restify / restify/node-restify

Node crashes when URL path contains nullbyte (%00)

Open
#1,864 2 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
10.7k
Forks
975
Avg merge
1d 6h
Merged PRs (30d)
5

Description

  • Used appropriate template for the issue type
  • Searched both open and closed issues for duplicates of this issue
  • Title adequately and concisely reflects the feature or the bug

Restify Version: 8.5.1
Node.js Version: 10.19.0 (which is what you get from sudo apt install nodejs in Ubuntu 20.04)

Expected behaviour

Handle error from fs gracefully

Actual behaviour

Crashes the Node process

Repro case

Having installed restify via npm install restify, assume a very basic project that serves a static web page:

testproject
|
 -> server.js
 -> static
    |
     -> index.html

The server.js looks like this:

const restify = require('restify');
var server;
server = restify.createServer();
server.listen(8080, function() {
	console.log('Server started at %s.', server.url);
});
server.get('/*', restify.plugins.serveStatic({
    directory: './static',
    default: 'index.html'
}));

Accessing localhost:8080 serves the contents of the index.html as expected.

But accessing localhost:8080/%00 (note the URL-encoded nullbyte in the end) results in Node crashing with the following error:

internal/fs/utils.js:453
throw err;
^

TypeError [ERR_INVALID_ARG_VALUE]: The argument 'path' must be a string or Uint8Array without null bytes. Received 'static/\u0000'
at Object.stat (fs.js:825:3)
at serveNormal (/home/cfriedrich/dev/test-restify-nullbyte-bug/node_modules/restify/lib/plugins/static.js:143:12)
at serve (/home/cfriedrich/dev/test-restify-nullbyte-bug/node_modules/restify/lib/plugins/static.js:214:13)
at nextTick (/home/cfriedrich/dev/test-restify-nullbyte-bug/node_modules/restify/lib/chain.js:167:13)
at process._tickCallback (internal/process/next_tick.js:61:11)

Cause

As indicated by the error trace, the cause is the call to fs.stat in static.js:143:

fs.stat(file, function fileStat(err, stats) {

That file argument should be checked for nullbytes before it is fed to fs.stat.

Are you willing and able to fix this?

Probably yes, as adding a condition like

if(file.indexOf("\u0000") != -1)

before the line I quoted above would detect this issue. But I don't know

  1. whether that's how you want to approach this and
  2. what should happen within that if.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with restify/lib/plugins/static.js at the fs.stat call on line 143 and reproduce the failure with a request to /%00 using the supplied server setup. Trace how the static plugin handles the fs error and establish handling that prevents the Node process from crashing; done means the malformed request is handled gracefully.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, node.js
Domain
backend
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.