From: Michal Fox <me@dualfroz.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH http-server 2/2] fix #7389: apiserver: accept unquoted multipart parameter values
Date: Fri, 25 Sep 2026 05:34:23 +0000 [thread overview]
Message-ID: <20260925053423.7-3-me@dualfroz.com> (raw)
In-Reply-To: <20260925053423.7-1-me@dualfroz.com>
In the Content-Disposition header of a multipart/form-data part, the
values of the name and filename parameters can be either a token or a
quoted-string, see RFC 7578, section 4.2, and RFC 6266. The upload
parser only matched the quoted form.
Browsers, curl and Python always quote these values, but the .NET
HttpClient, and with it PowerShell's Invoke-RestMethod -Form, uses the
token form for simple ASCII values, e.g.:
Content-Disposition: form-data; name=filename; filename=foo.iso;
filename*=utf-8''foo.iso
For such requests, neither the 'content' parameter nor the file part
got recognized and the upload failed.
Accept both forms. For the named parameters, make sure the unquoted
name is not just a prefix of a longer one, like 'checksum' for
'checksum-algorithm'.
Signed-off-by: Michal Fox <me@dualfroz.com>
---
src/PVE/APIServer/AnyEvent.pm | 14 ++++++++------
1 file changed, 8 insertions(+), 6 deletions(-)
diff --git a/src/PVE/APIServer/AnyEvent.pm b/src/PVE/APIServer/AnyEvent.pm
index bb49a8f..f4ee9f2 100644
--- a/src/PVE/APIServer/AnyEvent.pm
+++ b/src/PVE/APIServer/AnyEvent.pm
@@ -1303,8 +1303,9 @@ sub file_upload_multipart {
my $extract_form_disposition = sub {
my ($name) = @_;
+ # parameter values can be a token or a quoted-string, see RFC 7578, section 4.2
if ($hdl->{rbuf} =~
- s/^${delim_re}.*?Content-Disposition: (.*?); name="$name"(.*?${delim_re})/$2/s
+ s/^${delim_re}.*?Content-Disposition: (.*?); name=(?:"\Q$name\E"|\Q$name\E(?=[;\s]))(.*?${delim_re})/$2/s
) {
assert_form_disposition($1);
$remove_until_data->($hdl);
@@ -1319,13 +1320,14 @@ sub file_upload_multipart {
$extract_form_disposition->('checksum');
if ($hdl->{rbuf} =~
- s/^${delim_re}Content-Disposition: (.*?); name="(.*?)"; filename="([^"]+)"//s
+ s/^${delim_re}Content-Disposition: (.*?); name=(?:"(.*?)"|([^\s;"]+)); filename=(?:"([^"]+)"|([^\s;"]+))//s
) {
- assert_form_disposition($1);
- die "wrong field name '$2' for file upload, expected 'filename'"
- if $2 ne "filename";
+ my ($disposition, $field, $filename) = ($1, $2 // $3, $4 // $5);
+ assert_form_disposition($disposition);
+ die "wrong field name '$field' for file upload, expected 'filename'"
+ if $field ne "filename";
$rstate->{phase} = 2;
- $rstate->{params}->{filename} = trim($3);
+ $rstate->{params}->{filename} = trim($filename);
$remove_until_data->($hdl); # any remaining multipart "headers" like Content-Type
}
}
--
2.43.0
prev parent reply other threads:[~2026-09-28 7:15 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 5:34 [PATCH http-server 0/2] apiserver: make multipart upload parsing more RFC compliant Michal Fox
2026-09-25 5:34 ` [PATCH http-server 1/2] fix #6887: apiserver: accept quoted multipart boundary Michal Fox
2026-09-25 5:34 ` Michal Fox [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260925053423.7-3-me@dualfroz.com \
--to=me@dualfroz.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox