diff options
| author | srdusr <[email protected]> | 2026-05-15 19:48:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2026-05-15 19:48:00 +0200 |
| commit | dd1621c0077e079e0693f16fe83f17d50338216e (patch) | |
| tree | 411a06d723a16aff1077d5d3e724680436aac85a /internal/proxy/proxy.go | |
| parent | d7d50ae9902d69b2e52d446684b5ab01a5ecab1e (diff) | |
| download | mitmux-dd1621c0077e079e0693f16fe83f17d50338216e.tar.gz mitmux-dd1621c0077e079e0693f16fe83f17d50338216e.zip | |
Stop mislabeling truncated captures as "exact"
internal/proxy/tee.go's teeConn silently drops bytes past
maxCaptureBytes (10 MiB) but callers unconditionally marked the result
"exact" anyway. Confirmed live: proxying a 15 MiB response worked
correctly end-to-end (the client got the full, real 15 MiB - proxying
itself is unbounded, only storage is capped), but the stored history
entry was exactly 10485760 bytes with response_exact=1 still set. For a
tool whose core value proposition is "raw bytes are the source of
truth," a silently truncated capture presented as complete could hide
the very evidence a smuggling or parser-differential investigation is
looking for in the tail of a large body - and give false confidence
that it isn't there.
teeConn.Take() now returns (data, truncated) instead of just data;
truncated is true whenever a Read had to drop bytes because the buffer
was already at cap. Every caller (proxy.go's forward() on both the
request and response side, repeat.go's sendRaw for Repeater/Intruder)
now folds truncated into exact - a truncated capture is never marked
exact - and additionally threads a distinct RequestTruncated/
ResponseTruncated bool through store.Entry, ipc.EntryDetail, and the
TUI, since "truncated" and "reconstructed" (HTTP/2, which never had
wire-exact bytes to begin with) are different situations worth telling
apart: a truncated capture is still real wire bytes, just incomplete,
not a synthesized reconstruction. The detail/repeater views now show
"truncated (hit capture size limit)" specifically rather than lumping
it in with "reconstructed", which would have implied more
transformation happened than actually did.
Schema: history gains request_truncated/response_truncated columns via
the same ALTER-TABLE-and-ignore-duplicate-column pattern already used
for source/flagged, so existing databases upgrade in place.
Verified live: a target server returning a 15 MiB body (over the 10 MiB
cap) proxied through cleanly - full body reached the client - while the
stored entry shows length=10485760, response_exact=0,
response_truncated=1 (previously would have shown response_exact=1);
the TUI's Detail view correctly displays "Response (10485760 bytes,
truncated (hit capture size limit))" instead of "exact".
go build/vet/gofmt/test/mod tidy all clean.
Diffstat (limited to 'internal/proxy/proxy.go')
| -rw-r--r-- | internal/proxy/proxy.go | 43 |
1 files changed, 23 insertions, 20 deletions
diff --git a/internal/proxy/proxy.go b/internal/proxy/proxy.go index 82328db..08b8551 100644 --- a/internal/proxy/proxy.go +++ b/internal/proxy/proxy.go @@ -383,8 +383,8 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr started := time.Now() conn, negotiated, dialErr := dial(r.Context()) if dialErr != nil { - reqRaw, reqExact := captureRequest(r, clientTee, reqBodyCap) - s.record(started, time.Since(started), scheme, hostname, r, reqRaw, reqExact, nil, false, 0, dialErr.Error()) + reqRaw, reqExact, reqTrunc := captureRequest(r, clientTee, reqBodyCap) + s.record(started, time.Since(started), scheme, hostname, r, reqRaw, reqExact, reqTrunc, nil, false, false, 0, dialErr.Error()) http.Error(w, dialErr.Error(), http.StatusBadGateway) return } @@ -412,10 +412,10 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr } duration := time.Since(started) - reqRaw, reqExact := captureRequest(r, clientTee, reqBodyCap) + reqRaw, reqExact, reqTrunc := captureRequest(r, clientTee, reqBodyCap) if err != nil { - s.record(started, duration, scheme, hostname, r, reqRaw, reqExact, nil, false, 0, err.Error()) + s.record(started, duration, scheme, hostname, r, reqRaw, reqExact, reqTrunc, nil, false, false, 0, err.Error()) http.Error(w, err.Error(), http.StatusBadGateway) return } @@ -448,14 +448,15 @@ func (s *Server) forward(dial dialer, scheme, hostname string, w http.ResponseWr io.Copy(w, resp.Body) var respRaw []byte - var respExact bool + var respExact, respTrunc bool if upstreamTee != nil { - respRaw, respExact = upstreamTee.Take(), true + respRaw, respTrunc = upstreamTee.Take() + respExact = !respTrunc } else { respRaw, respExact = captureResponse(resp, respBodyCap) } - s.record(started, duration, scheme, hostname, r, reqRaw, reqExact, respRaw, respExact, resp.StatusCode, "") + s.record(started, duration, scheme, hostname, r, reqRaw, reqExact, reqTrunc, respRaw, respExact, respTrunc, resp.StatusCode, "") } // enabledRules fetches the current enabled match-and-replace rules for @@ -471,24 +472,26 @@ func (s *Server) enabledRules(scope string) ([]rules.Rule, error) { // record stores one history entry and notifies OnEntry. func (s *Server) record(started time.Time, duration time.Duration, scheme, host string, r *http.Request, - reqRaw []byte, reqExact bool, respRaw []byte, respExact bool, status int, errMsg string) { + reqRaw []byte, reqExact, reqTruncated bool, respRaw []byte, respExact, respTruncated bool, status int, errMsg string) { if s.store == nil { return } e := &store.Entry{ - StartedAt: started, - Duration: duration, - Method: r.Method, - Scheme: scheme, - Host: host, - Path: r.URL.Path, - StatusCode: status, - RequestRaw: reqRaw, - ResponseRaw: respRaw, - RequestExact: reqExact, - ResponseExact: respExact, - Error: errMsg, + StartedAt: started, + Duration: duration, + Method: r.Method, + Scheme: scheme, + Host: host, + Path: r.URL.Path, + StatusCode: status, + RequestRaw: reqRaw, + ResponseRaw: respRaw, + RequestExact: reqExact, + ResponseExact: respExact, + RequestTruncated: reqTruncated, + ResponseTruncated: respTruncated, + Error: errMsg, } id, err := s.store.Insert(e) if err != nil { |