tree a80572de4c7cf442a67e2af0bb3aa78566e71973
parent 7c6b03efd48b785eb5c9787bfc1bd06043595f4a
author Christopher Faulet <cfaulet@haproxy.com> 1649407461 +0200
committer Christopher Faulet <cfaulet@haproxy.com> 1650956254 +0200

BUG/MEDIUM: http-act: Don't replace URI if path is not found or invalid

For replace-path, replace-pathq and replace-uri actions, we must take care
to not match on the selected element if it is not defined.

regex_exec_match2() function expects to be called with a defined
subject. However, if the request path is invalid or not found, the function
is called with a NULL subject, leading to a crash when compiled without the
PRCE/PCRE2 support.

For instance the following rules crashes HAProxy on a CONNECT request:

  http-request replace-path /short/(.) /\1

This patch must be backported as far as 2.0.

(cherry picked from commit 114e759d5d5e9d93e0c5993f49e3de3ec5dcbf3b)
Signed-off-by: Christopher Faulet <cfaulet@haproxy.com>
(cherry picked from commit 27ef430cd71c42453089747e5ccdfcf1a58efad8)
Signed-off-by: Christopher Faulet <cfaulet@haproxy.com>
