HTTP/2 to origin: bodyless response with a header block over 4 KB fails to parse and is sent to the client as 502/500
I maintainer di solito rispondono entro 2 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 68/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- cpp
- Ambito
- backend-api-design, networking
Direzione di ricerca
Start with Http2Stream::send_headers and HttpSM::state_read_server_response_header, then follow HTTPHdr::parse_resp in HdrTSOnly.cc and MIMEScanner::get. Reproduce the bodyless HTTP/2 302 or 204 with an approximately 8.8 KB header block. Done means the large header parses across blocks and the client receives the origin response instead of a 502 or 500.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
If an HTTP/2 origin sends a bodyless response (HEADERS with END_STREAM) whose header block is larger than one IOBuffer block (about 4 KB), ATS fails to parse it. The client gets a 502 or 500 instead of the origin's response. It mostly shows up on redirects and 204s that carry a large Content-Security-Policy or Set-Cookie.
Cause
Http2Stream::send_headers, which hands a received header to the HttpSM, prints the decoded response header into_receive_bufferone block at a time, adding a block wheneverprint()doesn't finish. A header of more than about 4 KB therefore spans several blocks, and a field can be split at a block boundary.- With
receive_end_streamset on an outbound stream, it then signalsVC_EVENT_EOS, not READ_READY or READ_COMPLETE. HttpSM::state_read_server_response_headerhandles that EOS by parsing witheof = true. It logsServer closed connection while reading response headerat this point, even though nothing closed.HTTPHdr::parse_resp(HdrTSOnly.cc) loops over the reader one block at a time and passes the sameeofflag for every block. When a field is cut at the end of the first block,MIMEScanner::gettreats it as the end of input and returnsParseResult::ERROR(unterminated field).- The result is
handle_server_setup_error, and the client gets an error. squid-style logs show the origin's real status (a 3xx or 204) next to the 5xx sent to the client, witho_bytesstopping just short of the field that crosses the 4 KB boundary.
Observed / reproduction
Reproduced on a 10.0.x build; HdrTSOnly.cc is identical on master.
- An HTTP/2 origin returns
302with no body and a header block of about 8.8 KB, including one longContent-Security-Policyfield. - A GET through ATS: the origin logs a 302, and the client gets a 502 every time, with
o_bytes=202and the request retried once (two attempts). - The same responses had no errors while that origin was reached over HTTP/1.1.
- In production traffic, one bodyless 3xx endpoint failed 150 of 150 requests.
Suggested fix
Either of these, or both:
- In
HTTPHdr::parse_resp, passeofonly for the last block, when there is no further block to read. - In
Http2Stream, write the whole decoded header into one block sized to fit it, so a header from an HTTP/2 frame is never split.
- Lingua principale
- C++
- Stelle
- 2k
- Fork
- 878
- Merge medio
- 3g 16h
- PR unite (30g)
- 91
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di apache/trafficserver
-
Bug HTTP Support
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
apache/trafficserver#13118 ·
I maintainer di solito rispondono entro 2 giorni
-
header_rewrite: rm-destination after set-destination URL crashes traffic_serverForse già presa @moonchen l’ha presa 5 giorni fa. ApertaBug Crash header_rewrite Plugins
apache/trafficserver#13800 · 1 assegnatario ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
apache/trafficserver#13798 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
apache/trafficserver#13784 ·
I maintainer di solito rispondono entro 2 giorni
-
Plugins
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
apache/trafficserver#13774 ·
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di apache/trafficserver
Issue simili
-
Incorrect Link in README.mdForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 95/100
flameshot-org/flameshot#4996 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 64/100
utopia-rise/godot-jvm#1004 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
I maintainer di solito rispondono entro 3 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
I maintainer di solito rispondono entro 1 giorno
-
chore(build): TxCoordinator.cpp uses the deprecated shared_ptr atomic free functionsForse già presa @w5jwp l’ha presa oggi. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 84/100
aethersdr/AetherSDR#6368 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno