From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id AD4511FF09B for ; Mon, 28 Sep 2026 09:15:26 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 7CF582174F; Mon, 28 Sep 2026 09:14:58 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dualfroz.com; s=dkim; t=1790314466; h=from:subject:date:message-id:to:mime-version: content-transfer-encoding:in-reply-to:references; bh=NXgjiIGUFgVJjZK8SiSXekzNoU8DB2g79DtzoTEjie4=; b=WZevYJAVgpfkKmqXOlwuD47qY7Voj2XmwUA0kjtkkg8iV/vyCcyrb8gKawuP+TYVun1Mtj AJGd3QtpYPI0wS47PFvhLCerYFt+MwWEvCM1mHfDZLGXgahXQNHSLldkRb9mmrC2Q2fk1G 7AZobJkJi+3BqGiMaOHwSj0AP+pJkCueZ2PAqmysBcLkft+JIUOdIDzBECxUdxz8aJhDza 1Mc6Xs55mB7YAbv1yPOzVtiQnmbnfa1ta3nI+X1H2cV5HUIbv4cD2aCovomcMY3VMZjLKM 35yGUfgR7gNuDXowimbFBfGUnkBJ7ewZBAYkLBbnI+7nx4KCZBx1G6e9VMUdmQ== From: Michal Fox To: pve-devel@lists.proxmox.com Subject: [PATCH http-server 2/2] fix #7389: apiserver: accept unquoted multipart parameter values Date: Fri, 25 Sep 2026 05:34:23 +0000 Message-ID: <20260925053423.7-3-me@dualfroz.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260925053423.7-1-me@dualfroz.com> References: <20260925053423.7-1-me@dualfroz.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.391 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record X-MailFrom: me@dualfroz.com X-Mailman-Rule-Hits: nonmember-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation Message-ID-Hash: 3OIOT52UORQIPMAOYUX25HIIBX6Y7CDI X-Message-ID-Hash: 3OIOT52UORQIPMAOYUX25HIIBX6Y7CDI X-Mailman-Approved-At: Mon, 28 Sep 2026 09:14:42 +0200 X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: In the Content-Disposition header of a multipart/form-data part, the values of the name and filename parameters can be either a token or a quoted-string, see RFC 7578, section 4.2, and RFC 6266. The upload parser only matched the quoted form. Browsers, curl and Python always quote these values, but the .NET HttpClient, and with it PowerShell's Invoke-RestMethod -Form, uses the token form for simple ASCII values, e.g.: Content-Disposition: form-data; name=filename; filename=foo.iso; filename*=utf-8''foo.iso For such requests, neither the 'content' parameter nor the file part got recognized and the upload failed. Accept both forms. For the named parameters, make sure the unquoted name is not just a prefix of a longer one, like 'checksum' for 'checksum-algorithm'. Signed-off-by: Michal Fox --- src/PVE/APIServer/AnyEvent.pm | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/src/PVE/APIServer/AnyEvent.pm b/src/PVE/APIServer/AnyEvent.pm index bb49a8f..f4ee9f2 100644 --- a/src/PVE/APIServer/AnyEvent.pm +++ b/src/PVE/APIServer/AnyEvent.pm @@ -1303,8 +1303,9 @@ sub file_upload_multipart { my $extract_form_disposition = sub { my ($name) = @_; + # parameter values can be a token or a quoted-string, see RFC 7578, section 4.2 if ($hdl->{rbuf} =~ - s/^${delim_re}.*?Content-Disposition: (.*?); name="$name"(.*?${delim_re})/$2/s + s/^${delim_re}.*?Content-Disposition: (.*?); name=(?:"\Q$name\E"|\Q$name\E(?=[;\s]))(.*?${delim_re})/$2/s ) { assert_form_disposition($1); $remove_until_data->($hdl); @@ -1319,13 +1320,14 @@ sub file_upload_multipart { $extract_form_disposition->('checksum'); if ($hdl->{rbuf} =~ - s/^${delim_re}Content-Disposition: (.*?); name="(.*?)"; filename="([^"]+)"//s + s/^${delim_re}Content-Disposition: (.*?); name=(?:"(.*?)"|([^\s;"]+)); filename=(?:"([^"]+)"|([^\s;"]+))//s ) { - assert_form_disposition($1); - die "wrong field name '$2' for file upload, expected 'filename'" - if $2 ne "filename"; + my ($disposition, $field, $filename) = ($1, $2 // $3, $4 // $5); + assert_form_disposition($disposition); + die "wrong field name '$field' for file upload, expected 'filename'" + if $field ne "filename"; $rstate->{phase} = 2; - $rstate->{params}->{filename} = trim($3); + $rstate->{params}->{filename} = trim($filename); $remove_until_data->($hdl); # any remaining multipart "headers" like Content-Type } } -- 2.43.0