httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Roy T. Fielding" <field...@kiwi.ics.uci.edu>
Subject Re: cvs commit: apache-1.3/src/main http_config.c http_core.c http_protocol.c
Date Mon, 10 Aug 1998 23:29:34 GMT
>> We just had this discussion yesterday, and now everybody changes
>> their minds?
>
>I don't recall discussing this.  I certainly never said anything either
>way about run-time configurable limits.

Jim suggested it.  Someone else repeated his suggestion.  I said that
was the plan.  Six hours later I fixed it that way.  I was the only person
who ever expressed *any* desire for runtime configurability prior to
this morning.  I was the only person who committed a working version.

>> It doesn't make sense to allow people not compiling the server to
>> change values that they need an understanding of the protocol and
>> source code just to get right.  There is really no advantage to
>> allowing a person to artificially shrink those values, and I am far
>> too paranoid to allow them to fool with actual input buffer sizes.
>> So -1 on that idea for the request-line and fieldsize limits.
>
>-1 on your limit patch then, as it removes functionality from the server
>and does not provide an alternative workaround that is compatible with
>predistributed binaries.

Do you want me to back out all the changes of the weekend?  The only
compile-time functionality I added was the limit on number of request
fields -- the others were already controlled by HUGE_STRING_LENGTH.

....Roy

Mime
View raw message