commit | 1e63c2f08a10a150fa02c50ece89b340ae64efe4 | [log] [tgz] |
---|---|---|
author | Damien Neil <dneil@google.com> | Tue Dec 06 11:57:53 2022 -0800 |
committer | Damien Neil <dneil@google.com> | Tue Dec 06 20:08:15 2022 +0000 |
tree | fd834d61e1417ad2ff60d896a51323c1d4cfd494 | |
parent | 3247b5b4f2e9df1a390dbb76f025ee291a142129 [diff] |
http2: limit canonical header cache by bytes, not entries The canonical header cache is a per-connection cache mapping header keys to their canonicalized form. (For example, "foo-bar" => "Foo-Bar"). We limit the number of entries in the cache to prevent an attacker from consuming unbounded amounts of memory by sending many unique keys, but a small number of very large keys can still consume an unreasonable amount of memory. Track the amount of memory consumed by the cache and limit it based on memory rather than number of entries. Thanks to Josselin Costanzi for reporting this issue. For golang/go#56350 Change-Id: I41db4c9823ed5bf371a9881accddff1268489b16 Reviewed-on: https://go-review.googlesource.com/c/net/+/455635 Reviewed-by: Jenny Rakoczy <jenny@golang.org> Run-TryBot: Damien Neil <dneil@google.com> TryBot-Result: Gopher Robot <gobot@golang.org>
This repository holds supplementary Go networking libraries.
The easiest way to install is to run go get -u golang.org/x/net
. You can also manually git clone the repository to $GOPATH/src/golang.org/x/net
.
This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see https://golang.org/doc/contribute.html. The main issue tracker for the net repository is located at https://github.com/golang/go/issues. Prefix your issue with “x/net:” in the subject line, so it is easy to find.