forked from apache/pekko-http
-
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Http2 frame type throttle (apache#394)
* parent 38aa25e author PJ Fanning <[email protected]> 1698583210 +0000 committer PJ Fanning <[email protected]> 1702470760 +0100 test for http2 rapid reset Co-Authored-By: Johannes Rudolph <[email protected]> Update Http2ServerSpec.scala add throttle and config Co-Authored-By: Johannes Rudolph <[email protected]> revert code format change Update Http2ServerSettings.scala Update Http2ServerSpec.scala rework test - still needs proper asserts refactor tests scalafmt Create http2-rapid-reset-configs.backwards.excludes refactor test update test add ability to disable throttle Update Http2ServerDisableResetSpec.scala use keepLeft after rapidResetMitigation Update http2-rapid-reset-configs.backwards.excludes uptake sbt-pekko-build use updated plugin refactor sbt-pekko-build 0.1.0 rename configs rename vars * remove imports * Update http2-rapid-reset-configs.backwards.excludes * don't throttle header frames * only throttle reset frames * rename params * Update Http2ServerDisableResetSpec.scala * Rapid reset bench (#2) * Update H2ClientServerBenchmark.scala * don't throttle header frames * only throttle reset frames * rename params * Update H2ClientServerBenchmark.scala * Update Http2ServerDisableResetSpec.scala * disable throttle by default * rename methods * rename configs * extra config * scalafmt * refactor * Update reference.conf * use sets * test frame type alias * scalafmt * Update reference.conf * rename params * Update Http2Blueprint.scala
- Loading branch information
Showing
12 changed files
with
448 additions
and
125 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
22 changes: 22 additions & 0 deletions
22
...c/main/mima-filters/1.0.x.backwards.excludes/http2-rapid-reset-configs.backwards.excludes
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,22 @@ | ||
# Licensed to the Apache Software Foundation (ASF) under one | ||
# or more contributor license agreements. See the NOTICE file | ||
# distributed with this work for additional information | ||
# regarding copyright ownership. The ASF licenses this file | ||
# to you under the Apache License, Version 2.0 (the | ||
# "License"); you may not use this file except in compliance | ||
# with the License. You may obtain a copy of the License at | ||
# | ||
# http://www.apache.org/licenses/LICENSE-2.0 | ||
# | ||
# Unless required by applicable law or agreed to in writing, | ||
# software distributed under the License is distributed on an | ||
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY | ||
# KIND, either express or implied. See the License for the | ||
# specific language governing permissions and limitations | ||
# under the License. | ||
|
||
# New configs added to support throttling HTTP/2 reset frames | ||
ProblemFilters.exclude[ReversedMissingMethodProblem]("org.apache.pekko.http.scaladsl.settings.Http2ServerSettings.frameTypeThrottleFrameTypes") | ||
ProblemFilters.exclude[ReversedMissingMethodProblem]("org.apache.pekko.http.scaladsl.settings.Http2ServerSettings.frameTypeThrottleCost") | ||
ProblemFilters.exclude[ReversedMissingMethodProblem]("org.apache.pekko.http.scaladsl.settings.Http2ServerSettings.frameTypeThrottleBurst") | ||
ProblemFilters.exclude[ReversedMissingMethodProblem]("org.apache.pekko.http.scaladsl.settings.Http2ServerSettings.frameTypeThrottleInterval") |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
71 changes: 71 additions & 0 deletions
71
http-core/src/test/scala/org/apache/pekko/http/impl/engine/http2/Http2BlueprintSpec.scala
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,71 @@ | ||
/* | ||
* Licensed to the Apache Software Foundation (ASF) under one or more | ||
* contributor license agreements. See the NOTICE file distributed with | ||
* this work for additional information regarding copyright ownership. | ||
* The ASF licenses this file to You under the Apache License, Version 2.0 | ||
* (the "License"); you may not use this file except in compliance with | ||
* the License. You may obtain a copy of the License at | ||
* | ||
* http://www.apache.org/licenses/LICENSE-2.0 | ||
* | ||
* Unless required by applicable law or agreed to in writing, software | ||
* distributed under the License is distributed on an "AS IS" BASIS, | ||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
* See the License for the specific language governing permissions and | ||
* limitations under the License. | ||
*/ | ||
|
||
package org.apache.pekko.http.impl.engine.http2 | ||
|
||
import org.apache.pekko | ||
import pekko.http.impl.engine.http2.FrameEvent._ | ||
import pekko.http.impl.engine.http2.Http2Protocol.ErrorCode | ||
import pekko.util.ByteString | ||
import org.scalatest.matchers.should.Matchers | ||
import org.scalatest.wordspec.AnyWordSpec | ||
|
||
class Http2BlueprintSpec extends AnyWordSpec with Matchers { | ||
"Http2Blueprint" should { | ||
"match frame type alias (reset)" in { | ||
Http2Blueprint.frameTypeAliasToFrameTypeName("reset") shouldEqual | ||
Some(RstStreamFrame(0, ErrorCode.PROTOCOL_ERROR).frameTypeName) | ||
} | ||
"match frame type alias (headers)" in { | ||
Http2Blueprint.frameTypeAliasToFrameTypeName("headers") shouldEqual | ||
Some(HeadersFrame(0, true, true, ByteString.empty, None).frameTypeName) | ||
} | ||
"match frame type alias (continuation)" in { | ||
Http2Blueprint.frameTypeAliasToFrameTypeName("continuation") shouldEqual | ||
Some(ContinuationFrame(0, true, ByteString.empty).frameTypeName) | ||
} | ||
"match frame type alias (go-away)" in { | ||
Http2Blueprint.frameTypeAliasToFrameTypeName("go-away") shouldEqual | ||
Some(GoAwayFrame(0, ErrorCode.PROTOCOL_ERROR).frameTypeName) | ||
} | ||
"match frame type alias (priority)" in { | ||
Http2Blueprint.frameTypeAliasToFrameTypeName("priority") shouldEqual | ||
Some(PriorityFrame(0, true, 0, 0).frameTypeName) | ||
} | ||
"match frame type alias (ping)" in { | ||
val rnd = new java.util.Random() | ||
val bytes = new Array[Byte](8) | ||
rnd.nextBytes(bytes) | ||
Http2Blueprint.frameTypeAliasToFrameTypeName("ping") shouldEqual | ||
Some(PingFrame(true, ByteString(bytes)).frameTypeName) | ||
} | ||
"match frame type alias (push-promise)" in { | ||
Http2Blueprint.frameTypeAliasToFrameTypeName("push-promise") shouldEqual | ||
Some(PushPromiseFrame(0, true, 0, ByteString.empty).frameTypeName) | ||
} | ||
"match frame type alias (window-update)" in { | ||
Http2Blueprint.frameTypeAliasToFrameTypeName("window-update") shouldEqual | ||
Some(WindowUpdateFrame(0, 0).frameTypeName) | ||
} | ||
"not match empty frame type alias" in { | ||
Http2Blueprint.frameTypeAliasToFrameTypeName("") shouldEqual None | ||
} | ||
"not match unknown frame type alias" in { | ||
Http2Blueprint.frameTypeAliasToFrameTypeName("unknown") shouldEqual None | ||
} | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
43 changes: 43 additions & 0 deletions
43
...ala/org/apache/pekko/http/impl/engine/http2/Http2ServerDisableFrameTypeThrottleSpec.scala
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,43 @@ | ||
/* | ||
* Licensed to the Apache Software Foundation (ASF) under one or more | ||
* license agreements; and to You under the Apache License, version 2.0: | ||
* | ||
* https://www.apache.org/licenses/LICENSE-2.0 | ||
* | ||
* This file is part of the Apache Pekko project, which was derived from Akka. | ||
*/ | ||
|
||
/* | ||
* Copyright (C) 2018-2022 Lightbend Inc. <https://www.lightbend.com> | ||
*/ | ||
|
||
package org.apache.pekko.http.impl.engine.http2 | ||
|
||
import org.apache.pekko | ||
import pekko.http.impl.engine.http2.Http2Protocol.FrameType | ||
import pekko.http.impl.engine.http2.framing.FrameRenderer | ||
import pekko.util.ByteStringBuilder | ||
|
||
import java.nio.ByteOrder | ||
|
||
/** | ||
* This tests the http2 server throttle support for rapid resets is disabled by default. | ||
*/ | ||
class Http2ServerDisableFrameTypeThrottleSpec extends Http2SpecWithMaterializer(""" | ||
pekko.http.server.remote-address-header = on | ||
pekko.http.server.http2.log-frames = on | ||
""") { | ||
override def failOnSevereMessages: Boolean = true | ||
|
||
"The Http/2 server implementation" should { | ||
"not cancel connection during rapid reset attack (throttle disabled)".inAssertAllStagesStopped( | ||
new TestSetup with RequestResponseProbes { | ||
implicit val bigEndian: ByteOrder = ByteOrder.BIG_ENDIAN | ||
val bb = new ByteStringBuilder | ||
bb.putInt(0) | ||
val rstFrame = FrameRenderer.renderFrame(FrameType.RST_STREAM, ByteFlag.Zero, 1, bb.result()) | ||
val longFrame = Seq.fill(1000)(rstFrame).reduce(_ ++ _) | ||
network.sendBytes(longFrame) | ||
}) | ||
} | ||
} |
Oops, something went wrong.