Skip to content

v1.1.1: Core Security Patches & io_uring Sendfile Fallback

Choose a tag to compare

@varuns2903 varuns2903 released this 09 Aug 17:46
· 555 commits to main since this release

This patch release focuses on resolving critical security vulnerabilities and addressing edge-case bugs in the high-performance io_uring reactor engine. All users running v1.0.0 or v1.1.0 in
production are strongly encouraged to upgrade.

### 🛡️ Security Fixes                                                                                                                                                                            
* **Path Traversal Vulnerability Patched (`StaticFiles.cpp`)**: Resolved a critical security flaw where string-prefix path validation could be tricked (e.g., bypassing `/var/www/public` by     

requesting /var/www/public_secrets). The framework now strictly mandates a trailing slash boundary or an exact directory match before serving static assets.

### 🐛 Bug Fixes                                                                                                                                                                                 
* **Keep-Alive Connection Hangs Resolved (`Connection.cpp`)**: Fixed an issue where the HTTP Keep-Alive pipelining state machine would fail to re-arm the `Proactor` read triggers               

(trigger_read()) after completing a request. Browsers loading pages with multiple assets (HTML, CSS, JS) will no longer experience 10-second idle-timeout hangs.
* RFC-Compliant HTTP Header Parsing (HttpParser.cpp): Replaced the case-sensitive std::unordered_map with a custom CaseInsensitiveHash and CaseInsensitiveEqual implementation. HTTP
headers are now parsed completely case-insensitively across the framework. Furthermore, Connection::check_request_state() now uses case-insensitive boundary searches for Content-Length.
* io_uring sendfile EINVAL Resolution (IoUringProactor.cpp): Addressed an issue where io_uring_prep_splice would fail with -EINVAL when attempting to zero-copy from a static file
to a TCP socket without a kernel pipe buffer. The IoUringProactor now gracefully falls back to non-blocking sendfile(2), wrapped inside an io_uring_prep_poll_add (POLLOUT) operation to
strictly preserve 100% asynchronous, non-blocking execution semantics.

### ⚙️ Upgrade Instructions                                                                                                                                                                      
If you are using CMake, simply pull the latest `v1.1.1` tag and rebuild the `server_core` library:                                                                                               
```bash                                                                                                                                                                                          
git fetch --tags                                                                                                                                                                                 
git checkout v1.1.1                                                                                                                                                                              
cd build && make -j4 && sudo make install