[Bug] Request body lost when Upgrade: h2c + Transfer-Encoding: chunked is used
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 42/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- python
- Lĩnh vực
- backend, networking
Hướng nghiên cứu
Callback của parser nằm trong parser.pyx; trước tiên hãy lần theo cb_on_headers_complete và phần xử lý upgrade hiện có, sau đó kiểm tra wrapper parser Python và bài kiểm thử parser có thể tái hiện. Tái hiện yêu cầu h2c được chia thành các chunk và xác minh rằng body vẫn được giữ lại sau một upgrade bị bỏ qua, với các bài kiểm thử parser liên quan đều vượt qua.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Overview
When sending a POST request from a Java RestClient (Spring Boot 3.2+, Java 21) to a FastAPI backend running on Uvicorn + httptools, we encountered a strange issue where the request body was missing.
The request looked like this:
POST /endpoint HTTP/1.1
Host: my-api.com
Upgrade: h2c
Connection: Upgrade, HTTP2-Settings
Transfer-Encoding: chunked
Content-Type: application/json
3\r\nabc\r\n0\r\n\r\n
On the server side, Uvicorn logs showed:
Unsupported upgrade requestNo request bodyInvalid HTTP request received
But when we routed the same request through ngrok or used RestTemplate instead of RestClient, it worked fine.
🔍 Root Cause
After analyzing Uvicorn’s httptools_impl.py and httptools parser behavior, we found this:
Upgrade: h2cis ignored by Uvicorn (as expected).- But internally,
httptoolsstill enters the upgrade state. - Since the upgrade is ignored and the parser is not reset, no body is parsed.
- This violates RFC 7230 §6.7, which allows the server to ignore upgrades and proceed normally.
Proposed Fix
Patch parser.pyx to resume HTTP/1.1 parsing after upgrade is ignored:
cdef int cb_on_headers_complete(cparser.llhttp_t* parser) except -1:
cdef HttpParser pyparser = <HttpParser>parser.data
try:
if parser.upgrade and not pyparser._should_upgrade():
cparser.llhttp_resume_after_upgrade(parser)
pyparser._on_headers_complete()
except BaseException as ex:
pyparser._last_error = ex
return -1
return 0
Also expose this from Python:
def resume_after_upgrade(self):
httptools.llhttp_resume_after_upgrade(self.cparser)
Then frameworks like Uvicorn can call it in:
def on_headers_complete(self):
if self.upgrade and self.upgrade.lower() != b"websocket":
self.parser.resume_after_upgrade()
Reproducible Test
def test_chunked_body_with_ignored_upgrade():
headers = {
"Upgrade": "h2c",
"Connection": "Upgrade",
"Transfer-Encoding": "chunked"
}
body = b"4\r\ntest\r\n0\r\n\r\n"
request = b"POST / HTTP/1.1\r\n" + headers_to_bytes(headers) + b"\r\n" + body
parser = HttpRequestParser(TestProtocol())
parser.feed_data(request)
assert protocol.body == b"test"
Why it matters
This is RFC-compliant behavior that should be supported.
RestClient in Java 21+ sends Upgrade: h2c by default.
Any server not resetting its parser state will lose the body.
This breaks many interop scenarios between Spring Boot and Python ASGI apps.
I'm happy to submit a PR if maintainers are open to it. Thanks for your time and for maintaining this great project!
- Ngôn ngữ chính
- Python
- Star
- 1.3k
- Fork
- 107
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của MagicStack/httptools
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
MagicStack/httptools#136 ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100
MagicStack/httptools#140 · 1 reaction ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
MagicStack/httptools#127 · 2 bình luận · 1 reaction ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 48/100
MagicStack/httptools#126 ·
-
Python 3.10 Armv7 version Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 30/100
MagicStack/httptools#125 ·
Tất cả issue của MagicStack/httptools
Issue tương tự
-
triage/confirmed
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
agentscope-ai/agentscope#2775 ·
-
comp/desktop P3 type/bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
NousResearch/hermes-agent#118866 ·
-
bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
apache/cloudstack#14222 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100