From d466c1122b89625ef3ccec55d184f0aed8a61541 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sat, 8 Aug 2026 12:50:10 -1000 Subject: Bound the search and cache key a request can ask --- source/cache.c | 15 +++++++++++++++ 1 file changed, 15 insertions(+) (limited to 'source/cache.c') diff --git a/source/cache.c b/source/cache.c index e916728..c6d0427 100644 --- a/source/cache.c +++ b/source/cache.c @@ -75,6 +75,15 @@ static int open_slot(struct cache_slot *slot) return 0; } +/* A key longer than the buffer above can never be read back, so a slot keyed + * on one would never match and every such request would regenerate its page + * while still writing a slot nothing can use. Those requests skip the cache + * instead. */ +static int key_fits_slot(const char *key) +{ + return strlen(key) + 1 <= CACHE_BUFSIZE; +} + /* Close the active cache slot */ static int close_slot(struct cache_slot *slot) { @@ -379,6 +388,12 @@ int cache_process(int size, const char *path, const char *key, int ttl, } if (!key) key = ""; + if (!key_fits_slot(key)) { + cache_log("[cgit] Cache key too long for a slot, caching is " + "disabled for this request\n"); + fn(); + return 0; + } hash = cache_hash_str(key) % size; strbuf_addstr(&filename, path); strbuf_ensure_end(&filename, '/'); -- cgit v2.8.0