HSTS: cap the list at 1,000 entries

Avoid never-ending growth.

When adding more entries, it now deletes the first entry in the list,
which is the oldest added entry still held in memory. I decided to avoid
a Least Recently Used concept as I suspect with a list with this many
entries most entries have not been used, and we don't save the timestamp
of recent use anyway.

The net effect might (no matter what) be that the removed entry might
feel a bit "random" in the eyes of the user.

Verify with test 1674

Ref #21183
Closes #21190
This commit is contained in:
Daniel Stenberg 2026-04-01 10:24:06 +02:00
parent 4f3a0ef90d
commit 03a792b186
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
6 changed files with 139 additions and 2 deletions

View file

@ -42,6 +42,7 @@ TESTS_C = \
unit1650.c unit1651.c unit1652.c unit1653.c unit1654.c unit1655.c unit1656.c \
unit1657.c unit1658.c unit1660.c unit1661.c unit1663.c unit1664.c \
unit1666.c unit1667.c unit1668.c unit1669.c \
unit1674.c \
unit1979.c unit1980.c \
unit2600.c unit2601.c unit2602.c unit2603.c unit2604.c unit2605.c \
unit3200.c unit3205.c \

82
tests/unit/unit1674.c Normal file
View file

@ -0,0 +1,82 @@
/***************************************************************************
* _ _ ____ _
* Project ___| | | | _ \| |
* / __| | | | |_) | |
* | (__| |_| | _ <| |___
* \___|\___/|_| \_\_____|
*
* Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
*
* This software is licensed as described in the file COPYING, which
* you should have received as part of this distribution. The terms
* are also available at https://curl.se/docs/copyright.html.
*
* You may opt to use, copy, modify, merge, publish, distribute and/or sell
* copies of the Software, and permit persons to whom the Software is
* furnished to do so, under the terms of the COPYING file.
*
* This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
* KIND, either express or implied.
*
* SPDX-License-Identifier: curl
*
***************************************************************************/
#include "unitcheck.h"
#if !defined(CURL_DISABLE_HTTP) && !defined(CURL_DISABLE_HSTS)
#include "urldata.h"
#include "hsts.h"
/* create a HSTS file with lots of unique host names all using the same
fixed expire time */
static void render_unit1674(const char *file)
{
FILE *f = curlx_fopen(file, FOPEN_WRITETEXT);
size_t i;
if(!f)
return;
for(i = 0; i < (MAX_HSTS_ENTRIES + 5); i++) {
curl_mfprintf(f, "host%zu.readfrom.example \"20211001 04:47:41\"\n", i);
}
curlx_fclose(f);
}
static CURLcode test_unit1674(const char *arg)
{
UNITTEST_BEGIN_SIMPLE
struct hsts *h = Curl_hsts_init();
CURL *easy;
char savename[256];
abort_unless(h, "Curl_hsts_init()");
render_unit1674(arg);
curl_global_init(CURL_GLOBAL_ALL);
easy = curl_easy_init();
if(!easy) {
Curl_hsts_cleanup(&h);
abort_unless(easy, "curl_easy_init()");
}
Curl_hsts_loadfile(easy, h, arg);
curl_mprintf("Number of entries: %zu\n", Curl_llist_count(&h->list));
curl_msnprintf(savename, sizeof(savename), "%s.save", arg);
(void)Curl_hsts_save(easy, h, savename);
Curl_hsts_cleanup(&h);
curl_easy_cleanup(easy);
UNITTEST_END(curl_global_cleanup())
}
#else
static CURLcode test_unit1674(const char *arg)
{
UNITTEST_BEGIN_SIMPLE
puts("nothing to do when HTTP or HSTS are disabled");
UNITTEST_END_SIMPLE
}
#endif