Commit graph

38901 commits

Author SHA1 Message Date
Daniel Stenberg
c7cba2fd2d
sigv4: URL encode the user name in the header
- split into sub functions
- add 'aws-sigv4' as keyword for many tests

Verify with test 3222

Reported-by: Trail of Bits
Closes #21923
2026-06-09 13:34:27 +02:00
Viktor Szakats
cb4b3e75e8
smbserver: check impacket presence differently
To silence ruff and GitHub CodeQL warnings.

Closes #21929
2026-06-09 13:24:09 +02:00
Viktor Szakats
056dcd9e71
pytest: use Optional[], adjust whitespace
Reported by GitHub Code Quality

Closes #21928
2026-06-09 13:24:09 +02:00
Viktor Szakats
847aac066d
tidy-up: use uppercase TRUE/FALSE where missing
Keep it only in external API calls and C++ code.

Also:
- curlx/fopen: replace with `!!`.

Spotted by GitHub Code Quality in cf-socket.c.

Closes #21925
2026-06-09 12:52:08 +02:00
Viktor Szakats
9dcc57b801
pytest: add comment to empty except branch
To silence GitHub CodeQL.

Follow-up to 4aa8cc3c4a #21924
2026-06-09 12:33:46 +02:00
Viktor Szakats
bbb226b226
unit1675: fix potential memory leak on dynbuf fail path
Spotted by GitHub Code Quality

Closes #21922
2026-06-09 12:30:16 +02:00
Viktor Szakats
4aa8cc3c4a
pytest: fix remaining code checker warnings
- curl.py: delete commented no-op code.
- certs.py, curl.py: narrow down exceptions to fix:
  Except block handles 'BaseException'
- test_20_websockets: add comment to empty except branch.

Reported by GitHub CodeQL

Closes #21924
2026-06-09 12:30:16 +02:00
Yedaya Katsman
feb609f28b
cf-socket: store errno from do_connect in ctx->error
This fixes a misleading log in verbose mode when ipv6 connectivity isn't
available, presumably also in other cases:

```
* Immediate connect fail for 2a00:1450:4028:806::200e: Network is unreachable
* connect to 2a00:1450:4028:806::200e port 443 from :: port 0 failed: Success
```

Closes #21914
2026-06-09 11:12:14 +02:00
Daniel Stenberg
e66b81a532
cookie: tailmatch the domains for secure override
If a SECURE cookie is set for a sub-domain (`example.com`) and is then
attempted to get set again for more specific part of that domain
(`www.example.com`) without the SECURE property, the second occurance
should not be allowed.

Reported-by: Trail of Bits

Verified by test 3305
Closes #21910
2026-06-09 11:11:07 +02:00
Viktor Szakats
952b04474c
tidy-up: miscellaneous
- badwords: replace stray synonyms with 'null-terminator'.
- tests/FILEFORMAT.md: tidy up feature descriptions.
- printf: replace stray `%i` masks with `%d` for consistency.
- pytest: add comments for empty excepts to try silencing GitHub CodeQL
  warnings.
- tool1394, unit1675: merge nested `if`s.
- dnscache: fix typo in comment.
- fix whitespace, indent and newlines.

Closes #21921
2026-06-09 11:07:55 +02:00
Stefan Eissing
849317ff5c
ws: make pong sending lazy
Do not send PONG frames unless there is sufficient space left in the
websocket send buffer. A server might be lazy in reading our data and
intermediary PONG frames can be skipped by a client (RFC 6455, ch.
5.5.3).

Add test case measuring no real RSS increase on a server blasting with
PING frames.

Closes #21911
2026-06-09 11:05:34 +02:00
Daniel Stenberg
fb9a520873
peer.h: fix typo in comment
Closes #21920
2026-06-09 11:00:01 +02:00
Viktor Szakats
b9b2c0cbb8
docs: returned header size reflects HTTP/1-style format
Ref: #21889

Closes #21912
2026-06-09 10:24:07 +02:00
Viktor Szakats
cb4465bfe6
pytest: close file handles after use (cont.), and tidy-ups
- dante.py, dnsd.py, sshd.py: drop redundant conditions.
  Spotted in sshd by GitHub Code Quality.
- curl.py: comment out `if` to silence CodeQL warning.

Reported by GitHub CodeQL

Follow-up to 8145476d5d #21916

Closes #21917
2026-06-09 10:24:07 +02:00
Yedaya Katsman
7b9d74abf6
resolve: Mention in error that IP address is expected
If you try using a DNS name like connect-to supports it can be confusing that
it is illegal. Also make it a bit more readable

Closes #21913
2026-06-09 09:23:52 +02:00
Daniel Stenberg
a2b943b115
digest: escape control codes too
Since the username is decoded when used and control codes are accepted
in HTTP usernames in general, the username encoding for the Digest auth
needs to percent encode such bytes.

