with each push event to a Pull Request and modify the contents of this comment.

Please consider the following:
- Danger mainly focuses on the PR structure and formatting and can't understand the meaning behind your code or changes.
- Danger is not a substitute for human code reviews; it's still important to request a code review from your colleagues.
- To manually retry these Danger checks, please navigate to the Actions tab and re-run last Danger workflow.

Review and merge process you can expect ...


We do welcome contributions in the form of bug reports, feature requests and pull requests via this public GitHub repository.

This GitHub project is public mirror of our internal git repository

1. An internal issue has been created for the PR, we assign it to the relevant engineer.
2. They review the PR and either approve it or ask you for changes or clarifications.
3. Once the GitHub PR is approved, we synchronize it into our internal git repository.
4. In the internal git repository we do the final review, collect approvals from core owners and make sure all the automated tests are passing.
- At this point we may do some adjustments to the proposed change, or extend it by adding tests or documentation.
5. If the change is approved and passes the tests it is merged into the default branch.
5. On next sync from the internal git repository merged change will appear in this public GitHub repository.

Generated by 🚫 dangerJS against 16d9b94

@espressif-bot espressif-bot added the Status: Opened Issue is new label Jan 26, 2025
@github-actions github-actions bot changed the title Improve httpd string value fetching efficiency Improve httpd string value fetching efficiency (IDFGH-14524) Jan 26, 2025
@Adam5Wu Adam5Wu force-pushed the improve/httpd_parse_efficiency branch 2 times, most recently from 0816995 to aa0bfd2 Compare January 26, 2025 20:19
…ency

- Avoid using `strlcpy()` when source is not null-terminated;
- Avoid duplicate `strlen()` when `strlcpy()` is used.
@Adam5Wu Adam5Wu force-pushed the improve/httpd_parse_efficiency branch from af2b7c6 to 16d9b94 Compare January 26, 2025 20:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Status: Opened Issue is new
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants