Header limit of 32 KiB, upstream URL checks, build and run scripts
check / check (push) Successful in 1m46s

The request line and headers are now refused above 32 KiB exactly: Go's
server reads 4 KiB past MaxHeaderBytes, so that is set to 28 KiB, and
the tests try exactly 32 KiB and one byte more. SWWAF_UPSTREAM_URL now
needs a host, and a given port must be from 1 to 65535. make build and
make run call script/build and script/run.

Model: opus-5-5
This commit is contained in:
2026-10-03 14:45:44 +00:00
parent 545ce67f44
commit d63465d278
9 changed files with 81 additions and 33 deletions
+7 -4
View File
@@ -15,11 +15,14 @@ import (
// The request line and headers a client may send, and how long a
// kept-open client connection may wait for its next request, are fixed
// rather than settings. The idle time is longer than the 90 seconds after
// which traefik closes a connection it is not using, so traefik never
// sends a request on a connection smallwebwaf is closing.
// rather than settings. The limit on the request line and headers is
// 32 KiB, but Go's server reads 4 KiB past its MaxHeaderBytes before it
// refuses, so MaxHeaderBytes is set 4 KiB lower. The idle time is longer
// than the 90 seconds after which traefik closes a connection it is not
// using, so traefik never sends a request on a connection smallwebwaf is
// closing.
const (
requestHeaderMaxBytes = 32 << 10
requestHeaderMaxBytes = 32<<10 - 4<<10
clientIdleTimeout = 120 * time.Second
)