<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>16128</bug_id>
          
          <creation_ts>2026-01-09 15:54:01 +0000</creation_ts>
          <short_desc>lighttpd 1.4.74 contains bug in mod_dirlisting that displays files as directories</short_desc>
          <delta_ts>2026-02-17 20:16:36 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>Other YP Layers</product>
          <component>layers</component>
          <version>5.0.15</version>
          <rep_platform>All</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>5.0.16</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Fred Bacon">fred.w.bacon</reporter>
          <assigned_to name="Fred Bacon">fred.w.bacon</assigned_to>
          <cc>poky.bs.watcher</cc>
    
    <cc>poky.watcher</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>yoann.congal</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>103794</commentid>
    <comment_count>0</comment_count>
      <attachid>5169</attachid>
    <who name="Fred Bacon">fred.w.bacon</who>
    <bug_when>2026-01-09 15:54:01 +0000</bug_when>
    <thetext>Created attachment 5169
Documented patch for lighttpd dir-listing bug.

The Scarthgap long term support branch ships with version 1.4.74 of lighttpd. Unfortunately, this version contains a known bug that can cause problems when downloading files using the lighttpd web server. The mod_dirlisting software incorrectly displays files in a directory listing as if they are directories. 

If you click on the generated links in a web browser, the contents of the file are displayed correctly. However, if you right click on the link and choose &quot;Save As&quot;, the saved file&apos;s name is changed to a random string. This is a minor inconvenience since we use the lighttpd web server to access data log files on our instrumentation. Since the original file name encodes a timestamp, downloading multiple files are problematic due to loss of information.

This bug only exists in version 1.4.74 and was fixed in 1.4.75. The upstream bug report, along with the fix, are located at the following link. 

https://redmine.lighttpd.net/issues/3242

Based on the available upstream patch, I have created and tested the attached patch for lighttd in the Scarthgap branch. It passed the QA checks in bitbake. 

Let me know if you need any additional information.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103912</commentid>
    <comment_count>1</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2026-01-15 15:35:01 +0000</bug_when>
    <thetext>Hi Fred,
Are you able to send a patch to the oe-core list ?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103913</commentid>
    <comment_count>2</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2026-01-15 15:35:38 +0000</bug_when>
    <thetext>FYI: https://docs.yoctoproject.org/contributor-guide/index.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103936</commentid>
    <comment_count>3</comment_count>
    <who name="Fred Bacon">fred.w.bacon</who>
    <bug_when>2026-01-15 17:00:22 +0000</bug_when>
    <thetext>(In reply to Randy MacLeod from comment #1)
&gt; Hi Fred,
&gt; Are you able to send a patch to the oe-core list ?

Yes, but I&apos;ll have to sign up for it first. I attached a patch to the original bug report. I pulled the patch from the upstream provider and added enough context to get it to pass the QA tests on my system. I&apos;ll read the contributor guide to see if I missed anything.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103939</commentid>
    <comment_count>4</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2026-01-15 19:15:28 +0000</bug_when>
    <thetext>Thanks for the prompt positive reply Fred.
If you get stuck with our process, please just ask on IRC or here.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103949</commentid>
    <comment_count>5</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2026-01-16 17:25:12 +0000</bug_when>
    <thetext>Moving to Accepted since Fred agreed to work on our process and the bug.
Thanks Fred!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103956</commentid>
    <comment_count>6</comment_count>
    <who name="Fred Bacon">fred.w.bacon</who>
    <bug_when>2026-01-18 18:10:32 +0000</bug_when>
    <thetext>Since this bug exists only in version 1.4.74, wouldn&apos;t it make more sense to move to version 1.4.75 of lighttpd? Is that an acceptable solution?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103957</commentid>
    <comment_count>7</comment_count>
    <who name="Yoann Congal">yoann.congal</who>
    <bug_when>2026-01-18 21:36:17 +0000</bug_when>
    <thetext>(In reply to Fred Bacon from comment #6)
&gt; Since this bug exists only in version 1.4.74, wouldn&apos;t it make more sense to
&gt; move to version 1.4.75 of lighttpd? Is that an acceptable solution?

It can be acceptable under the stable patch inclusion policy: There can be no breaking changes nor feature addition, only bugfixes (CVE patches included). Look through the changelog. If acceptable, send an upgrade patch with changelog links and summary in commit message.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>104192</commentid>
    <comment_count>8</comment_count>
    <who name="Yoann Congal">yoann.congal</who>
    <bug_when>2026-02-08 22:49:09 +0000</bug_when>
    <thetext>Patch sent: https://lore.kernel.org/openembedded-core/20260120155748.32482-1-fred.w.bacon@gmail.com/T/#u</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>104336</commentid>
    <comment_count>9</comment_count>
    <who name="Fred Bacon">fred.w.bacon</who>
    <bug_when>2026-02-17 20:14:14 +0000</bug_when>
    <thetext>Rebuilt system image and verified that issue has been resolved.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>104337</commentid>
    <comment_count>10</comment_count>
    <who name="Fred Bacon">fred.w.bacon</who>
    <bug_when>2026-02-17 20:16:36 +0000</bug_when>
    <thetext>This issue can be closed. The new patch resolves the issue.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="0"
              isprivate="0"
          >
            <attachid>5169</attachid>
            <date>2026-01-09 15:54:01 +0000</date>
            <delta_ts>2026-01-09 15:54:01 +0000</delta_ts>
            <desc>Documented patch for lighttpd dir-listing bug.</desc>
            <filename>0001-dir-listing.patch</filename>
            <type>application/mbox</type>
            <size>1812</size>
            <attacher name="Fred Bacon">fred.w.bacon</attacher>
            
              <data encoding="base64">RnJvbSAzZDQwMGNlMDZkY2I5NTBhNjEzNjNmODczMzAzMjRkYjI0NGY0YmFjIE1vbiBTZXAgMTcg
MDA6MDA6MDAgMjAwMQpGcm9tOiBHbGVubiBTdHJhdXNzIDxnc3RyYXVzc0BnbHVlbG9naWMuY29t
PgpEYXRlOiBUaHUsIDI5IEZlYiAyMDI0IDIwOjU5OjU3IC0wNTAwClN1YmplY3Q6IFtQQVRDSF0g
W21vZF9kaXJsaXN0aW5nXSBmaXggc3VmZml4IGRpc3BsYXkgb2YgJy8nIG9uIGZpbGUgKGZpeGVz
CiAjMzI0MikKCmZpeCBpbmNvcnJlY3Qgc3VmZml4IGRpc3BsYXkgb2YgJy8nIG9uIGZpbGVzCgoo
cmVncmVzc2lvbiBpbiBsaWdodHRwZCAxLjQuNzQpCgoodGh4IGd1eSkKClVwc3RyZWFtLVN0YXR1
czogQmFja3BvcnQgWzEuNC43NV0KClJlZmVyZW5jZXM6ClsxXSBodHRwczovL3JlZG1pbmUubGln
aHR0cGQubmV0L2lzc3Vlcy8zMjQyCgpTaWduZWQtb2ZmLWJ5OiBHbGVubiBTdHJhdXNzIDxnc3Ry
YXVzc0BnbHVlbG9naWMuY29tPgotLS0KIHNyYy9tb2RfZGlybGlzdGluZy5jIHwgMTEgKysrKysr
KysrKy0KIDEgZmlsZSBjaGFuZ2VkLCAxMCBpbnNlcnRpb25zKCspLCAxIGRlbGV0aW9uKC0pCgpk
aWZmIC0tZ2l0IGEvc3JjL21vZF9kaXJsaXN0aW5nLmMgYi9zcmMvbW9kX2Rpcmxpc3RpbmcuYwpp
bmRleCBhMzQzMjIxMS4uMjY4NmNkM2UgMTAwNjQ0Ci0tLSBhL3NyYy9tb2RfZGlybGlzdGluZy5j
CisrKyBiL3NyYy9tb2RfZGlybGlzdGluZy5jCkBAIC0xMDIyLDEwICsxMDIyLDE5IEBAIHN0YXRp
YyB2b2lkIGh0dHBfbGlzdF9kaXJlY3RvcnlfZGlybmFtZShidWZmZXIgKiBjb25zdCBvdXQsIGNv
bnN0IGRpcmxzX2VudHJ5X3QKIAlidWZmZXJfYXBwZW5kX3N0cmluZ19sZW4ob3V0LCBDT05TVF9T
VFJfTEVOKCI8L3RkPjx0ZCBjbGFzcz1cInNcIj4tICZuYnNwOzwvdGQ+PHRkIGNsYXNzPVwidFwi
PkRpcmVjdG9yeTwvdGQ+PC90cj5cbiIpKTsKIH0KIAorc3RhdGljIHZvaWQgaHR0cF9saXN0X2Zp
bGVfZW50KGJ1ZmZlciAqIGNvbnN0IG91dCwgY29uc3QgZGlybHNfZW50cnlfdCAqIGNvbnN0IGVu
dCwgY29uc3QgY2hhciAqIGNvbnN0IG5hbWUpIHsKKwlidWZmZXJfYXBwZW5kX3N0cmluZ19lbmNv
ZGVkKG91dCwgbmFtZSwgZW50LT5uYW1lbGVuLCBFTkNPRElOR19SRUxfVVJJX1BBUlQpOworCWJ1
ZmZlcl9hcHBlbmRfc3RyaW5nX2xlbihvdXQsIENPTlNUX1NUUl9MRU4oIlwiPiIpKTsKKwlidWZm
ZXJfYXBwZW5kX3N0cmluZ19lbmNvZGVkKG91dCwgbmFtZSwgZW50LT5uYW1lbGVuLCBFTkNPRElO
R19NSU5JTUFMX1hNTCk7CisJYnVmZmVyX2FwcGVuZF9zdHJpbmdfbGVuKG91dCwgQ09OU1RfU1RS
X0xFTigiPC9hPjwvdGQ+PHRkIGNsYXNzPVwibVwiPiIpKTsKKworCWh0dHBfbGlzdF9kaXJlY3Rv
cnlfbXRpbWUob3V0LCBlbnQpOworfQorCiBzdGF0aWMgdm9pZCBodHRwX2xpc3RfZGlyZWN0b3J5
X2ZpbGVuYW1lKGJ1ZmZlciAqIGNvbnN0IG91dCwgY29uc3QgZGlybHNfZW50cnlfdCAqIGNvbnN0
IGVudCwgY29uc3QgY2hhciAqIGNvbnN0IG5hbWUsIGhhbmRsZXJfY3R4ICogY29uc3QgaGN0eCkg
ewogCWJ1ZmZlcl9hcHBlbmRfc3RyaW5nX2xlbihvdXQsIENPTlNUX1NUUl9MRU4oIjx0cj48dGQg
Y2xhc3M9XCJuXCI+PGEgaHJlZj1cIiIpKTsKIAotCWh0dHBfbGlzdF9kaXJlY3RvcnlfZW50KG91
dCwgZW50LCBuYW1lKTsKKwlodHRwX2xpc3RfZmlsZV9lbnQob3V0LCBlbnQsIG5hbWUpOwogCiAJ
Y29uc3QgYnVmZmVyICpjb250ZW50X3R5cGU7CiAgICNpZiBkZWZpbmVkKEhBVkVfWEFUVFIpIHx8
IGRlZmluZWQoSEFWRV9FWFRBVFRSKSAvKihwYXNzIGZ1bGwgcGF0aCkqLwoK
</data>

          </attachment>
      

    </bug>

</bugzilla>