Bug 16128 - lighttpd 1.4.74 contains bug in mod_dirlisting that displays files as directories
Summary: lighttpd 1.4.74 contains bug in mod_dirlisting that displays files as directo...
Status: CLOSED FIXED
Alias: None
Product: Other YP Layers
Classification: Build System, Metadata & Runtime
Component: layers (show other bugs)
Version: 5.0.15
Hardware: All Multiple
: Medium+ normal
Target Milestone: 5.0.16
Assignee: Fred Bacon
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2026-01-09 15:54 UTC by Fred Bacon
Modified: 2026-02-17 20:16 UTC (History)
4 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments
Documented patch for lighttpd dir-listing bug. (1.77 KB, application/mbox)
2026-01-09 15:54 UTC, Fred Bacon
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Fred Bacon 2026-01-09 15:54:01 UTC
Created attachment 5169 [details]
Documented patch for lighttpd dir-listing bug.

The Scarthgap long term support branch ships with version 1.4.74 of lighttpd. Unfortunately, this version contains a known bug that can cause problems when downloading files using the lighttpd web server. The mod_dirlisting software incorrectly displays files in a directory listing as if they are directories. 

If you click on the generated links in a web browser, the contents of the file are displayed correctly. However, if you right click on the link and choose "Save As", the saved file's name is changed to a random string. This is a minor inconvenience since we use the lighttpd web server to access data log files on our instrumentation. Since the original file name encodes a timestamp, downloading multiple files are problematic due to loss of information.

This bug only exists in version 1.4.74 and was fixed in 1.4.75. The upstream bug report, along with the fix, are located at the following link. 

https://redmine.lighttpd.net/issues/3242

Based on the available upstream patch, I have created and tested the attached patch for lighttd in the Scarthgap branch. It passed the QA checks in bitbake. 

Let me know if you need any additional information.
Comment 1 Randy MacLeod 2026-01-15 15:35:01 UTC
Hi Fred,
Are you able to send a patch to the oe-core list ?
Comment 2 Randy MacLeod 2026-01-15 15:35:38 UTC
FYI: https://docs.yoctoproject.org/contributor-guide/index.html
Comment 3 Fred Bacon 2026-01-15 17:00:22 UTC
(In reply to Randy MacLeod from comment #1)
> Hi Fred,
> Are you able to send a patch to the oe-core list ?

Yes, but I'll have to sign up for it first. I attached a patch to the original bug report. I pulled the patch from the upstream provider and added enough context to get it to pass the QA tests on my system. I'll read the contributor guide to see if I missed anything.
Comment 4 Randy MacLeod 2026-01-15 19:15:28 UTC
Thanks for the prompt positive reply Fred.
If you get stuck with our process, please just ask on IRC or here.
Comment 5 Randy MacLeod 2026-01-16 17:25:12 UTC
Moving to Accepted since Fred agreed to work on our process and the bug.
Thanks Fred!
Comment 6 Fred Bacon 2026-01-18 18:10:32 UTC
Since this bug exists only in version 1.4.74, wouldn't it make more sense to move to version 1.4.75 of lighttpd? Is that an acceptable solution?
Comment 7 Yoann Congal 2026-01-18 21:36:17 UTC
(In reply to Fred Bacon from comment #6)
> Since this bug exists only in version 1.4.74, wouldn't it make more sense to
> move to version 1.4.75 of lighttpd? Is that an acceptable solution?

It can be acceptable under the stable patch inclusion policy: There can be no breaking changes nor feature addition, only bugfixes (CVE patches included). Look through the changelog. If acceptable, send an upgrade patch with changelog links and summary in commit message.
Comment 9 Fred Bacon 2026-02-17 20:14:14 UTC
Rebuilt system image and verified that issue has been resolved.
Comment 10 Fred Bacon 2026-02-17 20:16:36 UTC
This issue can be closed. The new patch resolves the issue.