diff --git a/context_test.go b/context_test.go index e8d305e4..6c36bbec 100644 --- a/context_test.go +++ b/context_test.go @@ -3955,3 +3955,62 @@ func BenchmarkGetMapFromFormData(b *testing.B) { }) } } + +func TestWildcardParamUnicodeConcurrency(t *testing.T) { + router := New() + + var mu sync.Mutex + var errs []string + + router.GET("/user/:name", func(c *Context) { + name := c.Param("name") + if name == "" { + mu.Lock() + errs = append(errs, "name param is empty") + mu.Unlock() + } + }) + + router.GET("/files/*filepath", func(c *Context) { + filepath := c.Param("filepath") + if filepath == "" { + mu.Lock() + errs = append(errs, "filepath param is empty") + mu.Unlock() + } + }) + + var wg sync.WaitGroup + paths := []string{ + "/user/जयेश", + "/files/🎉/photo.png", + "/user/こんにちは", + } + + for i := 0; i < 20; i++ { + wg.Add(1) + go func() { + defer wg.Done() + for _, p := range paths { + req, err := http.NewRequest(http.MethodGet, p, nil) + if err != nil { + mu.Lock() + errs = append(errs, "failed to create request: "+err.Error()) + mu.Unlock() + continue + } + w := httptest.NewRecorder() + router.ServeHTTP(w, req) + + if w.Code != http.StatusOK { + mu.Lock() + errs = append(errs, "status code is not 200") + mu.Unlock() + } + } + }() + } + wg.Wait() + + assert.Empty(t, errs) +} diff --git a/tree.go b/tree.go index 580abbaf..f12d3b5c 100644 --- a/tree.go +++ b/tree.go @@ -509,6 +509,11 @@ walk: // Outer loop for walking the tree // Expand slice within preallocated capacity i := len(*value.params) *value.params = (*value.params)[:i+1] + + // Ensure 'end' index lands exactly on a valid UTF-8 rune boundary + for end > 0 && end < len(path) && !utf8.RuneStart(path[end]) { + end-- + } val := path[:end] if unescape { if v, err := url.QueryUnescape(val); err == nil { diff --git a/tree_test.go b/tree_test.go index 23339af4..70cc4f4b 100644 --- a/tree_test.go +++ b/tree_test.go @@ -1111,3 +1111,20 @@ func TestTreeFindCaseInsensitivePathWildcardParamAndStaticChild(t *testing.T) { t.Errorf("Wrong result for '/prefix/something': %s", string(out)) } } + +func TestTreeWildcardParamImproperBoundaryCoverage(t *testing.T) { + tree := &node{} + + // Register a path with a wild named parameter segment + tree.addRoute("/submit/:info", HandlersChain{func(c *Context) {}}) + + // Pass a path containing a multi-byte sequence where a standard byte segment lookup + // drifts directly into the middle of a continuation block. + // This exercises our inner boundary alignment decrement loop. + path := "/submit/जय" + value := tree.getValue(path, &Params{}, nil, false) + + if value.handlers == nil { + t.Errorf("Routing fallback failed on multi-byte parameter verification evaluation.") + } +}