diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 7ebfa399813..dbc88cff171 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -29,17 +29,17 @@ jobs: uses: actions/checkout@v7 - name: Initialize CodeQL - uses: github/codeql-action/init@v4.38.1 + uses: github/codeql-action/init@v4.38.2 with: languages: ${{ matrix.language }} config-file: ./.github/codeql.yml queries: +security-and-quality - name: Autobuild - uses: github/codeql-action/autobuild@v4.38.1 + uses: github/codeql-action/autobuild@v4.38.2 if: ${{ matrix.language == 'python' || matrix.language == 'javascript' }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v4.38.1 + uses: github/codeql-action/analyze@v4.38.2 with: category: "/language:${{ matrix.language }}" diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 3962f573c2e..b98f269a334 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -104,7 +104,7 @@ repos: - id: pyupgrade args: ['--py37-plus'] - repo: https://github.com/PyCQA/flake8 - rev: '7.3.0' + rev: '7.4.1' hooks: - id: flake8 additional_dependencies: diff --git a/CHANGES/13758.bugfix.rst b/CHANGES/13758.bugfix.rst new file mode 100644 index 00000000000..36bb4ffc3e9 --- /dev/null +++ b/CHANGES/13758.bugfix.rst @@ -0,0 +1,6 @@ +Fixed a crash in :meth:`~aiohttp.BodyPartReader.read_chunk` on a body part +with an explicit ``Content-Length: 0``: the part fell through to the +streaming read strategy, whose minimum chunk size assertion then failed for +chunk sizes below the boundary length. Such parts now yield an immediate +empty chunk, like any other part with a known length +-- by :user:`istoolsfox`. diff --git a/CHANGES/13760.bugfix.rst b/CHANGES/13760.bugfix.rst new file mode 120000 index 00000000000..4c97bb5bc7a --- /dev/null +++ b/CHANGES/13760.bugfix.rst @@ -0,0 +1 @@ +13758.bugfix.rst \ No newline at end of file diff --git a/CONTRIBUTORS.txt b/CONTRIBUTORS.txt index e9e72254437..ddbd02c152d 100644 --- a/CONTRIBUTORS.txt +++ b/CONTRIBUTORS.txt @@ -188,6 +188,7 @@ Illia Volochii Ilya Chichak Ilya Gruzinov Ingmar Steen +istoolsfox Ivan Lakovic Ivan Larin J. Nick Koston diff --git a/aiohttp/multipart.py b/aiohttp/multipart.py index 37895666d2d..957b21058d6 100644 --- a/aiohttp/multipart.py +++ b/aiohttp/multipart.py @@ -386,7 +386,7 @@ async def read_chunk(self, size: int = chunk_size) -> bytes: if carry: self._b64_carry = b"" want = max(want, self._boundary_len) - if self._length: + if self._length is not None: fresh = await self._read_chunk_from_length(want) else: fresh = await self._read_chunk_from_stream(want) diff --git a/requirements/constraints.txt b/requirements/constraints.txt index 5a0fff5255a..36697d2bb0a 100644 --- a/requirements/constraints.txt +++ b/requirements/constraints.txt @@ -168,7 +168,7 @@ pip-tools==7.6.1 # via -r requirements/dev.in pkgconfig==1.6.0 # via -r requirements/test-common-base.in -platformdirs==4.11.12 +platformdirs==4.11.14 # via virtualenv pluggy==1.6.0 # via @@ -336,7 +336,7 @@ uvloop==0.22.1 ; platform_system != "Windows" # -r requirements/lint.in valkey==6.1.1 # via -r requirements/lint.in -virtualenv==21.9.1 +virtualenv==21.12.1 # via pre-commit wheel==0.48.0 # via pip-tools diff --git a/requirements/dev.txt b/requirements/dev.txt index e6cfed71ab9..af815b6717e 100644 --- a/requirements/dev.txt +++ b/requirements/dev.txt @@ -165,7 +165,7 @@ pip-tools==7.6.1 # via -r requirements/dev.in pkgconfig==1.6.0 # via -r requirements/test-common-base.in -platformdirs==4.11.12 +platformdirs==4.11.14 # via virtualenv pluggy==1.6.0 # via @@ -326,7 +326,7 @@ uvloop==0.22.1 ; platform_system != "Windows" and implementation_name == "cpytho # -r requirements/lint.in valkey==6.1.1 # via -r requirements/lint.in -virtualenv==21.9.1 +virtualenv==21.12.1 # via pre-commit wheel==0.48.0 # via pip-tools diff --git a/requirements/lint.txt b/requirements/lint.txt index d6b73071913..681fd47cd0d 100644 --- a/requirements/lint.txt +++ b/requirements/lint.txt @@ -86,7 +86,7 @@ packaging==26.3 # via pytest pathspec==1.1.1 # via mypy -platformdirs==4.11.12 +platformdirs==4.11.14 # via virtualenv pluggy==1.6.0 # via pytest @@ -166,7 +166,7 @@ uvloop==0.22.1 ; platform_system != "Windows" # via -r requirements/lint.in valkey==6.1.1 # via -r requirements/lint.in -virtualenv==21.9.1 +virtualenv==21.12.1 # via pre-commit yarl==1.25.1 # via aiohttp diff --git a/tests/test_multipart.py b/tests/test_multipart.py index 184b766f5f4..990175d89cd 100644 --- a/tests/test_multipart.py +++ b/tests/test_multipart.py @@ -206,6 +206,14 @@ async def test_read_chunk_without_content_length(self) -> None: assert c1 + c2 == b"Hello, world!" assert c3 == b"" + async def test_read_chunk_with_zero_content_length(self) -> None: + with Stream(b"\r\n--:--\r\n") as stream: + d = HeadersDictProxy(CIMultiDict({"Content-Length": "0"})) + obj = aiohttp.BodyPartReader(BOUNDARY, d, stream) + result = await obj.read_chunk(4) + assert obj.at_eof() + assert b"" == result + async def test_read_incomplete_chunk(self) -> None: with Stream(b"") as stream: