sftp: fix range downloads in both SSH backends

When asking for the last N bytes of a file, and that size was larger
than the file size, it would miss the first byte due to a logic error.

The fixed range parser is now made a common function in the file now
renamed to vssh.c (from curl_path.c) - used by both backends.

Unit test 2605 verifies the parser.

Reported-by: Stanislav Fort (Aisle Research)
Closes #19460
This commit is contained in:
Daniel Stenberg 2025-11-11 09:42:16 +01:00
parent 67ef4a34f2
commit c545e10fa7
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
12 changed files with 204 additions and 84 deletions

View file

@ -64,7 +64,7 @@
#include "../multiif.h"
#include "../select.h"
#include "../curlx/warnless.h"
#include "curl_path.h"
#include "vssh.h"
#ifdef HAVE_UNISTD_H
#include <unistd.h>
@ -1329,44 +1329,11 @@ static int myssh_in_SFTP_DOWNLOAD_STAT(struct Curl_easy *data,
return myssh_to_ERROR(data, sshc, CURLE_BAD_DOWNLOAD_RESUME);
}
if(data->state.use_range) {
curl_off_t from, to;
const char *p = data->state.range;
int from_t, to_t;
from_t = curlx_str_number(&p, &from, CURL_OFF_T_MAX);
if(from_t == STRE_OVERFLOW)
return myssh_to_ERROR(data, sshc, CURLE_RANGE_ERROR);
curlx_str_passblanks(&p);
(void)curlx_str_single(&p, '-');
to_t = curlx_str_numblanks(&p, &to);
if(to_t == STRE_OVERFLOW)
return myssh_to_ERROR(data, sshc, CURLE_RANGE_ERROR);
if((to_t == STRE_NO_NUM) || (to >= size)) {
to = size - 1;
}
if(from_t == STRE_NO_NUM) {
/* from is relative to end of file */
from = size - to;
to = size - 1;
}
if(from > size) {
failf(data, "Offset (%" FMT_OFF_T ") was beyond file size (%"
FMT_OFF_T ")", from, size);
return myssh_to_ERROR(data, sshc, CURLE_BAD_DOWNLOAD_RESUME);
}
if(from > to) {
from = to;
size = 0;
}
else {
if((to - from) == CURL_OFF_T_MAX)
return myssh_to_ERROR(data, sshc, CURLE_RANGE_ERROR);
size = to - from + 1;
}
curl_off_t from;
CURLcode result = Curl_ssh_range(data, data->state.range, size,
&from, &size);
if(result)
return myssh_to_ERROR(data, sshc, result);
rc = sftp_seek64(sshc->sftp_file, from);
if(rc)

View file

@ -63,7 +63,7 @@
#include "../select.h"
#include "../curlx/fopen.h"
#include "../curlx/warnless.h"
#include "curl_path.h"
#include "vssh.h"
#include "../curlx/strparse.h"
#include "../curlx/base64.h" /* for base64 encoding/decoding */
@ -1434,42 +1434,11 @@ sftp_download_stat(struct Curl_easy *data,
return CURLE_BAD_DOWNLOAD_RESUME;
}
if(data->state.use_range) {
curl_off_t from, to;
const char *p = data->state.range;
int to_t, from_t;
from_t = curlx_str_number(&p, &from, CURL_OFF_T_MAX);
if(from_t == STRE_OVERFLOW)
return CURLE_RANGE_ERROR;
curlx_str_passblanks(&p);
(void)curlx_str_single(&p, '-');
to_t = curlx_str_numblanks(&p, &to);
if(to_t == STRE_OVERFLOW)
return CURLE_RANGE_ERROR;
if((to_t == STRE_NO_NUM) /* no "to" value given */
|| (to >= size)) {
to = size - 1;
}
if(from_t) {
/* from is relative to end of file */
from = size - to;
to = size - 1;
}
if(from > size) {
failf(data, "Offset (%" FMT_OFF_T ") was beyond file size (%"
FMT_OFF_T ")", from, (curl_off_t)attrs.filesize);
return CURLE_BAD_DOWNLOAD_RESUME;
}
if(from > to) {
from = to;
size = 0;
}
else {
if((to - from) == CURL_OFF_T_MAX)
return CURLE_RANGE_ERROR;
size = to - from + 1;
}
curl_off_t from;
CURLcode result = Curl_ssh_range(data, data->state.range, size,
&from, &size);
if(result)
return result;
libssh2_sftp_seek64(sshc->sftp_handle, (libssh2_uint64_t)from);
}

View file

@ -36,7 +36,7 @@
#include <libssh/sftp.h>
#endif
#include "curl_path.h"
#include "vssh.h"
/* meta key for storing protocol meta at easy handle */
#define CURL_META_SSH_EASY "meta:proto:ssh:easy"

View file

@ -26,9 +26,10 @@
#ifdef USE_SSH
#include "curl_path.h"
#include "vssh.h"
#include <curl/curl.h>
#include "../curlx/strparse.h"
#include "../curl_trc.h"
#include "../curl_memory.h"
#include "../escape.h"
#include "../memdebug.h"
@ -196,4 +197,50 @@ fail:
return CURLE_QUOTE_ERROR;
}
CURLcode Curl_ssh_range(struct Curl_easy *data,
const char *p, curl_off_t filesize,
curl_off_t *startp, curl_off_t *sizep)
{
curl_off_t from, to;
int to_t;
int from_t = curlx_str_number(&p, &from, CURL_OFF_T_MAX);
if(from_t == STRE_OVERFLOW)
return CURLE_RANGE_ERROR;
curlx_str_passblanks(&p);
(void)curlx_str_single(&p, '-');
to_t = curlx_str_numblanks(&p, &to);
if((to_t == STRE_OVERFLOW) || (to_t && from_t) || *p)
return CURLE_RANGE_ERROR;
if(from_t) {
/* no start point given, set from relative to end of file */
if(!to)
/* "-0" is not a fine range */
return CURLE_RANGE_ERROR;
else if(to > filesize)
to = filesize;
from = filesize - to;
to = filesize - 1;
}
else if(from > filesize) {
failf(data, "Offset (%" FMT_OFF_T ") was beyond file size (%"
FMT_OFF_T ")", from, filesize);
return CURLE_RANGE_ERROR;
}
else if((to_t == STRE_NO_NUM) || (to >= filesize))
to = filesize - 1;
if(from > to) {
failf(data, "Bad range: start offset larger than end offset");
return CURLE_RANGE_ERROR;
}
if((to - from) == CURL_OFF_T_MAX)
return CURLE_RANGE_ERROR;
*startp = from;
*sizep = to - from + 1;
return CURLE_OK;
}
#endif /* if SSH is used */

View file

@ -33,4 +33,8 @@ CURLcode Curl_getworkingpath(struct Curl_easy *data,
char **path);
CURLcode Curl_get_pathname(const char **cpp, char **path, const char *homedir);
CURLcode Curl_ssh_range(struct Curl_easy *data,
const char *range, curl_off_t filesize,
curl_off_t *startp, curl_off_t *sizep);
#endif /* HEADER_CURL_PATH_H */