Skip to content

Reject H2 DATA on reserved streams - #709

Merged
arturobernalg merged 1 commit into
apache:masterfrom
arturobernalg:h2-reject-data-on-reserved-stream
Sep 30, 2026
Merged

arturobernalg merged 1 commit into
apache:masterfrom
arturobernalg:h2-reject-data-on-reserved-stream

Conversation

@arturobernalg

Copy link
Copy Markdown
Member

RFC 9113 Section 5.1 restricts the frame types that can be received while a stream is in a reserved state.

For a reserved (remote) stream, receiving a frame other than HEADERS, RST_STREAM, or PRIORITY must be treated as a connection error of type PROTOCOL_ERROR. DATA is therefore not permitted before the reserved stream has been activated by HEADERS.

The current DATA path accepts a reserved stream and passes the payload to the stream handler.

This change rejects DATA frames received on reserved streams with a connection PROTOCOL_ERROR and adds a regression test covering DATA received on a reserved (remote) stream created by PUSH_PROMISE.

RFC 9113 Section 5.1 — Stream States, reserved (remote):
https://www.rfc-editor.org/rfc/rfc9113.html#section-5.1

Report a connection PROTOCOL_ERROR when DATA is received
on a reserved stream.
@arturobernalg
arturobernalg requested a review from ok2c September 29, 2026 12:16

@ok2c ok2c left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@arturobernalg Please cherry-pick to 5.4.x

@arturobernalg
arturobernalg merged commit 814622c into apache:master Sep 30, 2026
12 checks passed
@arturobernalg

Copy link
Copy Markdown
Member Author

@arturobernalg Please cherry-pick to 5.4.x

done

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants