From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id C955A1FF09B for ; Mon, 28 Sep 2026 09:15:36 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id CF0F62177D; Mon, 28 Sep 2026 09:14:58 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dualfroz.com; s=dkim; t=1790314464; h=from:subject:date:message-id:to:mime-version: content-transfer-encoding; bh=4wKiQV6UNwKHbxB4phMfoWsM0XDWaaAqe/FGryrVXU8=; b=aOWWUF2YDz7RiZdfZqgh3LjEIZ4NtS7uX3jCu+tP8niVLyzc8Umu3WDI6AFy9hMfpNdzc6 oLjCWBcUUAKKyw9IeV1/MiP7ZBMnNURD3Qwftbci6XLxyLz2yPegAEC3tEuaJBiqvjRo0Q orFJcKcYJkSsPkMYx4mLpfrup6BrFHXg/Da3qnJEhXHe8g62dmXImxvTMCzs7Ui2vANrX+ WdxupsSqy5+q6m0XpBBx5XzX0n9O40NxtSGKidjumHBv46Kasgfzo1m9/mYEG//eRL7SAE gZO6FnadyFEQy4nNotpjMbCSCAY3MJApdVCdmPdWymVR6OrkZtNH4CSxI74npA== From: Michal Fox To: pve-devel@lists.proxmox.com Subject: [PATCH http-server 0/2] apiserver: make multipart upload parsing more RFC compliant Date: Fri, 25 Sep 2026 05:34:21 +0000 Message-ID: <20260925053423.7-1-me@dualfroz.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-SPAM-LEVEL: Spam detection results: 0 AWL 1.172 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record X-MailFrom: me@dualfroz.com X-Mailman-Rule-Hits: nonmember-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation Message-ID-Hash: FYKVJ7DFDQN62VAPY24G72SIKMURSI2K X-Message-ID-Hash: FYKVJ7DFDQN62VAPY24G72SIKMURSI2K X-Mailman-Approved-At: Mon, 28 Sep 2026 09:14:42 +0200 X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: two small fixes for the upload parser, both for things the RFCs allow and real clients send: a quoted boundary (#6887) and unquoted name/filename values, which .NET and PowerShell use (#7389). tested by running curl, quoted-boundary and .NET style bodies through file_upload_multipart() with different chunk sizes. curl behaves as before, the other two now parse and the file comes out intact Michal Fox (2): fix #6887: apiserver: accept quoted multipart boundary fix #7389: apiserver: accept unquoted multipart parameter values src/PVE/APIServer/AnyEvent.pm | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) -- 2.43.0