From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id A96261FF09B for ; Mon, 28 Sep 2026 09:15:45 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 369AF21795; Mon, 28 Sep 2026 09:14:59 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dualfroz.com; s=dkim; t=1790314466; h=from:subject:date:message-id:to:mime-version: content-transfer-encoding:in-reply-to:references; bh=Z257DSKgPQMpp89Te6mb9MNJoiHN2QrUKK/TbMGWcA4=; b=vRv7bAI19kipKm+tZVHktt99QLIciIt4L85u5KnTU3gZDCPOuyDcvCMidCN7uenNkcHuMG S+Vgoo6DtBHTBLhniKLFftaGoNjFr+CnDjJ6lZ4Jq6u4F6FHs5YS/tPkPz3kpUU8bparom G9IH6uGwKZ2izYOcNqbBLF7tlJMHqA/828/QXPFWI2Q9y+13YeN8jdgmbwTi6F4laKPOd5 o+c7sPhcrGajLQvh7eHCo7ja2Ced48ovbJVPrES+QIQUlGuGxdlek6aHEFTtKzgy9QBjmY 2JKdF/iHEXim5HW8nye612xi02fY5U8H9/0b/l0oS5jbNN3TTEqgJES2N+Ze8Q== From: Michal Fox To: pve-devel@lists.proxmox.com Subject: [PATCH http-server 1/2] fix #6887: apiserver: accept quoted multipart boundary Date: Fri, 25 Sep 2026 05:34:22 +0000 Message-ID: <20260925053423.7-2-me@dualfroz.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260925053423.7-1-me@dualfroz.com> References: <20260925053423.7-1-me@dualfroz.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.586 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record X-MailFrom: me@dualfroz.com X-Mailman-Rule-Hits: nonmember-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation Message-ID-Hash: C3FXTDKE3U2QBFOBFGEKKAB7G32R7NCG X-Message-ID-Hash: C3FXTDKE3U2QBFOBFGEKKAB7G32R7NCG X-Mailman-Approved-At: Mon, 28 Sep 2026 09:14:43 +0200 X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: RFC 2046 allows the boundary parameter of a multipart Content-Type to be a quoted-string, and even requires it if the boundary contains characters like a colon. RFC 7578 notes that quoting it is often necessary for multipart/form-data. parse_content_type() took everything after the equal sign verbatim, so for 'boundary="foo"' the quotes became part of the boundary. The delimiter lines of the body, correctly written as '--foo', never matched and the upload failed. Strip the quotes of a quoted boundary. Signed-off-by: Michal Fox --- src/PVE/APIServer/AnyEvent.pm | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/src/PVE/APIServer/AnyEvent.pm b/src/PVE/APIServer/AnyEvent.pm index 915d678..bb49a8f 100644 --- a/src/PVE/APIServer/AnyEvent.pm +++ b/src/PVE/APIServer/AnyEvent.pm @@ -1382,8 +1382,9 @@ sub parse_content_type { my ($ct, @params) = split(/\s*[;,]\s*/o, $ctype); foreach my $v (@params) { - if ($v =~ m/^\s*boundary\s*=\s*(\S+?)\s*$/o) { - return wantarray ? ($ct, $1) : $ct; + # the boundary may be given as quoted-string, see RFC 2046, section 5.1.1 + if ($v =~ m/^\s*boundary\s*=\s*(?:"([^"]+)"|(\S+?))\s*$/o) { + return wantarray ? ($ct, $1 // $2) : $ct; } } -- 2.43.0