Skip to content

Correct handling of unsigned HTTP/2 SETTINGS values - #713

Open
arturobernalg wants to merge 1 commit into
apache:masterfrom
arturobernalg:h2-unsigned-settings
Open

arturobernalg wants to merge 1 commit into
apache:masterfrom
arturobernalg:h2-unsigned-settings

Conversation

@arturobernalg

Copy link
Copy Markdown
Member

RFC 9113 defines SETTINGS values as unsigned 32-bit integers. Values with the high bit set are currently read as negative Java int values and rejected for SETTINGS_HEADER_TABLE_SIZE, SETTINGS_MAX_CONCURRENT_STREAMS, and SETTINGS_MAX_HEADER_LIST_SIZE.

Accept the full unsigned wire range for these settings and bound values above Integer.MAX_VALUE to the internal H2Config representation.

SETTINGS_INITIAL_WINDOW_SIZE is intentionally unchanged: values above 2^31-1 continue to produce FLOW_CONTROL_ERROR. SETTINGS_MAX_FRAME_SIZE also retains its RFC-defined range.

RFC 9113 §2.2, §6.5.1 and §6.5.2.

Treat HEADER_TABLE_SIZE, MAX_CONCURRENT_STREAMS and MAX_HEADER_LIST_SIZE as unsigned values.
Keep RFC-defined validation for INITIAL_WINDOW_SIZE and MAX_FRAME_SIZE unchanged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant