Skip to content

Harden modern port and zone-id parsing - #34

Merged
un33k merged 4 commits into
mainfrom
fix/oversized-port-and-zone
Oct 1, 2026
Merged

un33k merged 4 commits into
mainfrom
fix/oversized-port-and-zone

Conversation

@un33k

@un33k un33k commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Tighten modern port parsing so an oversized numeric port is rejected instead of failing the request.
  • Reject an overly long IPv6 zone id in the modern parser only. Legacy is unchanged.
  • Bump to 4.1.1.

Reported privately by David Gilman. Thank you.

Test plan

  • Full suite, including the new parser cases
  • ruff check on the changed parser and router tests

🚀 Generated with Dojo ⛩️

un33k added 2 commits October 1, 2026 14:33
Reject a port with more than five significant digits before calling int(),
so a long digit string in a request header cannot raise ValueError.
Zero-padded ports stay valid. Cap IPv6 zone ids at 255 characters in the
modern engine only. Legacy is unchanged.
@un33k un33k changed the title Fix modern parser crash on oversized ports Harden modern port and zone-id parsing Oct 1, 2026
@coveralls

coveralls commented Oct 1, 2026 •

Copy link
Copy Markdown

Coverage Status

Coverage is 98.789% — fix/oversized-port-and-zone into main. No base build found for main.

@un33k
un33k merged commit ac5086d into main Oct 1, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants