net/http: raise an error when a http2 header frame is malformed
This PR attempts to fix : #31986
diff --git a/src/net/http/h2_bundle.go b/src/net/http/h2_bundle.go
index 0df2763..a2b902a 100644
--- a/src/net/http/h2_bundle.go
+++ b/src/net/http/h2_bundle.go
@@ -2044,6 +2044,10 @@
// sends a frame that is larger than declared with SetMaxReadFrameSize.
var http2ErrFrameTooLarge = errors.New("http2: frame too large")
+// ErrFrameHeadersMalformed is returned from Framer.ReadFrame when the
+// peer sends a http2FrameHeaders frame with a malformed header block.
+var http2ErrFrameHeadersMalformed = errors.New("http2: malformed header frame")
+
// terminalReadFrameError reports whether err is an unrecoverable
// error from ReadFrame and no other frames should be read.
func http2terminalReadFrameError(err error) bool {
@@ -2099,7 +2103,12 @@
fr.debugReadLoggerf("http2: Framer %p: read %v", fr, http2summarizeFrame(f))
}
if fh.Type == http2FrameHeaders && fr.ReadMetaHeaders != nil {
- return fr.readMetaFrame(f.(*http2HeadersFrame))
+ hf, ok := f.(*http2HeadersFrame)
+ if !ok {
+ return nil, http2ErrFrameHeadersMalformed
+ }
+
+ return fr.readMetaFrame(hf)
}
return f, nil
}
| Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. |
I spotted some possible problems with your PR:
1. Are you describing the change in complete sentences with correct punctuation in the commit message body, including ending sentences with periods?
2. Do you have the right bug reference format? For this repo, the format is usually 'Fixes #12345' or 'Updates #12345' at the end of the commit message.
Please address any problems by updating the GitHub PR.
When complete, mark this comment as 'Done' and click the [blue 'Reply' button](https://go.dev/wiki/GerritBot#i-left-a-reply-to-a-comment-in-gerrit-but-no-one-but-me-can-see-it) above. These findings are based on heuristics; if a finding does not apply, briefly reply here saying so.
To update the commit title or commit message body shown here in Gerrit, you must edit the GitHub PR title and PR description (the first comment) in the GitHub web interface using the 'Edit' button or 'Edit' menu entry there. Note: pushing a new commit to the PR will not automatically update the commit message used by Gerrit.
For more details, see:
(In general for Gerrit code reviews, the change author is expected to [log in to Gerrit](https://go-review.googlesource.com/login/) with a Gmail or other Google account and then close out each piece of feedback by marking it as 'Done' if implemented as suggested or otherwise reply to each review comment. See the [Review](https://go.dev/doc/contribute#review) section of the Contributing Guide for details.)
| Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. |
Congratulations on opening your first change. Thank you for your contribution!
Next steps:
A maintainer will review your change and provide feedback. See
https://go.dev/doc/contribute#review for more info and tips to get your
patch through code review.
Most changes in the Go project go through a few rounds of revision. This can be
surprising to people new to the project. The careful, iterative review process
is our way of helping mentor contributors and ensuring that their contributions
have a lasting impact.
During May-July and Nov-Jan the Go project is in a code freeze, during which
little code gets reviewed or merged. If a reviewer responds with a comment like
R=go1.11 or adds a tag like "wait-release", it means that this CL will be
reviewed as part of the next development cycle. See https://go.dev/s/release
for more details.
| Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. |
| Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. |
}I commented on https://go.dev/issue/31986 in more detail, but:
I don't see any way that this type assertion cannot succeed without some form of memory corruption happening. If the frame type is FrameHeaders, then the frame parser can only return a *HeadersFrame.
| Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. |