Verified by test 3221

Reported-by: Trail of Bits
Closes #21915
2026-06-09 09:20:47 +02:00
Daniel Stenberg
04afd16076
urlapi: URL decode hostname before IP address normalization
With this, IPv6 addresses that end with '%25' with no following zone id are
considered invalid.

Extend test 1560 to verify

Reported-by: Hem Parekh
Closes #21918
2026-06-09 08:42:19 +02:00
Viktor Szakats
8145476d5d
pytest: close file handles after use, and two minor tidy-ups
Also:
- drop two unreachable return statements.
- test_17_ssl_use: avoid implicit string concatenations in lists.

Reported by GitHub CodeQL

Closes #21916
2026-06-09 02:05:21 +02:00
Viktor Szakats
2dfd265d66
checksrc-all.pl: do not check files multiple times
Restrict `git ls-files` to return `*.[ch]` files within `$dir` only.
Before this patch it returned files in subdirectories too, which did
double work and may have made `checksrc.pl` pick `.checksrc` from the
first such subdirectory, masking the one in `$dir`. (current curl tree
is not affected)

Ref: https://git-scm.com/docs/gitglossary#Documentation/gitglossary.txt-aiddefpathspecapathspec

Follow-up to 33f606cd51 #20439

Closes #21909
2026-06-08 14:59:47 +02:00
alhudz
7de0a7e71a
chunked: reject invalid bytes in trailer
Trailers are delivered to the application as headers via
CLIENTWRITE_TRAILER, but unlike regular response headers they skipped
the verify_header() checks, so a server could smuggle a nul byte (or
stray CR) into a header reaching CURLOPT_HEADERFUNCTION and
curl_easy_header().

Run each assembled trailer line through Curl_verify_header(), the same
validation used for normal headers.

Covered by the new test 2106.

Closes #21896
2026-06-08 13:56:10 +02:00
Stefan Eissing
d69bfad3fa
ssl native_ca_store: always reinit
Add bit `native_ca_store_opt` to keep the setting of
CURLOPT_(PROXY_)SSL_OPTIONS and use that to calculate every easy
transfer if a native CA store shall be used or not.

This avoids `native_ca_store` getting stuck on TRUE after being set
once.

Closes #21902
2026-06-08 13:53:54 +02:00
Stefan Eissing
435fb96dcf
netrc: remember and check filename loaded
Remember the filename of a loaded netrc file to detect changed
configurations in a reused easy handle.

Closes #21903
2026-06-08 13:53:02 +02:00
Daniel Stenberg
e786a4e915
CURLOPT_DOH_URL.md: does not inherit proxy options
Closes #21904
2026-06-08 13:30:39 +02:00
Daniel Stenberg
ff7086874e
_ENVIRONMENT.md. Windows does case insensitive env variables
Closes #21907
2026-06-08 13:29:47 +02:00
renovate[bot]
a89fd1ffd4
GHA: update dependency pizlonator/fil-c to v0.679
Closes #21897
2026-06-08 13:29:09 +02:00
Viktor Szakats
cdce2460b3
runtests: allow skipping tests on torture, use for test 357
Some tests may take a long time in torture mode. Make it possible
to skip individual tests when runtests in running in torture mode.

Also:
- skip test 357 for the reason above.
  Saved 1-3 minutes for the Linux CI torture job, 1-1.5m on Windows.
  No savings on macOS.

Reported-by: Stefan Eissing
Fixes #21873

Closes #21906
2026-06-08 13:26:31 +02:00
Viktor Szakats
39d5cead0d
libssh2: save non-standard port to known_hosts
Reported-by: dyingc on github
Fixes #21863

Closes #21874
2026-06-08 13:26:31 +02:00
Daniel Stenberg
5df33efab4
setopt: claer the "custom" CA booleans when set to NULL
Mark them as custom choices only when pointer is passed, and clear them
again when set to NULL.

Closes #21901
2026-06-08 12:37:35 +02:00
Daniel Stenberg
9b69cfb937
var: use a dedicated pointer for the alloc
As the 'c' pointer might actually get modified before it is time to free
the memory.

Verify in test 2310

Reported-by: Eunsoo Kim
Fixes #21898
Closes #21900
2026-06-08 09:37:06 +02:00
Daniel Stenberg
0618ffe50d
Revert "url: remove ssh_config_matches"
This reverts commit 3e9817cd1b.

The change was incorrect as the check was not for the options the commit
message mentions.

Reported-by: ByteRay on hackerone
Closes #21899
2026-06-08 09:09:58 +02:00
Viktor Szakats
7c34365cce
urlapi: fix memleaks on error in parse_hostname_login()
Detected by GitHub Code Quality

Follow-up to acd82c8bfd #11006
Follow-up to 4183b8fe9a #8049

Closes #21879
2026-06-08 00:42:51 +02:00
Viktor Szakats
9c1ebea359
lib1587: drop redundant includes
Closes #21892
2026-06-08 00:42:51 +02:00
Daniel Stenberg
1a1ec74b0b
RELEASE-NOTES: synced 2026-06-07 23:19:55 +02:00
Daniel Stenberg
e2cb3cc78e
CURLOPT_DISALLOW_USERNAME_IN_URL: is for CURLOPT_URL only
Closes #21890
2026-06-07 23:09:56 +02:00
Daniel Stenberg
7bb7b2c2a4
tool: warn when --ssl and --ftp-ssl-control override each other
and mention this properly in the docs.

Closes #21887
2026-06-07 14:42:13 +02:00
Daniel Stenberg
c4c12843df
CURLOPT_PORT.md: use stronger language
This option should not be used.

Closes #21886
2026-06-07 14:41:04 +02:00
Stefan Eissing
fbcf10ab84
progress: fx CURLINFO time reporting
Whack the times reported for a transfer (see
https://curl.se/libcurl/c/curl_easy_getinfo.html#TIMES) into order for
all variations of up-/download, http/ftp etc. Make sure they are
reported in the documented order.

There is still the *possibility* of PRETRANSFER being longer then
POSTTRANSFER, if a server sends a response before an upload is done.
POST is the time the first response byte is received, and PRE is the
time the last byte was sent by curl.

This may happen with more likelihood on HTTP/2 and 3 for a server
rejected upload. But for successful uploads, the answer will almost over
come afterwards.

Undo the previous twists in lib500.c tests, adjust pytest timeline
checks.

Fixes #21828
Reported-by: BazaarAcc32 on github
Closes #21843
2026-06-07 14:39:10 +02:00
Daniel Stenberg
317bf7e8a8
ftplistparser: clear strings.target if not symlink
When the struct is passed to the CURLOPT_CHUNK_BGN_FUNCTION callback,
clear the pointer if the provided data is not a symlink.

Closes #21884
2026-06-07 00:26:51 +02:00
Daniel Stenberg
38b72f3b56
CURLOPT_PINNEDPUBLICKEY.md: does not apply for other origins
Clarify

Closes #21885
2026-06-07 00:12:02 +02:00
Daniel Stenberg
f7f1666ee2
CURLOPT_CHUNK_BGN_FUNCTION: target is there for symlinks only
Closes #21883
2026-06-07 00:11:14 +02:00
Daniel Stenberg
c3c2cfb65d
http: reject spurious CR bytes in headers
Verified by test 2105

Closes #21882
2026-06-06 22:54:25 +02:00
Vasiliy-Kkk
3b9f0972e2 schannel_verify: simplify CryptQueryObject use
- Specify that the content is base64 encoded, rather than rely on
  auto-detect.

- Remove unnecessary sanity check of the returned content type.

Closes https://github.com/curl/curl/pull/21760
2026-06-06 11:27:34 -04:00
Viktor Szakats
d3e9a815c4
tidy-up: miscellaneous
- fix typos.
- badword: add two new words.
- cpp: drop parentheses from standalone `#if` expressions.
- libssh: vertical-align comment block with others.
- clang-format.

Closes #21880
2026-06-05 16:57:38 +02:00
Viktor Szakats
982e19f231
vquic: drop stray casts for iovec.iov_len
Spotted by GitHub Code Quality

Closes #21877
2026-06-05 16:57:38 +02:00
Viktor Szakats
0c8c6f4fc0
libssh2: replace macro names with non-misspelled alternatives
They are available in libssh2 0.15+.

Closes #21876
2026-06-05 16:57:38 +02:00
Viktor Szakats
1b8f4dba28
tidy-up: drop stray casts for allocated pointers
Closes #21865
2026-06-05 12:24:01 +02:00
Viktor Szakats
cb307544ad
libssh2: sync version check with INTERNALS.md
Follow-up to cf3b9657bc

Closes #21868
2026-06-05 12:06:22 +02:00
Viktor Szakats
5c9ac36e58
libssh2: do not use deprecated macros when unavailable
To support building with `LIBSSH2_NO_DEPRECATED` macro defined, a future
libssh2 that may have dropped these macros.

Ref: https://github.com/libssh2/libssh2/pull/1977

Closes #21867
2026-06-05 12:06:22 +02:00
Viktor Szakats
3c7d136225
libssh2: use non-deprecated libssh2_knownhost_addc()
Supported since libssh2 v1.2.5. Replacing `libssh2_knownhost_add()`,
which was deprecated in that same version.

The new API supports a comment field.

Ref: https://github.com/libssh2/libssh2/pull/1977

Closes #21866
2026-06-05 12:06:22 +02:00
Stefan Eissing
56eca2afb4
quic: count zero length packets against max
With a flood of zero lenght UDP packets to curl, the receive loop might
run longer than intended to. Count such packets against the max to
terminate the loop as intended.

URL: https://hackerone.com/reports/3783438
Reported-by: vectorqueue on hackerone
Closes #21869
2026-06-05 09:14:21 +02:00