Fix WebDAV status codes for traversal and stale If-Match requests #390

Closed
opened 2026-09-29 04:15:56 +00:00 by kayg · 2 comments
Owner

Evidence from the #339 real-server adversarial round

The encoded traversal probe sent GET /dav/files/{user}/%2e%2e/outside.txt. The server returned 404 with an empty body. Access was denied, but the probe's existing contract expects 400 for this malformed path.

Two concurrent PUT requests used the same current strong If-Match ETag for one file. The server returned [204, 405]: one writer installed its update, and the stale writer did not. The stale request should return 412 Precondition Failed. In code, FileDavError::fs_error() maps Precondition to FsError::Exists, which loses the 412 status.

Please preserve the intended DAV status codes at the HTTP boundary and add real-server regression coverage for both cases. No data loss was observed. These findings do not block the #339 merge; they are follow-up protocol status issues.

## Evidence from the #339 real-server adversarial round The encoded traversal probe sent `GET /dav/files/{user}/%2e%2e/outside.txt`. The server returned 404 with an empty body. Access was denied, but the probe's existing contract expects 400 for this malformed path. Two concurrent PUT requests used the same current strong `If-Match` ETag for one file. The server returned `[204, 405]`: one writer installed its update, and the stale writer did not. The stale request should return 412 Precondition Failed. In code, `FileDavError::fs_error()` maps `Precondition` to `FsError::Exists`, which loses the 412 status. Please preserve the intended DAV status codes at the HTTP boundary and add real-server regression coverage for both cases. No data loss was observed. These findings do not block the #339 merge; they are follow-up protocol status issues.
Author
Owner

Fixed on job/sec-batch in commits 30dea905 and 59dc6d43. The real loopback Files WebDAV probe passed: encoded %2e%2e traversal returned 400, and two PUTs with the same strong If-Match ETag returned one 204 and one 412. The provider's precondition result now survives the dav-server filesystem boundary as a clean 412 response. Probe output: WebDAV scripted probes passed and test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 129 filtered out.

Fixed on job/sec-batch in commits 30dea905 and 59dc6d43. The real loopback Files WebDAV probe passed: encoded `%2e%2e` traversal returned 400, and two PUTs with the same strong If-Match ETag returned one 204 and one 412. The provider's precondition result now survives the dav-server filesystem boundary as a clean 412 response. Probe output: `WebDAV scripted probes passed` and `test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 129 filtered out`.
Author
Owner

Fixed in cd6419620 (origin/dev); covered by file_route_rejects_dot_segments_before_dav_normalization, the tests/adversarial/webdav.py If-Match 412 probe, and precondition_failure_restores_412_after_filesystem_mapping.

Fixed in cd6419620 (origin/dev); covered by file_route_rejects_dot_segments_before_dav_normalization, the tests/adversarial/webdav.py If-Match 412 probe, and precondition_failure_restores_412_after_filesystem_mapping.
kayg closed this issue 2026-10-03 12:48:22 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#390
No description provided.