pcapkit.protocols.application.httpv1.HTTP rejects every HTTP/1 message that has no header fields, even though RFC 9112 allows zero (*( field-line CRLF )). Measured on main:
b'GET / HTTP/1.0\r\n\r\n' -> ProtocolError: HTTP: invalid format (httpv1.py:385)
b'HTTP/1.0 200 OK\r\n\r\nbody' -> ProtocolError: HTTP: invalid format (httpv1.py:385)
b'GET / HTTP/1.1\r\nHost: x\r\n\r\n' -> OK
Cause: _read_http_header (httpv1.py:381-385) does header.split(b'\r\n', 1) and treats a missing CRLF as malformed. A message without headers has a header block that is only the start line, so the two-way unpacking fails.
Round trip is broken too. HTTP.make(method='GET', uri='/', http_version='1.1') produces b'GET / HTTP/1.1\r\n\r\n', which the reader then rejects. So HTTPv1(method='GET', uri='/', http_version='1.1') raises.
Fix: treat a header block with no CRLF as a start line with zero fields. Keep the HTTP/2-preface rejection that the comment above the split depends on. Add tests for a headerless request, a headerless response with a body, and the make→read round trip.
Blocked on #1039, an open docstring-only PR (#719 sweep) that edits httpv1.py. Starts once #1039 merges or closes. Found while reviewing #1039.
pcapkit.protocols.application.httpv1.HTTPrejects every HTTP/1 message that has no header fields, even though RFC 9112 allows zero (*( field-line CRLF )). Measured onmain:Cause:
_read_http_header(httpv1.py:381-385) doesheader.split(b'\r\n', 1)and treats a missing CRLF as malformed. A message without headers has a header block that is only the start line, so the two-way unpacking fails.Round trip is broken too.
HTTP.make(method='GET', uri='/', http_version='1.1')producesb'GET / HTTP/1.1\r\n\r\n', which the reader then rejects. SoHTTPv1(method='GET', uri='/', http_version='1.1')raises.Fix: treat a header block with no CRLF as a start line with zero fields. Keep the HTTP/2-preface rejection that the comment above the split depends on. Add tests for a headerless request, a headerless response with a body, and the
make→readround trip.Blocked on #1039, an open docstring-only PR (#719 sweep) that edits
httpv1.py. Starts once #1039 merges or closes. Found while reviewing #1039.