Header limit of 32 KiB, upstream URL checks, build and run scripts
check / check (push) Successful in 1m46s

The request line and headers are now refused above 32 KiB exactly: Go's
server reads 4 KiB past MaxHeaderBytes, so that is set to 28 KiB, and
the tests try exactly 32 KiB and one byte more. SWWAF_UPSTREAM_URL now
needs a host, and a given port must be from 1 to 65535. make build and
make run call script/build and script/run.

Model: opus-5-5
This commit is contained in:
2026-10-03 14:45:44 +00:00
parent 545ce67f44
commit d63465d278
9 changed files with 81 additions and 33 deletions
+15 -8
View File
@@ -309,7 +309,7 @@ func TestServerHasTheFixedLimits(t *testing.T) {
ProcessLog: requestlog.NewProcessLogger(io.Discard),
})
if server.Addr != ":8080" || server.MaxHeaderBytes != 32<<10 ||
if server.Addr != ":8080" || server.MaxHeaderBytes != 28<<10 ||
server.IdleTimeout != 2*time.Minute || server.ReadHeaderTimeout != time.Minute {
t.Errorf("server listens on %q with header limit %d, idle time %s and "+
"header timeout %s", server.Addr, server.MaxHeaderBytes,
@@ -327,16 +327,23 @@ func TestRefusesHeadersOver32KiB(t *testing.T) {
})
addr, _ := startProxy(t, app.URL, nil)
// size counts every byte of the request: the request line, the
// headers and the blank line that ends them.
const (
start = "GET / HTTP/1.1\r\nHost: app\r\nX-Large: "
end = "\r\n\r\n"
)
for _, tc := range []struct {
headerSize int
want int
size int
want int
}{
{headerSize: 30 << 10, want: http.StatusOK},
{headerSize: 40 << 10, want: http.StatusRequestHeaderFieldsTooLarge},
{size: 32 << 10, want: http.StatusOK},
{size: 32<<10 + 1, want: http.StatusRequestHeaderFieldsTooLarge},
} {
req := newRequest(t, http.MethodGet, addr, "/", http.NoBody)
req.Header.Set("X-Large", strings.Repeat("a", tc.headerSize))
wantStatus(t, do(t, req), tc.want)
conn := dial(t, addr)
send(t, conn, start+strings.Repeat("a", tc.size-len(start)-len(end))+end)
wantStatus(t, readResponse(t, conn), tc.want)
}
if calls.Load() != 1 {