Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1 | // Copyright 2014 The Go Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style |
| 3 | // license that can be found in the LICENSE file. |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 4 | |
Brad Fitzpatrick | cf89663 | 2014-12-09 07:15:26 +1100 | [diff] [blame] | 5 | // TODO: turn off the serve goroutine when idle, so |
| 6 | // an idle conn only has the readFrames goroutine active. (which could |
| 7 | // also be optimized probably to pin less memory in crypto/tls). This |
| 8 | // would involve tracking when the serve goroutine is active (atomic |
| 9 | // int32 read/CAS probably?) and starting it up when frames arrive, |
| 10 | // and shutting it down when all handlers exit. the occasional PING |
| 11 | // packets could use time.AfterFunc to call sc.wakeStartServeLoop() |
| 12 | // (which is a no-op if already running) and then queue the PING write |
| 13 | // as normal. The serve loop would then exit in most cases (if no |
| 14 | // Handlers running) and not be woken up again until the PING packet |
| 15 | // returns. |
| 16 | |
| 17 | // TODO (maybe): add a mechanism for Handlers to going into |
| 18 | // half-closed-local mode (rw.(io.Closer) test?) but not exit their |
| 19 | // handler, and continue to be able to read from the |
| 20 | // Request.Body. This would be a somewhat semantic change from HTTP/1 |
| 21 | // (or at least what we expose in net/http), so I'd probably want to |
| 22 | // add it there too. For now, this package says that returning from |
| 23 | // the Handler ServeHTTP function means you're both done reading and |
| 24 | // done writing, without a way to stop just one or the other. |
| 25 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 26 | package http2 |
| 27 | |
| 28 | import ( |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 29 | "bufio" |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 30 | "bytes" |
| 31 | "crypto/tls" |
| 32 | "errors" |
| 33 | "fmt" |
| 34 | "io" |
| 35 | "log" |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 36 | "math" |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 37 | "net" |
| 38 | "net/http" |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 39 | "net/textproto" |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 40 | "net/url" |
Brad Fitzpatrick | eb066e3 | 2016-01-26 18:31:02 +0000 | [diff] [blame] | 41 | "os" |
| 42 | "reflect" |
Brad Fitzpatrick | 74bd44b | 2015-12-15 00:47:28 +0000 | [diff] [blame] | 43 | "runtime" |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 44 | "strconv" |
| 45 | "strings" |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 46 | "sync" |
Brad Fitzpatrick | 9584203 | 2014-11-15 09:47:42 -0800 | [diff] [blame] | 47 | "time" |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 48 | |
Brad Fitzpatrick | ae54c55 | 2015-09-24 09:19:02 +0200 | [diff] [blame] | 49 | "golang.org/x/net/http2/hpack" |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 50 | ) |
| 51 | |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 52 | const ( |
Brad Fitzpatrick | 9581fe1 | 2014-11-28 13:51:46 -0800 | [diff] [blame] | 53 | prefaceTimeout = 10 * time.Second |
Brad Fitzpatrick | 4e3c922 | 2014-11-22 17:35:09 -0800 | [diff] [blame] | 54 | firstSettingsTimeout = 2 * time.Second // should be in-flight with preface anyway |
| 55 | handlerChunkWriteSize = 4 << 10 |
Brad Fitzpatrick | 068d35d | 2014-12-09 07:10:31 +1100 | [diff] [blame] | 56 | defaultMaxStreams = 250 // TODO: make this 100 as the GFE seems to? |
Brad Fitzpatrick | 4e3c922 | 2014-11-22 17:35:09 -0800 | [diff] [blame] | 57 | ) |
| 58 | |
| 59 | var ( |
| 60 | errClientDisconnected = errors.New("client disconnected") |
| 61 | errClosedBody = errors.New("body closed by handler") |
Brad Fitzpatrick | b7f5d98 | 2015-10-26 13:59:20 -0500 | [diff] [blame] | 62 | errHandlerComplete = errors.New("http2: request body closed due to handler exiting") |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 63 | errStreamClosed = errors.New("http2: stream closed") |
Brad Fitzpatrick | 4e3c922 | 2014-11-22 17:35:09 -0800 | [diff] [blame] | 64 | ) |
| 65 | |
| 66 | var responseWriterStatePool = sync.Pool{ |
| 67 | New: func() interface{} { |
| 68 | rws := &responseWriterState{} |
| 69 | rws.bw = bufio.NewWriterSize(chunkWriter{rws}, handlerChunkWriteSize) |
| 70 | return rws |
| 71 | }, |
| 72 | } |
| 73 | |
| 74 | // Test hooks. |
| 75 | var ( |
| 76 | testHookOnConn func() |
| 77 | testHookGetServerConn func(*serverConn) |
Brad Fitzpatrick | f3a6d9a | 2014-12-08 07:53:36 -0800 | [diff] [blame] | 78 | testHookOnPanicMu *sync.Mutex // nil except in tests |
Brad Fitzpatrick | 996adcb | 2014-12-08 01:08:19 -0800 | [diff] [blame] | 79 | testHookOnPanic func(sc *serverConn, panicVal interface{}) (rePanic bool) |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 80 | ) |
| 81 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 82 | // Server is an HTTP/2 server. |
| 83 | type Server struct { |
Brad Fitzpatrick | 6ec1731 | 2014-11-23 10:07:07 -0800 | [diff] [blame] | 84 | // MaxHandlers limits the number of http.Handler ServeHTTP goroutines |
| 85 | // which may run at a time over all connections. |
| 86 | // Negative or zero no limit. |
| 87 | // TODO: implement |
| 88 | MaxHandlers int |
| 89 | |
| 90 | // MaxConcurrentStreams optionally specifies the number of |
| 91 | // concurrent streams that each client may have open at a |
| 92 | // time. This is unrelated to the number of http.Handler goroutines |
| 93 | // which may be active globally, which is MaxHandlers. |
| 94 | // If zero, MaxConcurrentStreams defaults to at least 100, per |
| 95 | // the HTTP/2 spec's recommendations. |
| 96 | MaxConcurrentStreams uint32 |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 97 | |
| 98 | // MaxReadFrameSize optionally specifies the largest frame |
| 99 | // this server is willing to read. A valid value is between |
Brad Fitzpatrick | 6ec1731 | 2014-11-23 10:07:07 -0800 | [diff] [blame] | 100 | // 16k and 16M, inclusive. If zero or otherwise invalid, a |
| 101 | // default value is used. |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 102 | MaxReadFrameSize uint32 |
Brad Fitzpatrick | e4cd9ad | 2015-01-17 18:03:57 -0800 | [diff] [blame] | 103 | |
| 104 | // PermitProhibitedCipherSuites, if true, permits the use of |
| 105 | // cipher suites prohibited by the HTTP/2 spec. |
| 106 | PermitProhibitedCipherSuites bool |
Brad Fitzpatrick | c33d378 | 2016-10-22 11:37:19 -0700 | [diff] [blame] | 107 | |
| 108 | // IdleTimeout specifies how long until idle clients should be |
| 109 | // closed with a GOAWAY frame. PING frames are not considered |
| 110 | // activity for the purposes of IdleTimeout. |
| 111 | IdleTimeout time.Duration |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 112 | |
Tom Bergan | 906cda9 | 2017-02-18 12:36:51 -0800 | [diff] [blame] | 113 | // MaxUploadBufferPerConnection is the size of the initial flow |
| 114 | // control window for each connections. The HTTP/2 spec does not |
| 115 | // allow this to be smaller than 65535 or larger than 2^32-1. |
| 116 | // If the value is outside this range, a default value will be |
| 117 | // used instead. |
| 118 | MaxUploadBufferPerConnection int32 |
| 119 | |
| 120 | // MaxUploadBufferPerStream is the size of the initial flow control |
| 121 | // window for each stream. The HTTP/2 spec does not allow this to |
| 122 | // be larger than 2^32-1. If the value is zero or larger than the |
| 123 | // maximum, a default value will be used instead. |
| 124 | MaxUploadBufferPerStream int32 |
| 125 | |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 126 | // NewWriteScheduler constructs a write scheduler for a connection. |
| 127 | // If nil, a default scheduler is chosen. |
| 128 | NewWriteScheduler func() WriteScheduler |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 129 | |
| 130 | // Internal state. This is a pointer (rather than embedded directly) |
| 131 | // so that we don't embed a Mutex in this struct, which will make the |
| 132 | // struct non-copyable, which might break some callers. |
| 133 | state *serverInternalState |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 134 | } |
| 135 | |
Tom Bergan | 906cda9 | 2017-02-18 12:36:51 -0800 | [diff] [blame] | 136 | func (s *Server) initialConnRecvWindowSize() int32 { |
| 137 | if s.MaxUploadBufferPerConnection > initialWindowSize { |
| 138 | return s.MaxUploadBufferPerConnection |
| 139 | } |
| 140 | return 1 << 20 |
| 141 | } |
| 142 | |
| 143 | func (s *Server) initialStreamRecvWindowSize() int32 { |
| 144 | if s.MaxUploadBufferPerStream > 0 { |
| 145 | return s.MaxUploadBufferPerStream |
| 146 | } |
| 147 | return 1 << 20 |
| 148 | } |
| 149 | |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 150 | func (s *Server) maxReadFrameSize() uint32 { |
| 151 | if v := s.MaxReadFrameSize; v >= minMaxFrameSize && v <= maxFrameSize { |
| 152 | return v |
| 153 | } |
| 154 | return defaultMaxReadFrameSize |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 155 | } |
| 156 | |
Brad Fitzpatrick | 6ec1731 | 2014-11-23 10:07:07 -0800 | [diff] [blame] | 157 | func (s *Server) maxConcurrentStreams() uint32 { |
| 158 | if v := s.MaxConcurrentStreams; v > 0 { |
| 159 | return v |
| 160 | } |
| 161 | return defaultMaxStreams |
| 162 | } |
| 163 | |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 164 | type serverInternalState struct { |
| 165 | mu sync.Mutex |
| 166 | activeConns map[*serverConn]struct{} |
| 167 | } |
| 168 | |
| 169 | func (s *serverInternalState) registerConn(sc *serverConn) { |
| 170 | if s == nil { |
| 171 | return // if the Server was used without calling ConfigureServer |
| 172 | } |
| 173 | s.mu.Lock() |
| 174 | s.activeConns[sc] = struct{}{} |
| 175 | s.mu.Unlock() |
| 176 | } |
| 177 | |
| 178 | func (s *serverInternalState) unregisterConn(sc *serverConn) { |
| 179 | if s == nil { |
| 180 | return // if the Server was used without calling ConfigureServer |
| 181 | } |
| 182 | s.mu.Lock() |
| 183 | delete(s.activeConns, sc) |
| 184 | s.mu.Unlock() |
| 185 | } |
| 186 | |
| 187 | func (s *serverInternalState) startGracefulShutdown() { |
| 188 | if s == nil { |
| 189 | return // if the Server was used without calling ConfigureServer |
| 190 | } |
| 191 | s.mu.Lock() |
| 192 | for sc := range s.activeConns { |
| 193 | sc.startGracefulShutdown() |
| 194 | } |
| 195 | s.mu.Unlock() |
| 196 | } |
| 197 | |
Brad Fitzpatrick | b5469d2 | 2014-11-13 12:17:52 -0800 | [diff] [blame] | 198 | // ConfigureServer adds HTTP/2 support to a net/http Server. |
| 199 | // |
| 200 | // The configuration conf may be nil. |
| 201 | // |
| 202 | // ConfigureServer must be called before s begins serving. |
Brad Fitzpatrick | 42ad508 | 2015-10-15 01:02:25 +0000 | [diff] [blame] | 203 | func ConfigureServer(s *http.Server, conf *Server) error { |
Brad Fitzpatrick | b336a97 | 2016-10-27 19:58:04 +0000 | [diff] [blame] | 204 | if s == nil { |
| 205 | panic("nil *http.Server") |
| 206 | } |
Brad Fitzpatrick | b5469d2 | 2014-11-13 12:17:52 -0800 | [diff] [blame] | 207 | if conf == nil { |
| 208 | conf = new(Server) |
| 209 | } |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 210 | conf.state = &serverInternalState{activeConns: make(map[*serverConn]struct{})} |
Brad Fitzpatrick | 76c1a11 | 2016-10-29 19:01:05 +0000 | [diff] [blame] | 211 | if err := configureServer18(s, conf); err != nil { |
| 212 | return err |
Brad Fitzpatrick | b336a97 | 2016-10-27 19:58:04 +0000 | [diff] [blame] | 213 | } |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 214 | if err := configureServer19(s, conf); err != nil { |
| 215 | return err |
| 216 | } |
Brad Fitzpatrick | 42ad508 | 2015-10-15 01:02:25 +0000 | [diff] [blame] | 217 | |
Brad Fitzpatrick | b5469d2 | 2014-11-13 12:17:52 -0800 | [diff] [blame] | 218 | if s.TLSConfig == nil { |
| 219 | s.TLSConfig = new(tls.Config) |
Brad Fitzpatrick | 42ad508 | 2015-10-15 01:02:25 +0000 | [diff] [blame] | 220 | } else if s.TLSConfig.CipherSuites != nil { |
| 221 | // If they already provided a CipherSuite list, return |
| 222 | // an error if it has a bad order or is missing |
| 223 | // ECDHE_RSA_WITH_AES_128_GCM_SHA256. |
| 224 | const requiredCipher = tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 |
| 225 | haveRequired := false |
| 226 | sawBad := false |
| 227 | for i, cs := range s.TLSConfig.CipherSuites { |
| 228 | if cs == requiredCipher { |
| 229 | haveRequired = true |
| 230 | } |
| 231 | if isBadCipher(cs) { |
| 232 | sawBad = true |
| 233 | } else if sawBad { |
| 234 | return fmt.Errorf("http2: TLSConfig.CipherSuites index %d contains an HTTP/2-approved cipher suite (%#04x), but it comes after unapproved cipher suites. With this configuration, clients that don't support previous, approved cipher suites may be given an unapproved one and reject the connection.", i, cs) |
| 235 | } |
| 236 | } |
| 237 | if !haveRequired { |
| 238 | return fmt.Errorf("http2: TLSConfig.CipherSuites is missing HTTP/2-required TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256") |
| 239 | } |
Brad Fitzpatrick | b5469d2 | 2014-11-13 12:17:52 -0800 | [diff] [blame] | 240 | } |
Brad Fitzpatrick | 5df015f | 2014-12-08 11:16:59 -0800 | [diff] [blame] | 241 | |
| 242 | // Note: not setting MinVersion to tls.VersionTLS12, |
| 243 | // as we don't want to interfere with HTTP/1.1 traffic |
| 244 | // on the user's server. We enforce TLS 1.2 later once |
| 245 | // we accept a connection. Ideally this should be done |
| 246 | // during next-proto selection, but using TLS <1.2 with |
| 247 | // HTTP/2 is still the client's bug. |
| 248 | |
Brad Fitzpatrick | 42ad508 | 2015-10-15 01:02:25 +0000 | [diff] [blame] | 249 | s.TLSConfig.PreferServerCipherSuites = true |
Brad Fitzpatrick | 5df015f | 2014-12-08 11:16:59 -0800 | [diff] [blame] | 250 | |
Brad Fitzpatrick | b5469d2 | 2014-11-13 12:17:52 -0800 | [diff] [blame] | 251 | haveNPN := false |
| 252 | for _, p := range s.TLSConfig.NextProtos { |
Brad Fitzpatrick | 36d9a67 | 2014-11-26 07:40:15 -0800 | [diff] [blame] | 253 | if p == NextProtoTLS { |
Brad Fitzpatrick | b5469d2 | 2014-11-13 12:17:52 -0800 | [diff] [blame] | 254 | haveNPN = true |
| 255 | break |
| 256 | } |
| 257 | } |
| 258 | if !haveNPN { |
Brad Fitzpatrick | 36d9a67 | 2014-11-26 07:40:15 -0800 | [diff] [blame] | 259 | s.TLSConfig.NextProtos = append(s.TLSConfig.NextProtos, NextProtoTLS) |
Brad Fitzpatrick | b5469d2 | 2014-11-13 12:17:52 -0800 | [diff] [blame] | 260 | } |
| 261 | |
| 262 | if s.TLSNextProto == nil { |
| 263 | s.TLSNextProto = map[string]func(*http.Server, *tls.Conn, http.Handler){} |
| 264 | } |
Brad Fitzpatrick | 13dfd89 | 2015-03-05 15:57:11 -0800 | [diff] [blame] | 265 | protoHandler := func(hs *http.Server, c *tls.Conn, h http.Handler) { |
Brad Fitzpatrick | b5469d2 | 2014-11-13 12:17:52 -0800 | [diff] [blame] | 266 | if testHookOnConn != nil { |
| 267 | testHookOnConn() |
| 268 | } |
Brad Fitzpatrick | 6ccd669 | 2016-02-02 14:37:19 -0800 | [diff] [blame] | 269 | conf.ServeConn(c, &ServeConnOpts{ |
| 270 | Handler: h, |
| 271 | BaseConfig: hs, |
| 272 | }) |
Brad Fitzpatrick | b5469d2 | 2014-11-13 12:17:52 -0800 | [diff] [blame] | 273 | } |
Brad Fitzpatrick | 13dfd89 | 2015-03-05 15:57:11 -0800 | [diff] [blame] | 274 | s.TLSNextProto[NextProtoTLS] = protoHandler |
Brad Fitzpatrick | 42ad508 | 2015-10-15 01:02:25 +0000 | [diff] [blame] | 275 | return nil |
Brad Fitzpatrick | b5469d2 | 2014-11-13 12:17:52 -0800 | [diff] [blame] | 276 | } |
| 277 | |
Brad Fitzpatrick | 6ccd669 | 2016-02-02 14:37:19 -0800 | [diff] [blame] | 278 | // ServeConnOpts are options for the Server.ServeConn method. |
| 279 | type ServeConnOpts struct { |
| 280 | // BaseConfig optionally sets the base configuration |
| 281 | // for values. If nil, defaults are used. |
| 282 | BaseConfig *http.Server |
| 283 | |
| 284 | // Handler specifies which handler to use for processing |
| 285 | // requests. If nil, BaseConfig.Handler is used. If BaseConfig |
| 286 | // or BaseConfig.Handler is nil, http.DefaultServeMux is used. |
| 287 | Handler http.Handler |
| 288 | } |
| 289 | |
| 290 | func (o *ServeConnOpts) baseConfig() *http.Server { |
| 291 | if o != nil && o.BaseConfig != nil { |
| 292 | return o.BaseConfig |
| 293 | } |
| 294 | return new(http.Server) |
| 295 | } |
| 296 | |
| 297 | func (o *ServeConnOpts) handler() http.Handler { |
| 298 | if o != nil { |
| 299 | if o.Handler != nil { |
| 300 | return o.Handler |
| 301 | } |
| 302 | if o.BaseConfig != nil && o.BaseConfig.Handler != nil { |
| 303 | return o.BaseConfig.Handler |
| 304 | } |
| 305 | } |
| 306 | return http.DefaultServeMux |
| 307 | } |
| 308 | |
| 309 | // ServeConn serves HTTP/2 requests on the provided connection and |
| 310 | // blocks until the connection is no longer readable. |
| 311 | // |
| 312 | // ServeConn starts speaking HTTP/2 assuming that c has not had any |
| 313 | // reads or writes. It writes its initial settings frame and expects |
| 314 | // to be able to read the preface and settings frame from the |
| 315 | // client. If c has a ConnectionState method like a *tls.Conn, the |
| 316 | // ConnectionState is used to verify the TLS ciphersuite and to set |
| 317 | // the Request.TLS field in Handlers. |
| 318 | // |
| 319 | // ServeConn does not support h2c by itself. Any h2c support must be |
| 320 | // implemented in terms of providing a suitably-behaving net.Conn. |
| 321 | // |
| 322 | // The opts parameter is optional. If nil, default values are used. |
| 323 | func (s *Server) ServeConn(c net.Conn, opts *ServeConnOpts) { |
Brad Fitzpatrick | 8aacbec | 2016-05-18 19:54:31 +0000 | [diff] [blame] | 324 | baseCtx, cancel := serverConnBaseContext(c, opts) |
| 325 | defer cancel() |
| 326 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 327 | sc := &serverConn{ |
Tom Bergan | 906cda9 | 2017-02-18 12:36:51 -0800 | [diff] [blame] | 328 | srv: s, |
| 329 | hs: opts.baseConfig(), |
| 330 | conn: c, |
| 331 | baseCtx: baseCtx, |
| 332 | remoteAddrStr: c.RemoteAddr().String(), |
| 333 | bw: newBufferedWriter(c), |
| 334 | handler: opts.handler(), |
| 335 | streams: make(map[uint32]*stream), |
| 336 | readFrameCh: make(chan readFrameResult), |
| 337 | wantWriteFrameCh: make(chan FrameWriteRequest, 8), |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 338 | serveMsgCh: make(chan interface{}, 8), |
Tom Bergan | 906cda9 | 2017-02-18 12:36:51 -0800 | [diff] [blame] | 339 | wroteFrameCh: make(chan frameWriteResult, 1), // buffered; one send in writeFrameAsync |
| 340 | bodyReadCh: make(chan bodyReadMsg), // buffering doesn't matter either way |
| 341 | doneServing: make(chan struct{}), |
| 342 | clientMaxStreams: math.MaxUint32, // Section 6.5.2: "Initially, there is no limit to this value" |
| 343 | advMaxStreams: s.maxConcurrentStreams(), |
| 344 | initialStreamSendWindowSize: initialWindowSize, |
| 345 | maxFrameSize: initialMaxFrameSize, |
| 346 | headerTableSize: initialHeaderTableSize, |
| 347 | serveG: newGoroutineLock(), |
| 348 | pushEnabled: true, |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 349 | } |
Brad Fitzpatrick | 8aacbec | 2016-05-18 19:54:31 +0000 | [diff] [blame] | 350 | |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 351 | s.state.registerConn(sc) |
| 352 | defer s.state.unregisterConn(sc) |
| 353 | |
Kale Blankenship | 8fd7f25 | 2016-12-29 12:13:24 -0800 | [diff] [blame] | 354 | // The net/http package sets the write deadline from the |
| 355 | // http.Server.WriteTimeout during the TLS handshake, but then |
Kale Blankenship | d1e1b35 | 2016-12-29 14:47:41 -0800 | [diff] [blame] | 356 | // passes the connection off to us with the deadline already set. |
| 357 | // Write deadlines are set per stream in serverConn.newStream. |
| 358 | // Disarm the net.Conn write deadline here. |
Kale Blankenship | 8fd7f25 | 2016-12-29 12:13:24 -0800 | [diff] [blame] | 359 | if sc.hs.WriteTimeout != 0 { |
| 360 | sc.conn.SetWriteDeadline(time.Time{}) |
| 361 | } |
| 362 | |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 363 | if s.NewWriteScheduler != nil { |
| 364 | sc.writeSched = s.NewWriteScheduler() |
| 365 | } else { |
| 366 | sc.writeSched = NewRandomWriteScheduler() |
| 367 | } |
| 368 | |
Tom Bergan | 906cda9 | 2017-02-18 12:36:51 -0800 | [diff] [blame] | 369 | // These start at the RFC-specified defaults. If there is a higher |
| 370 | // configured value for inflow, that will be updated when we send a |
| 371 | // WINDOW_UPDATE shortly after sending SETTINGS. |
Brad Fitzpatrick | 9876618 | 2014-12-02 10:30:08 -0800 | [diff] [blame] | 372 | sc.flow.add(initialWindowSize) |
Brad Fitzpatrick | 068d35d | 2014-12-09 07:10:31 +1100 | [diff] [blame] | 373 | sc.inflow.add(initialWindowSize) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 374 | sc.hpackEncoder = hpack.NewEncoder(&sc.headerWriteBuf) |
Brad Fitzpatrick | 5e4e2dc | 2014-11-19 16:49:43 -0800 | [diff] [blame] | 375 | |
| 376 | fr := NewFramer(sc.bw, c) |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 377 | fr.ReadMetaHeaders = hpack.NewDecoder(initialHeaderTableSize, nil) |
| 378 | fr.MaxHeaderListSize = sc.maxHeaderListSize() |
Brad Fitzpatrick | 6ccd669 | 2016-02-02 14:37:19 -0800 | [diff] [blame] | 379 | fr.SetMaxReadFrameSize(s.maxReadFrameSize()) |
Brad Fitzpatrick | 5e4e2dc | 2014-11-19 16:49:43 -0800 | [diff] [blame] | 380 | sc.framer = fr |
| 381 | |
Brad Fitzpatrick | 6ccd669 | 2016-02-02 14:37:19 -0800 | [diff] [blame] | 382 | if tc, ok := c.(connectionStater); ok { |
Brad Fitzpatrick | 30b1681 | 2014-12-08 10:10:39 -0800 | [diff] [blame] | 383 | sc.tlsState = new(tls.ConnectionState) |
| 384 | *sc.tlsState = tc.ConnectionState() |
| 385 | // 9.2 Use of TLS Features |
| 386 | // An implementation of HTTP/2 over TLS MUST use TLS |
| 387 | // 1.2 or higher with the restrictions on feature set |
| 388 | // and cipher suite described in this section. Due to |
| 389 | // implementation limitations, it might not be |
| 390 | // possible to fail TLS negotiation. An endpoint MUST |
| 391 | // immediately terminate an HTTP/2 connection that |
| 392 | // does not meet the TLS requirements described in |
| 393 | // this section with a connection error (Section |
| 394 | // 5.4.1) of type INADEQUATE_SECURITY. |
| 395 | if sc.tlsState.Version < tls.VersionTLS12 { |
Brad Fitzpatrick | 842bf9f | 2014-12-08 10:31:57 -0800 | [diff] [blame] | 396 | sc.rejectConn(ErrCodeInadequateSecurity, "TLS version too low") |
Brad Fitzpatrick | 30b1681 | 2014-12-08 10:10:39 -0800 | [diff] [blame] | 397 | return |
| 398 | } |
Brad Fitzpatrick | 842bf9f | 2014-12-08 10:31:57 -0800 | [diff] [blame] | 399 | |
Brad Fitzpatrick | 842bf9f | 2014-12-08 10:31:57 -0800 | [diff] [blame] | 400 | if sc.tlsState.ServerName == "" { |
Brad Fitzpatrick | f0f7876 | 2015-01-17 12:25:12 -0800 | [diff] [blame] | 401 | // Client must use SNI, but we don't enforce that anymore, |
| 402 | // since it was causing problems when connecting to bare IP |
| 403 | // addresses during development. |
| 404 | // |
| 405 | // TODO: optionally enforce? Or enforce at the time we receive |
| 406 | // a new request, and verify the the ServerName matches the :authority? |
| 407 | // But that precludes proxy situations, perhaps. |
| 408 | // |
| 409 | // So for now, do nothing here again. |
Brad Fitzpatrick | 842bf9f | 2014-12-08 10:31:57 -0800 | [diff] [blame] | 410 | } |
| 411 | |
Brad Fitzpatrick | 6ccd669 | 2016-02-02 14:37:19 -0800 | [diff] [blame] | 412 | if !s.PermitProhibitedCipherSuites && isBadCipher(sc.tlsState.CipherSuite) { |
Brad Fitzpatrick | 5df015f | 2014-12-08 11:16:59 -0800 | [diff] [blame] | 413 | // "Endpoints MAY choose to generate a connection error |
| 414 | // (Section 5.4.1) of type INADEQUATE_SECURITY if one of |
| 415 | // the prohibited cipher suites are negotiated." |
| 416 | // |
| 417 | // We choose that. In my opinion, the spec is weak |
| 418 | // here. It also says both parties must support at least |
| 419 | // TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 so there's no |
| 420 | // excuses here. If we really must, we could allow an |
| 421 | // "AllowInsecureWeakCiphers" option on the server later. |
| 422 | // Let's see how it plays out first. |
Brad Fitzpatrick | 36f7934 | 2015-01-17 12:24:34 -0800 | [diff] [blame] | 423 | sc.rejectConn(ErrCodeInadequateSecurity, fmt.Sprintf("Prohibited TLS 1.2 Cipher Suite: %x", sc.tlsState.CipherSuite)) |
Brad Fitzpatrick | 5df015f | 2014-12-08 11:16:59 -0800 | [diff] [blame] | 424 | return |
| 425 | } |
Brad Fitzpatrick | 30b1681 | 2014-12-08 10:10:39 -0800 | [diff] [blame] | 426 | } |
| 427 | |
Brad Fitzpatrick | 0db6d65 | 2014-11-15 15:49:19 -0800 | [diff] [blame] | 428 | if hook := testHookGetServerConn; hook != nil { |
| 429 | hook(sc) |
| 430 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 431 | sc.serve() |
| 432 | } |
| 433 | |
Brad Fitzpatrick | 842bf9f | 2014-12-08 10:31:57 -0800 | [diff] [blame] | 434 | func (sc *serverConn) rejectConn(err ErrCode, debug string) { |
Brad Fitzpatrick | 415f191 | 2015-12-16 20:28:38 +0000 | [diff] [blame] | 435 | sc.vlogf("http2: server rejecting conn: %v, %s", err, debug) |
Brad Fitzpatrick | 842bf9f | 2014-12-08 10:31:57 -0800 | [diff] [blame] | 436 | // ignoring errors. hanging up anyway. |
| 437 | sc.framer.WriteGoAway(0, err, []byte(debug)) |
| 438 | sc.bw.Flush() |
| 439 | sc.conn.Close() |
| 440 | } |
| 441 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 442 | type serverConn struct { |
| 443 | // Immutable: |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 444 | srv *Server |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 445 | hs *http.Server |
| 446 | conn net.Conn |
Brad Fitzpatrick | 5e4e2dc | 2014-11-19 16:49:43 -0800 | [diff] [blame] | 447 | bw *bufferedWriter // writing to conn |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 448 | handler http.Handler |
Brad Fitzpatrick | 8aacbec | 2016-05-18 19:54:31 +0000 | [diff] [blame] | 449 | baseCtx contextContext |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 450 | framer *Framer |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 451 | doneServing chan struct{} // closed when serverConn.serve ends |
| 452 | readFrameCh chan readFrameResult // written by serverConn.readFrames |
| 453 | wantWriteFrameCh chan FrameWriteRequest // from handlers -> serve |
| 454 | wroteFrameCh chan frameWriteResult // from writeFrameAsync -> serve, tickles more frame writes |
| 455 | bodyReadCh chan bodyReadMsg // from handlers -> serve |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 456 | serveMsgCh chan interface{} // misc messages & code to send to / run on the serve loop |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 457 | flow flow // conn-wide (not stream-specific) outbound flow control |
| 458 | inflow flow // conn-wide inbound flow control |
| 459 | tlsState *tls.ConnectionState // shared by all handlers, like net/http |
Brad Fitzpatrick | df959c2 | 2014-12-09 07:20:20 +1100 | [diff] [blame] | 460 | remoteAddrStr string |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 461 | writeSched WriteScheduler |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 462 | |
| 463 | // Everything following is owned by the serve loop; use serveG.check(): |
Tom Bergan | 906cda9 | 2017-02-18 12:36:51 -0800 | [diff] [blame] | 464 | serveG goroutineLock // used to verify funcs are on serve() |
| 465 | pushEnabled bool |
| 466 | sawFirstSettings bool // got the initial SETTINGS frame after the preface |
| 467 | needToSendSettingsAck bool |
| 468 | unackedSettings int // how many SETTINGS have we sent without ACKs? |
| 469 | clientMaxStreams uint32 // SETTINGS_MAX_CONCURRENT_STREAMS from client (our PUSH_PROMISE limit) |
| 470 | advMaxStreams uint32 // our SETTINGS_MAX_CONCURRENT_STREAMS advertised the client |
| 471 | curClientStreams uint32 // number of open streams initiated by the client |
| 472 | curPushedStreams uint32 // number of open streams initiated by server push |
| 473 | maxClientStreamID uint32 // max ever seen from client (odd), or 0 if there have been no client requests |
| 474 | maxPushPromiseID uint32 // ID of the last push promise (even), or 0 if there have been no pushes |
| 475 | streams map[uint32]*stream |
| 476 | initialStreamSendWindowSize int32 |
| 477 | maxFrameSize int32 |
| 478 | headerTableSize uint32 |
| 479 | peerMaxHeaderListSize uint32 // zero means unknown (default) |
| 480 | canonHeader map[string]string // http2-lower-case -> Go-Canonical-Case |
| 481 | writingFrame bool // started writing a frame (on serve goroutine or separate) |
| 482 | writingFrameAsync bool // started a frame on its own goroutine but haven't heard back on wroteFrameCh |
| 483 | needsFrameFlush bool // last frame write wasn't a flush |
| 484 | inGoAway bool // we've started to or sent GOAWAY |
| 485 | inFrameScheduleLoop bool // whether we're in the scheduleFrameWrite loop |
| 486 | needToSendGoAway bool // we need to schedule a GOAWAY frame write |
| 487 | goAwayCode ErrCode |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 488 | shutdownTimer *time.Timer // nil until used |
| 489 | idleTimer *time.Timer // nil if unused |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 490 | |
Brad Fitzpatrick | 23564bf | 2014-11-27 19:40:04 -0800 | [diff] [blame] | 491 | // Owned by the writeFrameAsync goroutine: |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 492 | headerWriteBuf bytes.Buffer |
| 493 | hpackEncoder *hpack.Encoder |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 494 | |
| 495 | // Used by startGracefulShutdown. |
| 496 | shutdownOnce sync.Once |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 497 | } |
| 498 | |
Brad Fitzpatrick | 29704b8 | 2015-10-10 18:01:18 -0700 | [diff] [blame] | 499 | func (sc *serverConn) maxHeaderListSize() uint32 { |
| 500 | n := sc.hs.MaxHeaderBytes |
Brad Fitzpatrick | d8f3c68 | 2015-10-12 20:56:49 +0000 | [diff] [blame] | 501 | if n <= 0 { |
Brad Fitzpatrick | 29704b8 | 2015-10-10 18:01:18 -0700 | [diff] [blame] | 502 | n = http.DefaultMaxHeaderBytes |
| 503 | } |
| 504 | // http2's count is in a slightly different unit and includes 32 bytes per pair. |
| 505 | // So, take the net/http.Server value and pad it up a bit, assuming 10 headers. |
| 506 | const perFieldOverhead = 32 // per http2 spec |
| 507 | const typicalHeaders = 10 // conservative |
| 508 | return uint32(n + typicalHeaders*perFieldOverhead) |
| 509 | } |
| 510 | |
Tom Bergan | 0c96df3 | 2016-12-05 22:33:37 -0800 | [diff] [blame] | 511 | func (sc *serverConn) curOpenStreams() uint32 { |
| 512 | sc.serveG.check() |
| 513 | return sc.curClientStreams + sc.curPushedStreams |
| 514 | } |
| 515 | |
Gabriel Aszalos | 1aa5b31 | 2014-11-19 16:56:22 +0000 | [diff] [blame] | 516 | // stream represents a stream. This is the minimal metadata needed by |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 517 | // the serve goroutine. Most of the actual stream state is owned by |
| 518 | // the http.Handler's goroutine in the responseWriter. Because the |
| 519 | // responseWriter's responseWriterState is recycled at the end of a |
| 520 | // handler, this struct intentionally has no pointer to the |
| 521 | // *responseWriter{,State} itself, as the Handler ending nils out the |
| 522 | // responseWriter's state field. |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 523 | type stream struct { |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 524 | // immutable: |
Brad Fitzpatrick | 8aacbec | 2016-05-18 19:54:31 +0000 | [diff] [blame] | 525 | sc *serverConn |
| 526 | id uint32 |
| 527 | body *pipe // non-nil if expecting DATA frames |
| 528 | cw closeWaiter // closed wait stream transitions to closed state |
| 529 | ctx contextContext |
| 530 | cancelCtx func() |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 531 | |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 532 | // owned by serverConn's serve loop: |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 533 | bodyBytes int64 // body bytes seen so far |
| 534 | declBodyBytes int64 // or -1 if undeclared |
| 535 | flow flow // limits writing from Handler to client |
| 536 | inflow flow // what the client is allowed to POST/etc to us |
| 537 | parent *stream // or nil |
| 538 | numTrailerValues int64 |
| 539 | weight uint8 |
| 540 | state streamState |
Kale Blankenship | d1e1b35 | 2016-12-29 14:47:41 -0800 | [diff] [blame] | 541 | resetQueued bool // RST_STREAM queued for write; set by sc.resetStream |
| 542 | gotTrailerHeader bool // HEADER frame for trailers was seen |
| 543 | wroteHeaders bool // whether we wrote headers (not status 100) |
| 544 | writeDeadline *time.Timer // nil if unused |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 545 | |
| 546 | trailer http.Header // accumulated trailers |
| 547 | reqTrailer http.Header // handler's Request.Trailer |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 548 | } |
| 549 | |
Brad Fitzpatrick | 23564bf | 2014-11-27 19:40:04 -0800 | [diff] [blame] | 550 | func (sc *serverConn) Framer() *Framer { return sc.framer } |
| 551 | func (sc *serverConn) CloseConn() error { return sc.conn.Close() } |
| 552 | func (sc *serverConn) Flush() error { return sc.bw.Flush() } |
| 553 | func (sc *serverConn) HeaderEncoder() (*hpack.Encoder, *bytes.Buffer) { |
| 554 | return sc.hpackEncoder, &sc.headerWriteBuf |
| 555 | } |
| 556 | |
Brad Fitzpatrick | a98415a | 2014-12-08 00:47:45 -0800 | [diff] [blame] | 557 | func (sc *serverConn) state(streamID uint32) (streamState, *stream) { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 558 | sc.serveG.check() |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 559 | // http://tools.ietf.org/html/rfc7540#section-5.1 |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 560 | if st, ok := sc.streams[streamID]; ok { |
Brad Fitzpatrick | a98415a | 2014-12-08 00:47:45 -0800 | [diff] [blame] | 561 | return st.state, st |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 562 | } |
| 563 | // "The first use of a new stream identifier implicitly closes all |
| 564 | // streams in the "idle" state that might have been initiated by |
| 565 | // that peer with a lower-valued stream identifier. For example, if |
| 566 | // a client sends a HEADERS frame on stream 7 without ever sending a |
| 567 | // frame on stream 5, then stream 5 transitions to the "closed" |
| 568 | // state when the first frame for stream 7 is sent or received." |
Tom Bergan | 55a3084 | 2016-11-04 15:18:50 -0700 | [diff] [blame] | 569 | if streamID%2 == 1 { |
| 570 | if streamID <= sc.maxClientStreamID { |
| 571 | return stateClosed, nil |
| 572 | } |
| 573 | } else { |
| 574 | if streamID <= sc.maxPushPromiseID { |
| 575 | return stateClosed, nil |
| 576 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 577 | } |
Brad Fitzpatrick | a98415a | 2014-12-08 00:47:45 -0800 | [diff] [blame] | 578 | return stateIdle, nil |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 579 | } |
| 580 | |
Brad Fitzpatrick | cd8c270 | 2015-10-15 20:01:14 +0000 | [diff] [blame] | 581 | // setConnState calls the net/http ConnState hook for this connection, if configured. |
| 582 | // Note that the net/http package does StateNew and StateClosed for us. |
| 583 | // There is currently no plan for StateHijacked or hijacking HTTP/2 connections. |
| 584 | func (sc *serverConn) setConnState(state http.ConnState) { |
| 585 | if sc.hs.ConnState != nil { |
| 586 | sc.hs.ConnState(sc.conn, state) |
| 587 | } |
| 588 | } |
| 589 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 590 | func (sc *serverConn) vlogf(format string, args ...interface{}) { |
| 591 | if VerboseLogs { |
| 592 | sc.logf(format, args...) |
| 593 | } |
| 594 | } |
| 595 | |
| 596 | func (sc *serverConn) logf(format string, args ...interface{}) { |
| 597 | if lg := sc.hs.ErrorLog; lg != nil { |
| 598 | lg.Printf(format, args...) |
| 599 | } else { |
| 600 | log.Printf(format, args...) |
| 601 | } |
| 602 | } |
| 603 | |
Brad Fitzpatrick | eb066e3 | 2016-01-26 18:31:02 +0000 | [diff] [blame] | 604 | // errno returns v's underlying uintptr, else 0. |
| 605 | // |
| 606 | // TODO: remove this helper function once http2 can use build |
| 607 | // tags. See comment in isClosedConnError. |
| 608 | func errno(v error) uintptr { |
| 609 | if rv := reflect.ValueOf(v); rv.Kind() == reflect.Uintptr { |
| 610 | return uintptr(rv.Uint()) |
| 611 | } |
| 612 | return 0 |
| 613 | } |
| 614 | |
| 615 | // isClosedConnError reports whether err is an error from use of a closed |
| 616 | // network connection. |
| 617 | func isClosedConnError(err error) bool { |
| 618 | if err == nil { |
| 619 | return false |
| 620 | } |
| 621 | |
| 622 | // TODO: remove this string search and be more like the Windows |
| 623 | // case below. That might involve modifying the standard library |
| 624 | // to return better error types. |
| 625 | str := err.Error() |
| 626 | if strings.Contains(str, "use of closed network connection") { |
| 627 | return true |
| 628 | } |
| 629 | |
| 630 | // TODO(bradfitz): x/tools/cmd/bundle doesn't really support |
| 631 | // build tags, so I can't make an http2_windows.go file with |
| 632 | // Windows-specific stuff. Fix that and move this, once we |
| 633 | // have a way to bundle this into std's net/http somehow. |
| 634 | if runtime.GOOS == "windows" { |
| 635 | if oe, ok := err.(*net.OpError); ok && oe.Op == "read" { |
| 636 | if se, ok := oe.Err.(*os.SyscallError); ok && se.Syscall == "wsarecv" { |
| 637 | const WSAECONNABORTED = 10053 |
| 638 | const WSAECONNRESET = 10054 |
| 639 | if n := errno(se.Err); n == WSAECONNRESET || n == WSAECONNABORTED { |
| 640 | return true |
| 641 | } |
| 642 | } |
| 643 | } |
| 644 | } |
| 645 | return false |
| 646 | } |
| 647 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 648 | func (sc *serverConn) condlogf(err error, format string, args ...interface{}) { |
| 649 | if err == nil { |
| 650 | return |
| 651 | } |
Brad Fitzpatrick | eb066e3 | 2016-01-26 18:31:02 +0000 | [diff] [blame] | 652 | if err == io.EOF || err == io.ErrUnexpectedEOF || isClosedConnError(err) { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 653 | // Boring, expected errors. |
| 654 | sc.vlogf(format, args...) |
| 655 | } else { |
| 656 | sc.logf(format, args...) |
| 657 | } |
| 658 | } |
| 659 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 660 | func (sc *serverConn) canonicalHeader(v string) string { |
| 661 | sc.serveG.check() |
Brad Fitzpatrick | 6520e26 | 2014-11-15 09:36:47 -0800 | [diff] [blame] | 662 | cv, ok := commonCanonHeader[v] |
| 663 | if ok { |
| 664 | return cv |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 665 | } |
Brad Fitzpatrick | 6520e26 | 2014-11-15 09:36:47 -0800 | [diff] [blame] | 666 | cv, ok = sc.canonHeader[v] |
| 667 | if ok { |
| 668 | return cv |
| 669 | } |
| 670 | if sc.canonHeader == nil { |
| 671 | sc.canonHeader = make(map[string]string) |
| 672 | } |
| 673 | cv = http.CanonicalHeaderKey(v) |
| 674 | sc.canonHeader[v] = cv |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 675 | return cv |
| 676 | } |
| 677 | |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 678 | type readFrameResult struct { |
| 679 | f Frame // valid until readMore is called |
| 680 | err error |
| 681 | |
| 682 | // readMore should be called once the consumer no longer needs or |
| 683 | // retains f. After readMore, f is invalid and more frames can be |
| 684 | // read. |
| 685 | readMore func() |
| 686 | } |
| 687 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 688 | // readFrames is the loop that reads incoming frames. |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 689 | // It takes care to only read one frame at a time, blocking until the |
| 690 | // consumer is done with the frame. |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 691 | // It's run on its own goroutine. |
| 692 | func (sc *serverConn) readFrames() { |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 693 | gate := make(gate) |
Brad Fitzpatrick | c561780 | 2016-03-22 01:45:52 +0000 | [diff] [blame] | 694 | gateDone := gate.Done |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 695 | for { |
| 696 | f, err := sc.framer.ReadFrame() |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 697 | select { |
Brad Fitzpatrick | c561780 | 2016-03-22 01:45:52 +0000 | [diff] [blame] | 698 | case sc.readFrameCh <- readFrameResult{f, err, gateDone}: |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 699 | case <-sc.doneServing: |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 700 | return |
| 701 | } |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 702 | select { |
| 703 | case <-gate: |
| 704 | case <-sc.doneServing: |
| 705 | return |
| 706 | } |
Brad Fitzpatrick | ea6dba8 | 2015-12-23 08:43:06 -0800 | [diff] [blame] | 707 | if terminalReadFrameError(err) { |
| 708 | return |
| 709 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 710 | } |
| 711 | } |
| 712 | |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 713 | // frameWriteResult is the message passed from writeFrameAsync to the serve goroutine. |
| 714 | type frameWriteResult struct { |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 715 | wr FrameWriteRequest // what was written (or attempted) |
| 716 | err error // result of the writeFrame call |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 717 | } |
| 718 | |
Brad Fitzpatrick | aa524f6 | 2014-11-25 10:31:37 -0800 | [diff] [blame] | 719 | // writeFrameAsync runs in its own goroutine and writes a single frame |
| 720 | // and then reports when it's done. |
| 721 | // At most one goroutine can be running writeFrameAsync at a time per |
| 722 | // serverConn. |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 723 | func (sc *serverConn) writeFrameAsync(wr FrameWriteRequest) { |
| 724 | err := wr.write.writeFrame(sc) |
| 725 | sc.wroteFrameCh <- frameWriteResult{wr, err} |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 726 | } |
| 727 | |
Brad Fitzpatrick | 9b41faf | 2014-11-19 10:45:13 -0800 | [diff] [blame] | 728 | func (sc *serverConn) closeAllStreamsOnConnClose() { |
Brad Fitzpatrick | 6d3aa4f | 2014-11-15 14:55:57 -0800 | [diff] [blame] | 729 | sc.serveG.check() |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 730 | for _, st := range sc.streams { |
| 731 | sc.closeStream(st, errClientDisconnected) |
Brad Fitzpatrick | 6d3aa4f | 2014-11-15 14:55:57 -0800 | [diff] [blame] | 732 | } |
| 733 | } |
| 734 | |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 735 | func (sc *serverConn) stopShutdownTimer() { |
| 736 | sc.serveG.check() |
| 737 | if t := sc.shutdownTimer; t != nil { |
| 738 | t.Stop() |
| 739 | } |
| 740 | } |
| 741 | |
Brad Fitzpatrick | 996adcb | 2014-12-08 01:08:19 -0800 | [diff] [blame] | 742 | func (sc *serverConn) notePanic() { |
Brad Fitzpatrick | 74bd44b | 2015-12-15 00:47:28 +0000 | [diff] [blame] | 743 | // Note: this is for serverConn.serve panicking, not http.Handler code. |
Brad Fitzpatrick | f3a6d9a | 2014-12-08 07:53:36 -0800 | [diff] [blame] | 744 | if testHookOnPanicMu != nil { |
| 745 | testHookOnPanicMu.Lock() |
| 746 | defer testHookOnPanicMu.Unlock() |
| 747 | } |
Brad Fitzpatrick | 996adcb | 2014-12-08 01:08:19 -0800 | [diff] [blame] | 748 | if testHookOnPanic != nil { |
| 749 | if e := recover(); e != nil { |
| 750 | if testHookOnPanic(sc, e) { |
| 751 | panic(e) |
| 752 | } |
| 753 | } |
| 754 | } |
| 755 | } |
| 756 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 757 | func (sc *serverConn) serve() { |
| 758 | sc.serveG.check() |
Brad Fitzpatrick | 996adcb | 2014-12-08 01:08:19 -0800 | [diff] [blame] | 759 | defer sc.notePanic() |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 760 | defer sc.conn.Close() |
Brad Fitzpatrick | 9b41faf | 2014-11-19 10:45:13 -0800 | [diff] [blame] | 761 | defer sc.closeAllStreamsOnConnClose() |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 762 | defer sc.stopShutdownTimer() |
Brad Fitzpatrick | aa524f6 | 2014-11-25 10:31:37 -0800 | [diff] [blame] | 763 | defer close(sc.doneServing) // unblocks handlers trying to send |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 764 | |
Brad Fitzpatrick | 415f191 | 2015-12-16 20:28:38 +0000 | [diff] [blame] | 765 | if VerboseLogs { |
| 766 | sc.vlogf("http2: server connection from %v on %p", sc.conn.RemoteAddr(), sc.hs) |
| 767 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 768 | |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 769 | sc.writeFrame(FrameWriteRequest{ |
Brad Fitzpatrick | f16a0b3 | 2014-11-28 13:49:30 -0800 | [diff] [blame] | 770 | write: writeSettings{ |
Brad Fitzpatrick | 23564bf | 2014-11-27 19:40:04 -0800 | [diff] [blame] | 771 | {SettingMaxFrameSize, sc.srv.maxReadFrameSize()}, |
| 772 | {SettingMaxConcurrentStreams, sc.advMaxStreams}, |
Brad Fitzpatrick | 29704b8 | 2015-10-10 18:01:18 -0700 | [diff] [blame] | 773 | {SettingMaxHeaderListSize, sc.maxHeaderListSize()}, |
Tom Bergan | 906cda9 | 2017-02-18 12:36:51 -0800 | [diff] [blame] | 774 | {SettingInitialWindowSize, uint32(sc.srv.initialStreamRecvWindowSize())}, |
Brad Fitzpatrick | 23564bf | 2014-11-27 19:40:04 -0800 | [diff] [blame] | 775 | }, |
| 776 | }) |
Brad Fitzpatrick | 6a9b77b | 2014-12-03 13:56:36 -0800 | [diff] [blame] | 777 | sc.unackedSettings++ |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 778 | |
Tom Bergan | 906cda9 | 2017-02-18 12:36:51 -0800 | [diff] [blame] | 779 | // Each connection starts with intialWindowSize inflow tokens. |
| 780 | // If a higher value is configured, we add more tokens. |
| 781 | if diff := sc.srv.initialConnRecvWindowSize() - initialWindowSize; diff > 0 { |
| 782 | sc.sendWindowUpdate(nil, int(diff)) |
| 783 | } |
| 784 | |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 785 | if err := sc.readPreface(); err != nil { |
Brad Fitzpatrick | 415f191 | 2015-12-16 20:28:38 +0000 | [diff] [blame] | 786 | sc.condlogf(err, "http2: server: error reading preface from client %v: %v", sc.conn.RemoteAddr(), err) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 787 | return |
| 788 | } |
Brad Fitzpatrick | cd8c270 | 2015-10-15 20:01:14 +0000 | [diff] [blame] | 789 | // Now that we've got the preface, get us out of the |
Dmitri Shuralyov | 357296a | 2016-11-07 15:02:51 -0800 | [diff] [blame] | 790 | // "StateNew" state. We can't go directly to idle, though. |
Brad Fitzpatrick | cd8c270 | 2015-10-15 20:01:14 +0000 | [diff] [blame] | 791 | // Active means we read some data and anticipate a request. We'll |
| 792 | // do another Active when we get a HEADERS frame. |
| 793 | sc.setConnState(http.StateActive) |
| 794 | sc.setConnState(http.StateIdle) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 795 | |
Brad Fitzpatrick | c33d378 | 2016-10-22 11:37:19 -0700 | [diff] [blame] | 796 | if sc.srv.IdleTimeout != 0 { |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 797 | sc.idleTimer = time.AfterFunc(sc.srv.IdleTimeout, sc.onIdleTimer) |
Brad Fitzpatrick | c33d378 | 2016-10-22 11:37:19 -0700 | [diff] [blame] | 798 | defer sc.idleTimer.Stop() |
Brad Fitzpatrick | c33d378 | 2016-10-22 11:37:19 -0700 | [diff] [blame] | 799 | } |
| 800 | |
Brad Fitzpatrick | aa524f6 | 2014-11-25 10:31:37 -0800 | [diff] [blame] | 801 | go sc.readFrames() // closed by defer sc.conn.Close above |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 802 | |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 803 | settingsTimer := time.AfterFunc(firstSettingsTimeout, sc.onSettingsTimer) |
| 804 | defer settingsTimer.Stop() |
| 805 | |
Brad Fitzpatrick | c94bffa | 2015-10-13 18:18:12 +0000 | [diff] [blame] | 806 | loopNum := 0 |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 807 | for { |
Brad Fitzpatrick | c94bffa | 2015-10-13 18:18:12 +0000 | [diff] [blame] | 808 | loopNum++ |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 809 | select { |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 810 | case wr := <-sc.wantWriteFrameCh: |
Kale Blankenship | d1e1b35 | 2016-12-29 14:47:41 -0800 | [diff] [blame] | 811 | if se, ok := wr.write.(StreamError); ok { |
| 812 | sc.resetStream(se) |
| 813 | break |
| 814 | } |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 815 | sc.writeFrame(wr) |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 816 | case res := <-sc.wroteFrameCh: |
| 817 | sc.wroteFrame(res) |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 818 | case res := <-sc.readFrameCh: |
| 819 | if !sc.processFrameFromReader(res) { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 820 | return |
| 821 | } |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 822 | res.readMore() |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 823 | if settingsTimer != nil { |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 824 | settingsTimer.Stop() |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 825 | settingsTimer = nil |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 826 | } |
Brad Fitzpatrick | c8bab6a | 2014-12-07 18:51:56 -0800 | [diff] [blame] | 827 | case m := <-sc.bodyReadCh: |
| 828 | sc.noteBodyRead(m.st, m.n) |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 829 | case msg := <-sc.serveMsgCh: |
| 830 | switch v := msg.(type) { |
| 831 | case func(int): |
| 832 | v(loopNum) // for testing |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 833 | case *serverMessage: |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 834 | switch v { |
| 835 | case settingsTimerMsg: |
| 836 | sc.logf("timeout waiting for SETTINGS frames from %v", sc.conn.RemoteAddr()) |
| 837 | return |
| 838 | case idleTimerMsg: |
| 839 | sc.vlogf("connection is idle") |
| 840 | sc.goAway(ErrCodeNo) |
| 841 | case shutdownTimerMsg: |
| 842 | sc.vlogf("GOAWAY close timer fired; closing conn from %v", sc.conn.RemoteAddr()) |
| 843 | return |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 844 | case gracefulShutdownMsg: |
| 845 | sc.startGracefulShutdownInternal() |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 846 | default: |
| 847 | panic("unknown timer") |
| 848 | } |
| 849 | case *startPushRequest: |
| 850 | sc.startPush(v) |
| 851 | default: |
| 852 | panic(fmt.Sprintf("unexpected type %T", v)) |
| 853 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 854 | } |
Brad Fitzpatrick | 73058b0 | 2016-10-30 16:20:31 +0000 | [diff] [blame] | 855 | |
Tom Bergan | cd69bc3 | 2017-10-17 13:25:22 -0700 | [diff] [blame^] | 856 | // Start the shutdown timer after sending a GOAWAY. When sending GOAWAY |
| 857 | // with no error code (graceful shutdown), don't start the timer until |
| 858 | // all open streams have been completed. |
| 859 | sentGoAway := sc.inGoAway && !sc.needToSendGoAway && !sc.writingFrame |
| 860 | gracefulShutdownComplete := sc.goAwayCode == ErrCodeNo && sc.curOpenStreams() == 0 |
| 861 | if sentGoAway && sc.shutdownTimer == nil && (sc.goAwayCode != ErrCodeNo || gracefulShutdownComplete) { |
| 862 | sc.shutDownIn(goAwayTimeout) |
Brad Fitzpatrick | 73058b0 | 2016-10-30 16:20:31 +0000 | [diff] [blame] | 863 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 864 | } |
| 865 | } |
| 866 | |
Tom Bergan | 84f0e6f | 2017-05-12 14:27:43 -0700 | [diff] [blame] | 867 | func (sc *serverConn) awaitGracefulShutdown(sharedCh <-chan struct{}, privateCh chan struct{}) { |
| 868 | select { |
| 869 | case <-sc.doneServing: |
| 870 | case <-sharedCh: |
| 871 | close(privateCh) |
| 872 | } |
| 873 | } |
| 874 | |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 875 | type serverMessage int |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 876 | |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 877 | // Message values sent to serveMsgCh. |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 878 | var ( |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 879 | settingsTimerMsg = new(serverMessage) |
| 880 | idleTimerMsg = new(serverMessage) |
| 881 | shutdownTimerMsg = new(serverMessage) |
| 882 | gracefulShutdownMsg = new(serverMessage) |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 883 | ) |
| 884 | |
| 885 | func (sc *serverConn) onSettingsTimer() { sc.sendServeMsg(settingsTimerMsg) } |
| 886 | func (sc *serverConn) onIdleTimer() { sc.sendServeMsg(idleTimerMsg) } |
| 887 | func (sc *serverConn) onShutdownTimer() { sc.sendServeMsg(shutdownTimerMsg) } |
| 888 | |
| 889 | func (sc *serverConn) sendServeMsg(msg interface{}) { |
| 890 | sc.serveG.checkNotOn() // NOT |
| 891 | select { |
| 892 | case sc.serveMsgCh <- msg: |
| 893 | case <-sc.doneServing: |
| 894 | } |
| 895 | } |
| 896 | |
Brad Fitzpatrick | 9584203 | 2014-11-15 09:47:42 -0800 | [diff] [blame] | 897 | // readPreface reads the ClientPreface greeting from the peer |
| 898 | // or returns an error on timeout or an invalid greeting. |
| 899 | func (sc *serverConn) readPreface() error { |
| 900 | errc := make(chan error, 1) |
| 901 | go func() { |
| 902 | // Read the client preface |
| 903 | buf := make([]byte, len(ClientPreface)) |
Brad Fitzpatrick | 9584203 | 2014-11-15 09:47:42 -0800 | [diff] [blame] | 904 | if _, err := io.ReadFull(sc.conn, buf); err != nil { |
| 905 | errc <- err |
| 906 | } else if !bytes.Equal(buf, clientPreface) { |
| 907 | errc <- fmt.Errorf("bogus greeting %q", buf) |
| 908 | } else { |
| 909 | errc <- nil |
| 910 | } |
| 911 | }() |
Brad Fitzpatrick | 068d35d | 2014-12-09 07:10:31 +1100 | [diff] [blame] | 912 | timer := time.NewTimer(prefaceTimeout) // TODO: configurable on *Server? |
Brad Fitzpatrick | 9584203 | 2014-11-15 09:47:42 -0800 | [diff] [blame] | 913 | defer timer.Stop() |
| 914 | select { |
| 915 | case <-timer.C: |
| 916 | return errors.New("timeout waiting for client preface") |
| 917 | case err := <-errc: |
| 918 | if err == nil { |
Brad Fitzpatrick | 415f191 | 2015-12-16 20:28:38 +0000 | [diff] [blame] | 919 | if VerboseLogs { |
| 920 | sc.vlogf("http2: server: client %v said hello", sc.conn.RemoteAddr()) |
| 921 | } |
Brad Fitzpatrick | 9584203 | 2014-11-15 09:47:42 -0800 | [diff] [blame] | 922 | } |
| 923 | return err |
| 924 | } |
| 925 | } |
| 926 | |
Brad Fitzpatrick | c94bffa | 2015-10-13 18:18:12 +0000 | [diff] [blame] | 927 | var errChanPool = sync.Pool{ |
| 928 | New: func() interface{} { return make(chan error, 1) }, |
| 929 | } |
| 930 | |
Brad Fitzpatrick | c95266f | 2015-10-29 12:35:12 -0700 | [diff] [blame] | 931 | var writeDataPool = sync.Pool{ |
| 932 | New: func() interface{} { return new(writeData) }, |
| 933 | } |
| 934 | |
| 935 | // writeDataFromHandler writes DATA response frames from a handler on |
| 936 | // the given stream. |
| 937 | func (sc *serverConn) writeDataFromHandler(stream *stream, data []byte, endStream bool) error { |
Brad Fitzpatrick | c94bffa | 2015-10-13 18:18:12 +0000 | [diff] [blame] | 938 | ch := errChanPool.Get().(chan error) |
Brad Fitzpatrick | c95266f | 2015-10-29 12:35:12 -0700 | [diff] [blame] | 939 | writeArg := writeDataPool.Get().(*writeData) |
| 940 | *writeArg = writeData{stream.id, data, endStream} |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 941 | err := sc.writeFrameFromHandler(FrameWriteRequest{ |
Brad Fitzpatrick | c95266f | 2015-10-29 12:35:12 -0700 | [diff] [blame] | 942 | write: writeArg, |
Brad Fitzpatrick | f16a0b3 | 2014-11-28 13:49:30 -0800 | [diff] [blame] | 943 | stream: stream, |
| 944 | done: ch, |
Brad Fitzpatrick | dc0c5c0 | 2014-11-20 14:15:26 -0800 | [diff] [blame] | 945 | }) |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 946 | if err != nil { |
Brad Fitzpatrick | dc0c5c0 | 2014-11-20 14:15:26 -0800 | [diff] [blame] | 947 | return err |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 948 | } |
Brad Fitzpatrick | c95266f | 2015-10-29 12:35:12 -0700 | [diff] [blame] | 949 | var frameWriteDone bool // the frame write is done (successfully or not) |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 950 | select { |
| 951 | case err = <-ch: |
Brad Fitzpatrick | c95266f | 2015-10-29 12:35:12 -0700 | [diff] [blame] | 952 | frameWriteDone = true |
Brad Fitzpatrick | dc0c5c0 | 2014-11-20 14:15:26 -0800 | [diff] [blame] | 953 | case <-sc.doneServing: |
| 954 | return errClientDisconnected |
Brad Fitzpatrick | 2b45947 | 2014-11-30 19:18:57 -0800 | [diff] [blame] | 955 | case <-stream.cw: |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 956 | // If both ch and stream.cw were ready (as might |
| 957 | // happen on the final Write after an http.Handler |
| 958 | // ends), prefer the write result. Otherwise this |
| 959 | // might just be us successfully closing the stream. |
| 960 | // The writeFrameAsync and serve goroutines guarantee |
| 961 | // that the ch send will happen before the stream.cw |
| 962 | // close. |
| 963 | select { |
| 964 | case err = <-ch: |
Brad Fitzpatrick | c95266f | 2015-10-29 12:35:12 -0700 | [diff] [blame] | 965 | frameWriteDone = true |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 966 | default: |
| 967 | return errStreamClosed |
| 968 | } |
Brad Fitzpatrick | dc0c5c0 | 2014-11-20 14:15:26 -0800 | [diff] [blame] | 969 | } |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 970 | errChanPool.Put(ch) |
Brad Fitzpatrick | c95266f | 2015-10-29 12:35:12 -0700 | [diff] [blame] | 971 | if frameWriteDone { |
| 972 | writeDataPool.Put(writeArg) |
| 973 | } |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 974 | return err |
Brad Fitzpatrick | dc0c5c0 | 2014-11-20 14:15:26 -0800 | [diff] [blame] | 975 | } |
| 976 | |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 977 | // writeFrameFromHandler sends wr to sc.wantWriteFrameCh, but aborts |
Brad Fitzpatrick | 4e3c922 | 2014-11-22 17:35:09 -0800 | [diff] [blame] | 978 | // if the connection has gone away. |
Brad Fitzpatrick | dc0c5c0 | 2014-11-20 14:15:26 -0800 | [diff] [blame] | 979 | // |
| 980 | // This must not be run from the serve goroutine itself, else it might |
| 981 | // deadlock writing to sc.wantWriteFrameCh (which is only mildly |
| 982 | // buffered and is read by serve itself). If you're on the serve |
Brad Fitzpatrick | 4e3c922 | 2014-11-22 17:35:09 -0800 | [diff] [blame] | 983 | // goroutine, call writeFrame instead. |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 984 | func (sc *serverConn) writeFrameFromHandler(wr FrameWriteRequest) error { |
Brad Fitzpatrick | 9b41faf | 2014-11-19 10:45:13 -0800 | [diff] [blame] | 985 | sc.serveG.checkNotOn() // NOT |
| 986 | select { |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 987 | case sc.wantWriteFrameCh <- wr: |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 988 | return nil |
Brad Fitzpatrick | 9b41faf | 2014-11-19 10:45:13 -0800 | [diff] [blame] | 989 | case <-sc.doneServing: |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 990 | // Serve loop is gone. |
Brad Fitzpatrick | 9b41faf | 2014-11-19 10:45:13 -0800 | [diff] [blame] | 991 | // Client has closed their connection to the server. |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 992 | return errClientDisconnected |
Brad Fitzpatrick | 9b41faf | 2014-11-19 10:45:13 -0800 | [diff] [blame] | 993 | } |
Brad Fitzpatrick | a29a323 | 2014-11-15 11:18:25 -0800 | [diff] [blame] | 994 | } |
| 995 | |
Brad Fitzpatrick | a92fa95 | 2014-12-02 10:31:34 -0800 | [diff] [blame] | 996 | // writeFrame schedules a frame to write and sends it if there's nothing |
| 997 | // already being written. |
Brad Fitzpatrick | dc0c5c0 | 2014-11-20 14:15:26 -0800 | [diff] [blame] | 998 | // |
Brad Fitzpatrick | a92fa95 | 2014-12-02 10:31:34 -0800 | [diff] [blame] | 999 | // There is no pushback here (the serve goroutine never blocks). It's |
| 1000 | // the http.Handlers that block, waiting for their previous frames to |
| 1001 | // make it onto the wire |
| 1002 | // |
| 1003 | // If you're not on the serve goroutine, use writeFrameFromHandler instead. |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1004 | func (sc *serverConn) writeFrame(wr FrameWriteRequest) { |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 1005 | sc.serveG.check() |
Brad Fitzpatrick | 0c60707 | 2016-05-21 00:18:04 +0000 | [diff] [blame] | 1006 | |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1007 | // If true, wr will not be written and wr.done will not be signaled. |
Brad Fitzpatrick | 0c60707 | 2016-05-21 00:18:04 +0000 | [diff] [blame] | 1008 | var ignoreWrite bool |
| 1009 | |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1010 | // We are not allowed to write frames on closed streams. RFC 7540 Section |
| 1011 | // 5.1.1 says: "An endpoint MUST NOT send frames other than PRIORITY on |
| 1012 | // a closed stream." Our server never sends PRIORITY, so that exception |
| 1013 | // does not apply. |
| 1014 | // |
| 1015 | // The serverConn might close an open stream while the stream's handler |
| 1016 | // is still running. For example, the server might close a stream when it |
| 1017 | // receives bad data from the client. If this happens, the handler might |
| 1018 | // attempt to write a frame after the stream has been closed (since the |
| 1019 | // handler hasn't yet been notified of the close). In this case, we simply |
| 1020 | // ignore the frame. The handler will notice that the stream is closed when |
| 1021 | // it waits for the frame to be written. |
| 1022 | // |
| 1023 | // As an exception to this rule, we allow sending RST_STREAM after close. |
| 1024 | // This allows us to immediately reject new streams without tracking any |
| 1025 | // state for those streams (except for the queued RST_STREAM frame). This |
| 1026 | // may result in duplicate RST_STREAMs in some cases, but the client should |
| 1027 | // ignore those. |
| 1028 | if wr.StreamID() != 0 { |
| 1029 | _, isReset := wr.write.(StreamError) |
| 1030 | if state, _ := sc.state(wr.StreamID()); state == stateClosed && !isReset { |
| 1031 | ignoreWrite = true |
| 1032 | } |
| 1033 | } |
| 1034 | |
Brad Fitzpatrick | 0c60707 | 2016-05-21 00:18:04 +0000 | [diff] [blame] | 1035 | // Don't send a 100-continue response if we've already sent headers. |
| 1036 | // See golang.org/issue/14030. |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1037 | switch wr.write.(type) { |
Brad Fitzpatrick | 0c60707 | 2016-05-21 00:18:04 +0000 | [diff] [blame] | 1038 | case *writeResHeaders: |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1039 | wr.stream.wroteHeaders = true |
Brad Fitzpatrick | 0c60707 | 2016-05-21 00:18:04 +0000 | [diff] [blame] | 1040 | case write100ContinueHeadersFrame: |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1041 | if wr.stream.wroteHeaders { |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1042 | // We do not need to notify wr.done because this frame is |
| 1043 | // never written with wr.done != nil. |
| 1044 | if wr.done != nil { |
| 1045 | panic("wr.done != nil for write100ContinueHeadersFrame") |
| 1046 | } |
Brad Fitzpatrick | 0c60707 | 2016-05-21 00:18:04 +0000 | [diff] [blame] | 1047 | ignoreWrite = true |
| 1048 | } |
| 1049 | } |
| 1050 | |
| 1051 | if !ignoreWrite { |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1052 | sc.writeSched.Push(wr) |
Brad Fitzpatrick | 0c60707 | 2016-05-21 00:18:04 +0000 | [diff] [blame] | 1053 | } |
Tatsuhiro Tsujikawa | cc1e1da | 2014-12-02 20:04:27 +0900 | [diff] [blame] | 1054 | sc.scheduleFrameWrite() |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 1055 | } |
| 1056 | |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1057 | // startFrameWrite starts a goroutine to write wr (in a separate |
Brad Fitzpatrick | 165c098 | 2014-11-26 08:53:01 -0800 | [diff] [blame] | 1058 | // goroutine since that might block on the network), and updates the |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1059 | // serve goroutine's state about the world, updated from info in wr. |
| 1060 | func (sc *serverConn) startFrameWrite(wr FrameWriteRequest) { |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 1061 | sc.serveG.check() |
| 1062 | if sc.writingFrame { |
Brad Fitzpatrick | 165c098 | 2014-11-26 08:53:01 -0800 | [diff] [blame] | 1063 | panic("internal error: can only be writing one frame at a time") |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 1064 | } |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1065 | |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1066 | st := wr.stream |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1067 | if st != nil { |
| 1068 | switch st.state { |
| 1069 | case stateHalfClosedLocal: |
Tom Bergan | 4909c4c | 2016-12-15 11:30:25 -0800 | [diff] [blame] | 1070 | switch wr.write.(type) { |
| 1071 | case StreamError, handlerPanicRST, writeWindowUpdate: |
| 1072 | // RFC 7540 Section 5.1 allows sending RST_STREAM, PRIORITY, and WINDOW_UPDATE |
| 1073 | // in this state. (We never send PRIORITY from the server, so that is not checked.) |
| 1074 | default: |
| 1075 | panic(fmt.Sprintf("internal error: attempt to send frame on a half-closed-local stream: %v", wr)) |
| 1076 | } |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1077 | case stateClosed: |
Brad Fitzpatrick | 45e7717 | 2016-12-15 19:42:18 +0000 | [diff] [blame] | 1078 | panic(fmt.Sprintf("internal error: attempt to send frame on a closed stream: %v", wr)) |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1079 | } |
| 1080 | } |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1081 | if wpp, ok := wr.write.(*writePushPromise); ok { |
| 1082 | var err error |
| 1083 | wpp.promisedID, err = wpp.allocatePromisedID() |
| 1084 | if err != nil { |
Brad Fitzpatrick | b626cca | 2016-10-27 01:46:15 +0000 | [diff] [blame] | 1085 | sc.writingFrameAsync = false |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1086 | wr.replyToWriter(err) |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1087 | return |
| 1088 | } |
| 1089 | } |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1090 | |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 1091 | sc.writingFrame = true |
Brad Fitzpatrick | 5e4e2dc | 2014-11-19 16:49:43 -0800 | [diff] [blame] | 1092 | sc.needsFrameFlush = true |
Brad Fitzpatrick | e7b1435 | 2016-10-19 19:12:55 +0000 | [diff] [blame] | 1093 | if wr.write.staysWithinBuffer(sc.bw.Available()) { |
Brad Fitzpatrick | b626cca | 2016-10-27 01:46:15 +0000 | [diff] [blame] | 1094 | sc.writingFrameAsync = false |
Brad Fitzpatrick | e7b1435 | 2016-10-19 19:12:55 +0000 | [diff] [blame] | 1095 | err := wr.write.writeFrame(sc) |
| 1096 | sc.wroteFrame(frameWriteResult{wr, err}) |
| 1097 | } else { |
Brad Fitzpatrick | b626cca | 2016-10-27 01:46:15 +0000 | [diff] [blame] | 1098 | sc.writingFrameAsync = true |
Brad Fitzpatrick | e7b1435 | 2016-10-19 19:12:55 +0000 | [diff] [blame] | 1099 | go sc.writeFrameAsync(wr) |
| 1100 | } |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 1101 | } |
| 1102 | |
Brad Fitzpatrick | 74bd44b | 2015-12-15 00:47:28 +0000 | [diff] [blame] | 1103 | // errHandlerPanicked is the error given to any callers blocked in a read from |
| 1104 | // Request.Body when the main goroutine panics. Since most handlers read in the |
| 1105 | // the main ServeHTTP goroutine, this will show up rarely. |
| 1106 | var errHandlerPanicked = errors.New("http2: handler panicked") |
| 1107 | |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 1108 | // wroteFrame is called on the serve goroutine with the result of |
| 1109 | // whatever happened on writeFrameAsync. |
| 1110 | func (sc *serverConn) wroteFrame(res frameWriteResult) { |
| 1111 | sc.serveG.check() |
| 1112 | if !sc.writingFrame { |
| 1113 | panic("internal error: expected to be already writing a frame") |
| 1114 | } |
| 1115 | sc.writingFrame = false |
Brad Fitzpatrick | b626cca | 2016-10-27 01:46:15 +0000 | [diff] [blame] | 1116 | sc.writingFrameAsync = false |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 1117 | |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1118 | wr := res.wr |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 1119 | |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1120 | if writeEndsStream(wr.write) { |
| 1121 | st := wr.stream |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1122 | if st == nil { |
Brad Fitzpatrick | f16a0b3 | 2014-11-28 13:49:30 -0800 | [diff] [blame] | 1123 | panic("internal error: expecting non-nil stream") |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1124 | } |
| 1125 | switch st.state { |
| 1126 | case stateOpen: |
Brad Fitzpatrick | f3a6d9a | 2014-12-08 07:53:36 -0800 | [diff] [blame] | 1127 | // Here we would go to stateHalfClosedLocal in |
| 1128 | // theory, but since our handler is done and |
| 1129 | // the net/http package provides no mechanism |
Brad Fitzpatrick | 3bafa33 | 2016-10-19 14:40:54 +0000 | [diff] [blame] | 1130 | // for closing a ResponseWriter while still |
| 1131 | // reading data (see possible TODO at top of |
| 1132 | // this file), we go into closed state here |
| 1133 | // anyway, after telling the peer we're |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1134 | // hanging up on them. We'll transition to |
| 1135 | // stateClosed after the RST_STREAM frame is |
| 1136 | // written. |
| 1137 | st.state = stateHalfClosedLocal |
Tom Bergan | 5602c73 | 2017-04-13 10:15:43 -0700 | [diff] [blame] | 1138 | // Section 8.1: a server MAY request that the client abort |
| 1139 | // transmission of a request without error by sending a |
| 1140 | // RST_STREAM with an error code of NO_ERROR after sending |
| 1141 | // a complete response. |
| 1142 | sc.resetStream(streamError(st.id, ErrCodeNo)) |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1143 | case stateHalfClosedRemote: |
Brad Fitzpatrick | b7f5d98 | 2015-10-26 13:59:20 -0500 | [diff] [blame] | 1144 | sc.closeStream(st, errHandlerComplete) |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 1145 | } |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1146 | } else { |
| 1147 | switch v := wr.write.(type) { |
| 1148 | case StreamError: |
| 1149 | // st may be unknown if the RST_STREAM was generated to reject bad input. |
| 1150 | if st, ok := sc.streams[v.StreamID]; ok { |
| 1151 | sc.closeStream(st, v) |
| 1152 | } |
| 1153 | case handlerPanicRST: |
| 1154 | sc.closeStream(wr.stream, errHandlerPanicked) |
| 1155 | } |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 1156 | } |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 1157 | |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1158 | // Reply (if requested) to unblock the ServeHTTP goroutine. |
| 1159 | wr.replyToWriter(res.err) |
| 1160 | |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 1161 | sc.scheduleFrameWrite() |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 1162 | } |
| 1163 | |
Brad Fitzpatrick | 4e3c922 | 2014-11-22 17:35:09 -0800 | [diff] [blame] | 1164 | // scheduleFrameWrite tickles the frame writing scheduler. |
| 1165 | // |
| 1166 | // If a frame is already being written, nothing happens. This will be called again |
| 1167 | // when the frame is done being written. |
| 1168 | // |
| 1169 | // If a frame isn't being written we need to send one, the best frame |
| 1170 | // to send is selected, preferring first things that aren't |
| 1171 | // stream-specific (e.g. ACKing settings), and then finding the |
| 1172 | // highest priority stream. |
| 1173 | // |
| 1174 | // If a frame isn't being written and there's nothing else to send, we |
| 1175 | // flush the write buffer. |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 1176 | func (sc *serverConn) scheduleFrameWrite() { |
| 1177 | sc.serveG.check() |
Brad Fitzpatrick | b626cca | 2016-10-27 01:46:15 +0000 | [diff] [blame] | 1178 | if sc.writingFrame || sc.inFrameScheduleLoop { |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 1179 | return |
| 1180 | } |
Brad Fitzpatrick | b626cca | 2016-10-27 01:46:15 +0000 | [diff] [blame] | 1181 | sc.inFrameScheduleLoop = true |
| 1182 | for !sc.writingFrameAsync { |
| 1183 | if sc.needToSendGoAway { |
| 1184 | sc.needToSendGoAway = false |
| 1185 | sc.startFrameWrite(FrameWriteRequest{ |
| 1186 | write: &writeGoAway{ |
Tom Bergan | 55a3084 | 2016-11-04 15:18:50 -0700 | [diff] [blame] | 1187 | maxStreamID: sc.maxClientStreamID, |
Brad Fitzpatrick | b626cca | 2016-10-27 01:46:15 +0000 | [diff] [blame] | 1188 | code: sc.goAwayCode, |
| 1189 | }, |
| 1190 | }) |
| 1191 | continue |
Brad Fitzpatrick | 2b45947 | 2014-11-30 19:18:57 -0800 | [diff] [blame] | 1192 | } |
Brad Fitzpatrick | b626cca | 2016-10-27 01:46:15 +0000 | [diff] [blame] | 1193 | if sc.needToSendSettingsAck { |
| 1194 | sc.needToSendSettingsAck = false |
| 1195 | sc.startFrameWrite(FrameWriteRequest{write: writeSettingsAck{}}) |
| 1196 | continue |
| 1197 | } |
Brad Fitzpatrick | 73058b0 | 2016-10-30 16:20:31 +0000 | [diff] [blame] | 1198 | if !sc.inGoAway || sc.goAwayCode == ErrCodeNo { |
Brad Fitzpatrick | b626cca | 2016-10-27 01:46:15 +0000 | [diff] [blame] | 1199 | if wr, ok := sc.writeSched.Pop(); ok { |
| 1200 | sc.startFrameWrite(wr) |
| 1201 | continue |
| 1202 | } |
| 1203 | } |
| 1204 | if sc.needsFrameFlush { |
| 1205 | sc.startFrameWrite(FrameWriteRequest{write: flushFrameWriter{}}) |
| 1206 | sc.needsFrameFlush = false // after startFrameWrite, since it sets this true |
| 1207 | continue |
| 1208 | } |
| 1209 | break |
Brad Fitzpatrick | 2b45947 | 2014-11-30 19:18:57 -0800 | [diff] [blame] | 1210 | } |
Brad Fitzpatrick | b626cca | 2016-10-27 01:46:15 +0000 | [diff] [blame] | 1211 | sc.inFrameScheduleLoop = false |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 1212 | } |
| 1213 | |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 1214 | // startGracefulShutdown gracefully shuts down a connection. This |
| 1215 | // sends GOAWAY with ErrCodeNo to tell the client we're gracefully |
| 1216 | // shutting down. The connection isn't closed until all current |
| 1217 | // streams are done. |
| 1218 | // |
| 1219 | // startGracefulShutdown returns immediately; it does not wait until |
| 1220 | // the connection has shut down. |
Brad Fitzpatrick | 6dfeb34 | 2016-11-11 23:53:59 +0000 | [diff] [blame] | 1221 | func (sc *serverConn) startGracefulShutdown() { |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 1222 | sc.serveG.checkNotOn() // NOT |
| 1223 | sc.shutdownOnce.Do(func() { sc.sendServeMsg(gracefulShutdownMsg) }) |
| 1224 | } |
| 1225 | |
Tom Bergan | cd69bc3 | 2017-10-17 13:25:22 -0700 | [diff] [blame^] | 1226 | // After sending GOAWAY, the connection will close after goAwayTimeout. |
| 1227 | // If we close the connection immediately after sending GOAWAY, there may |
| 1228 | // be unsent data in our kernel receive buffer, which will cause the kernel |
| 1229 | // to send a TCP RST on close() instead of a FIN. This RST will abort the |
| 1230 | // connection immediately, whether or not the client had received the GOAWAY. |
| 1231 | // |
| 1232 | // Ideally we should delay for at least 1 RTT + epsilon so the client has |
| 1233 | // a chance to read the GOAWAY and stop sending messages. Measuring RTT |
| 1234 | // is hard, so we approximate with 1 second. See golang.org/issue/18701. |
| 1235 | // |
| 1236 | // This is a var so it can be shorter in tests, where all requests uses the |
| 1237 | // loopback interface making the expected RTT very small. |
| 1238 | // |
| 1239 | // TODO: configurable? |
| 1240 | var goAwayTimeout = 1 * time.Second |
| 1241 | |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 1242 | func (sc *serverConn) startGracefulShutdownInternal() { |
Tom Bergan | cd69bc3 | 2017-10-17 13:25:22 -0700 | [diff] [blame^] | 1243 | sc.goAway(ErrCodeNo) |
Brad Fitzpatrick | 6dfeb34 | 2016-11-11 23:53:59 +0000 | [diff] [blame] | 1244 | } |
| 1245 | |
Brad Fitzpatrick | 55815ec | 2014-11-15 13:29:57 -0800 | [diff] [blame] | 1246 | func (sc *serverConn) goAway(code ErrCode) { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1247 | sc.serveG.check() |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 1248 | if sc.inGoAway { |
Brad Fitzpatrick | 55815ec | 2014-11-15 13:29:57 -0800 | [diff] [blame] | 1249 | return |
| 1250 | } |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 1251 | sc.inGoAway = true |
| 1252 | sc.needToSendGoAway = true |
| 1253 | sc.goAwayCode = code |
| 1254 | sc.scheduleFrameWrite() |
| 1255 | } |
| 1256 | |
| 1257 | func (sc *serverConn) shutDownIn(d time.Duration) { |
| 1258 | sc.serveG.check() |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 1259 | sc.shutdownTimer = time.AfterFunc(d, sc.onShutdownTimer) |
Brad Fitzpatrick | 55815ec | 2014-11-15 13:29:57 -0800 | [diff] [blame] | 1260 | } |
| 1261 | |
Brad Fitzpatrick | 6ec1731 | 2014-11-23 10:07:07 -0800 | [diff] [blame] | 1262 | func (sc *serverConn) resetStream(se StreamError) { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1263 | sc.serveG.check() |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1264 | sc.writeFrame(FrameWriteRequest{write: se}) |
Brad Fitzpatrick | f3a6d9a | 2014-12-08 07:53:36 -0800 | [diff] [blame] | 1265 | if st, ok := sc.streams[se.StreamID]; ok { |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1266 | st.resetQueued = true |
Brad Fitzpatrick | f3a6d9a | 2014-12-08 07:53:36 -0800 | [diff] [blame] | 1267 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1268 | } |
| 1269 | |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1270 | // processFrameFromReader processes the serve loop's read from readFrameCh from the |
| 1271 | // frame-reading goroutine. |
| 1272 | // processFrameFromReader returns whether the connection should be kept open. |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 1273 | func (sc *serverConn) processFrameFromReader(res readFrameResult) bool { |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1274 | sc.serveG.check() |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 1275 | err := res.err |
| 1276 | if err != nil { |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 1277 | if err == ErrFrameTooLarge { |
| 1278 | sc.goAway(ErrCodeFrameSize) |
| 1279 | return true // goAway will close the loop |
| 1280 | } |
Brad Fitzpatrick | eb066e3 | 2016-01-26 18:31:02 +0000 | [diff] [blame] | 1281 | clientGone := err == io.EOF || err == io.ErrUnexpectedEOF || isClosedConnError(err) |
Brad Fitzpatrick | 8ec321e | 2014-11-25 14:08:16 -0800 | [diff] [blame] | 1282 | if clientGone { |
| 1283 | // TODO: could we also get into this state if |
| 1284 | // the peer does a half close |
| 1285 | // (e.g. CloseWrite) because they're done |
| 1286 | // sending frames but they're still wanting |
| 1287 | // our open replies? Investigate. |
Brad Fitzpatrick | b2ca8da | 2014-12-08 00:41:28 -0800 | [diff] [blame] | 1288 | // TODO: add CloseWrite to crypto/tls.Conn first |
| 1289 | // so we have a way to test this? I suppose |
| 1290 | // just for testing we could have a non-TLS mode. |
Brad Fitzpatrick | 8ec321e | 2014-11-25 14:08:16 -0800 | [diff] [blame] | 1291 | return false |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1292 | } |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 1293 | } else { |
| 1294 | f := res.f |
Brad Fitzpatrick | 415f191 | 2015-12-16 20:28:38 +0000 | [diff] [blame] | 1295 | if VerboseLogs { |
| 1296 | sc.vlogf("http2: server read frame %v", summarizeFrame(f)) |
| 1297 | } |
Brad Fitzpatrick | 8ec321e | 2014-11-25 14:08:16 -0800 | [diff] [blame] | 1298 | err = sc.processFrame(f) |
Brad Fitzpatrick | 8ec321e | 2014-11-25 14:08:16 -0800 | [diff] [blame] | 1299 | if err == nil { |
| 1300 | return true |
| 1301 | } |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1302 | } |
| 1303 | |
| 1304 | switch ev := err.(type) { |
| 1305 | case StreamError: |
Brad Fitzpatrick | 6ec1731 | 2014-11-23 10:07:07 -0800 | [diff] [blame] | 1306 | sc.resetStream(ev) |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1307 | return true |
| 1308 | case goAwayFlowError: |
Brad Fitzpatrick | 55815ec | 2014-11-15 13:29:57 -0800 | [diff] [blame] | 1309 | sc.goAway(ErrCodeFlowControl) |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1310 | return true |
| 1311 | case ConnectionError: |
Brad Fitzpatrick | 415f191 | 2015-12-16 20:28:38 +0000 | [diff] [blame] | 1312 | sc.logf("http2: server connection error from %v: %v", sc.conn.RemoteAddr(), ev) |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 1313 | sc.goAway(ErrCode(ev)) |
| 1314 | return true // goAway will handle shutdown |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1315 | default: |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 1316 | if res.err != nil { |
Brad Fitzpatrick | eb066e3 | 2016-01-26 18:31:02 +0000 | [diff] [blame] | 1317 | sc.vlogf("http2: server closing client connection; error reading frame from client %s: %v", sc.conn.RemoteAddr(), err) |
Brad Fitzpatrick | 8ec321e | 2014-11-25 14:08:16 -0800 | [diff] [blame] | 1318 | } else { |
Brad Fitzpatrick | 415f191 | 2015-12-16 20:28:38 +0000 | [diff] [blame] | 1319 | sc.logf("http2: server closing client connection: %v", err) |
Brad Fitzpatrick | 8ec321e | 2014-11-25 14:08:16 -0800 | [diff] [blame] | 1320 | } |
Brad Fitzpatrick | 271cfc1 | 2015-10-12 23:49:56 +0000 | [diff] [blame] | 1321 | return false |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1322 | } |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1323 | } |
| 1324 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1325 | func (sc *serverConn) processFrame(f Frame) error { |
| 1326 | sc.serveG.check() |
| 1327 | |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1328 | // First frame received must be SETTINGS. |
| 1329 | if !sc.sawFirstSettings { |
| 1330 | if _, ok := f.(*SettingsFrame); !ok { |
| 1331 | return ConnectionError(ErrCodeProtocol) |
| 1332 | } |
| 1333 | sc.sawFirstSettings = true |
| 1334 | } |
| 1335 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1336 | switch f := f.(type) { |
| 1337 | case *SettingsFrame: |
| 1338 | return sc.processSettings(f) |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1339 | case *MetaHeadersFrame: |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1340 | return sc.processHeaders(f) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1341 | case *WindowUpdateFrame: |
| 1342 | return sc.processWindowUpdate(f) |
| 1343 | case *PingFrame: |
| 1344 | return sc.processPing(f) |
| 1345 | case *DataFrame: |
| 1346 | return sc.processData(f) |
Brad Fitzpatrick | 6d3aa4f | 2014-11-15 14:55:57 -0800 | [diff] [blame] | 1347 | case *RSTStreamFrame: |
| 1348 | return sc.processResetStream(f) |
Brad Fitzpatrick | 2ee3a49 | 2014-11-30 23:18:32 -0800 | [diff] [blame] | 1349 | case *PriorityFrame: |
| 1350 | return sc.processPriority(f) |
Tom Bergan | 87635b2 | 2016-11-07 17:51:22 -0800 | [diff] [blame] | 1351 | case *GoAwayFrame: |
| 1352 | return sc.processGoAway(f) |
Daniel Morsing | 9f25169 | 2014-12-05 18:17:30 +0000 | [diff] [blame] | 1353 | case *PushPromiseFrame: |
| 1354 | // A client cannot push. Thus, servers MUST treat the receipt of a PUSH_PROMISE |
| 1355 | // frame as a connection error (Section 5.4.1) of type PROTOCOL_ERROR. |
| 1356 | return ConnectionError(ErrCodeProtocol) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1357 | default: |
Brad Fitzpatrick | 415f191 | 2015-12-16 20:28:38 +0000 | [diff] [blame] | 1358 | sc.vlogf("http2: server ignoring frame: %v", f.Header()) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1359 | return nil |
| 1360 | } |
| 1361 | } |
| 1362 | |
| 1363 | func (sc *serverConn) processPing(f *PingFrame) error { |
| 1364 | sc.serveG.check() |
Brad Fitzpatrick | a179abb | 2015-11-07 16:46:24 +0100 | [diff] [blame] | 1365 | if f.IsAck() { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1366 | // 6.7 PING: " An endpoint MUST NOT respond to PING frames |
| 1367 | // containing this flag." |
| 1368 | return nil |
| 1369 | } |
| 1370 | if f.StreamID != 0 { |
| 1371 | // "PING frames are not associated with any individual |
| 1372 | // stream. If a PING frame is received with a stream |
| 1373 | // identifier field value other than 0x0, the recipient MUST |
| 1374 | // respond with a connection error (Section 5.4.1) of type |
| 1375 | // PROTOCOL_ERROR." |
| 1376 | return ConnectionError(ErrCodeProtocol) |
| 1377 | } |
Brad Fitzpatrick | 569280f | 2016-11-03 00:14:07 +0000 | [diff] [blame] | 1378 | if sc.inGoAway && sc.goAwayCode != ErrCodeNo { |
Brad Fitzpatrick | c33d378 | 2016-10-22 11:37:19 -0700 | [diff] [blame] | 1379 | return nil |
| 1380 | } |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1381 | sc.writeFrame(FrameWriteRequest{write: writePingAck{f}}) |
Brad Fitzpatrick | 9e0eccc | 2014-11-15 09:14:49 -0800 | [diff] [blame] | 1382 | return nil |
| 1383 | } |
| 1384 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1385 | func (sc *serverConn) processWindowUpdate(f *WindowUpdateFrame) error { |
| 1386 | sc.serveG.check() |
| 1387 | switch { |
| 1388 | case f.StreamID != 0: // stream-level flow control |
Brad Fitzpatrick | 41c5c5c | 2016-10-21 05:57:00 -0700 | [diff] [blame] | 1389 | state, st := sc.state(f.StreamID) |
| 1390 | if state == stateIdle { |
| 1391 | // Section 5.1: "Receiving any frame other than HEADERS |
| 1392 | // or PRIORITY on a stream in this state MUST be |
| 1393 | // treated as a connection error (Section 5.4.1) of |
| 1394 | // type PROTOCOL_ERROR." |
| 1395 | return ConnectionError(ErrCodeProtocol) |
| 1396 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1397 | if st == nil { |
| 1398 | // "WINDOW_UPDATE can be sent by a peer that has sent a |
| 1399 | // frame bearing the END_STREAM flag. This means that a |
| 1400 | // receiver could receive a WINDOW_UPDATE frame on a "half |
| 1401 | // closed (remote)" or "closed" stream. A receiver MUST |
| 1402 | // NOT treat this as an error, see Section 5.1." |
| 1403 | return nil |
| 1404 | } |
| 1405 | if !st.flow.add(int32(f.Increment)) { |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1406 | return streamError(f.StreamID, ErrCodeFlowControl) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1407 | } |
| 1408 | default: // connection-level flow control |
| 1409 | if !sc.flow.add(int32(f.Increment)) { |
| 1410 | return goAwayFlowError{} |
| 1411 | } |
| 1412 | } |
Brad Fitzpatrick | 2b45947 | 2014-11-30 19:18:57 -0800 | [diff] [blame] | 1413 | sc.scheduleFrameWrite() |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1414 | return nil |
| 1415 | } |
| 1416 | |
Brad Fitzpatrick | 6d3aa4f | 2014-11-15 14:55:57 -0800 | [diff] [blame] | 1417 | func (sc *serverConn) processResetStream(f *RSTStreamFrame) error { |
| 1418 | sc.serveG.check() |
Brad Fitzpatrick | a98415a | 2014-12-08 00:47:45 -0800 | [diff] [blame] | 1419 | |
| 1420 | state, st := sc.state(f.StreamID) |
| 1421 | if state == stateIdle { |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1422 | // 6.4 "RST_STREAM frames MUST NOT be sent for a |
| 1423 | // stream in the "idle" state. If a RST_STREAM frame |
| 1424 | // identifying an idle stream is received, the |
| 1425 | // recipient MUST treat this as a connection error |
| 1426 | // (Section 5.4.1) of type PROTOCOL_ERROR. |
| 1427 | return ConnectionError(ErrCodeProtocol) |
| 1428 | } |
Brad Fitzpatrick | a98415a | 2014-12-08 00:47:45 -0800 | [diff] [blame] | 1429 | if st != nil { |
Brad Fitzpatrick | 8aacbec | 2016-05-18 19:54:31 +0000 | [diff] [blame] | 1430 | st.cancelCtx() |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1431 | sc.closeStream(st, streamError(f.StreamID, f.ErrCode)) |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1432 | } |
Brad Fitzpatrick | 6d3aa4f | 2014-11-15 14:55:57 -0800 | [diff] [blame] | 1433 | return nil |
| 1434 | } |
| 1435 | |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1436 | func (sc *serverConn) closeStream(st *stream, err error) { |
Brad Fitzpatrick | 6d3aa4f | 2014-11-15 14:55:57 -0800 | [diff] [blame] | 1437 | sc.serveG.check() |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1438 | if st.state == stateIdle || st.state == stateClosed { |
Brad Fitzpatrick | f3a6d9a | 2014-12-08 07:53:36 -0800 | [diff] [blame] | 1439 | panic(fmt.Sprintf("invariant; can't close stream in state %v", st.state)) |
Brad Fitzpatrick | 6d3aa4f | 2014-11-15 14:55:57 -0800 | [diff] [blame] | 1440 | } |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1441 | st.state = stateClosed |
Kale Blankenship | d1e1b35 | 2016-12-29 14:47:41 -0800 | [diff] [blame] | 1442 | if st.writeDeadline != nil { |
| 1443 | st.writeDeadline.Stop() |
| 1444 | } |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1445 | if st.isPushed() { |
| 1446 | sc.curPushedStreams-- |
| 1447 | } else { |
| 1448 | sc.curClientStreams-- |
| 1449 | } |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1450 | delete(sc.streams, st.id) |
Brad Fitzpatrick | 6dfeb34 | 2016-11-11 23:53:59 +0000 | [diff] [blame] | 1451 | if len(sc.streams) == 0 { |
| 1452 | sc.setConnState(http.StateIdle) |
| 1453 | if sc.srv.IdleTimeout != 0 { |
| 1454 | sc.idleTimer.Reset(sc.srv.IdleTimeout) |
| 1455 | } |
| 1456 | if h1ServerKeepAlivesDisabled(sc.hs) { |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 1457 | sc.startGracefulShutdownInternal() |
Brad Fitzpatrick | 6dfeb34 | 2016-11-11 23:53:59 +0000 | [diff] [blame] | 1458 | } |
Brad Fitzpatrick | c33d378 | 2016-10-22 11:37:19 -0700 | [diff] [blame] | 1459 | } |
Brad Fitzpatrick | 6d3aa4f | 2014-11-15 14:55:57 -0800 | [diff] [blame] | 1460 | if p := st.body; p != nil { |
Brad Fitzpatrick | 6a513af | 2016-07-26 10:19:14 +0200 | [diff] [blame] | 1461 | // Return any buffered unread bytes worth of conn-level flow control. |
| 1462 | // See golang.org/issue/16481 |
| 1463 | sc.sendWindowUpdate(nil, p.Len()) |
| 1464 | |
Brad Fitzpatrick | b7f5d98 | 2015-10-26 13:59:20 -0500 | [diff] [blame] | 1465 | p.CloseWithError(err) |
Brad Fitzpatrick | 6d3aa4f | 2014-11-15 14:55:57 -0800 | [diff] [blame] | 1466 | } |
Brad Fitzpatrick | 2b45947 | 2014-11-30 19:18:57 -0800 | [diff] [blame] | 1467 | st.cw.Close() // signals Handler's CloseNotifier, unblocks writes, etc |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1468 | sc.writeSched.CloseStream(st.id) |
Brad Fitzpatrick | 6d3aa4f | 2014-11-15 14:55:57 -0800 | [diff] [blame] | 1469 | } |
| 1470 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1471 | func (sc *serverConn) processSettings(f *SettingsFrame) error { |
| 1472 | sc.serveG.check() |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1473 | if f.IsAck() { |
Brad Fitzpatrick | 6a9b77b | 2014-12-03 13:56:36 -0800 | [diff] [blame] | 1474 | sc.unackedSettings-- |
| 1475 | if sc.unackedSettings < 0 { |
| 1476 | // Why is the peer ACKing settings we never sent? |
| 1477 | // The spec doesn't mention this case, but |
| 1478 | // hang up on them anyway. |
| 1479 | return ConnectionError(ErrCodeProtocol) |
| 1480 | } |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1481 | return nil |
| 1482 | } |
| 1483 | if err := f.ForeachSetting(sc.processSetting); err != nil { |
| 1484 | return err |
| 1485 | } |
Brad Fitzpatrick | 4e3c922 | 2014-11-22 17:35:09 -0800 | [diff] [blame] | 1486 | sc.needToSendSettingsAck = true |
| 1487 | sc.scheduleFrameWrite() |
Brad Fitzpatrick | d07a0e4 | 2014-11-15 10:47:12 -0800 | [diff] [blame] | 1488 | return nil |
| 1489 | } |
| 1490 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1491 | func (sc *serverConn) processSetting(s Setting) error { |
| 1492 | sc.serveG.check() |
Brad Fitzpatrick | bc00c57 | 2014-11-17 12:28:01 -0800 | [diff] [blame] | 1493 | if err := s.Valid(); err != nil { |
| 1494 | return err |
| 1495 | } |
Brad Fitzpatrick | 415f191 | 2015-12-16 20:28:38 +0000 | [diff] [blame] | 1496 | if VerboseLogs { |
| 1497 | sc.vlogf("http2: server processing setting %v", s) |
| 1498 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1499 | switch s.ID { |
Brad Fitzpatrick | bc00c57 | 2014-11-17 12:28:01 -0800 | [diff] [blame] | 1500 | case SettingHeaderTableSize: |
| 1501 | sc.headerTableSize = s.Val |
Tatsuhiro Tsujikawa | c7d67a5 | 2014-11-20 01:01:39 +0900 | [diff] [blame] | 1502 | sc.hpackEncoder.SetMaxDynamicTableSize(s.Val) |
Brad Fitzpatrick | bc00c57 | 2014-11-17 12:28:01 -0800 | [diff] [blame] | 1503 | case SettingEnablePush: |
| 1504 | sc.pushEnabled = s.Val != 0 |
Brad Fitzpatrick | bc00c57 | 2014-11-17 12:28:01 -0800 | [diff] [blame] | 1505 | case SettingMaxConcurrentStreams: |
Brad Fitzpatrick | 6ec1731 | 2014-11-23 10:07:07 -0800 | [diff] [blame] | 1506 | sc.clientMaxStreams = s.Val |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1507 | case SettingInitialWindowSize: |
| 1508 | return sc.processSettingInitialWindowSize(s.Val) |
Brad Fitzpatrick | bc00c57 | 2014-11-17 12:28:01 -0800 | [diff] [blame] | 1509 | case SettingMaxFrameSize: |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1510 | sc.maxFrameSize = int32(s.Val) // the maximum valid s.Val is < 2^31 |
Brad Fitzpatrick | bc00c57 | 2014-11-17 12:28:01 -0800 | [diff] [blame] | 1511 | case SettingMaxHeaderListSize: |
Brad Fitzpatrick | 29704b8 | 2015-10-10 18:01:18 -0700 | [diff] [blame] | 1512 | sc.peerMaxHeaderListSize = s.Val |
gbbr | 0b3b574 | 2014-11-23 00:44:48 +0000 | [diff] [blame] | 1513 | default: |
| 1514 | // Unknown setting: "An endpoint that receives a SETTINGS |
| 1515 | // frame with any unknown or unsupported identifier MUST |
| 1516 | // ignore that setting." |
Brad Fitzpatrick | 415f191 | 2015-12-16 20:28:38 +0000 | [diff] [blame] | 1517 | if VerboseLogs { |
| 1518 | sc.vlogf("http2: server ignoring unknown setting %v", s) |
| 1519 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1520 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1521 | return nil |
| 1522 | } |
| 1523 | |
| 1524 | func (sc *serverConn) processSettingInitialWindowSize(val uint32) error { |
| 1525 | sc.serveG.check() |
Brad Fitzpatrick | bc00c57 | 2014-11-17 12:28:01 -0800 | [diff] [blame] | 1526 | // Note: val already validated to be within range by |
| 1527 | // processSetting's Valid call. |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1528 | |
| 1529 | // "A SETTINGS frame can alter the initial flow control window |
| 1530 | // size for all current streams. When the value of |
| 1531 | // SETTINGS_INITIAL_WINDOW_SIZE changes, a receiver MUST |
| 1532 | // adjust the size of all stream flow control windows that it |
| 1533 | // maintains by the difference between the new value and the |
| 1534 | // old value." |
Tom Bergan | 906cda9 | 2017-02-18 12:36:51 -0800 | [diff] [blame] | 1535 | old := sc.initialStreamSendWindowSize |
| 1536 | sc.initialStreamSendWindowSize = int32(val) |
| 1537 | growth := int32(val) - old // may be negative |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1538 | for _, st := range sc.streams { |
| 1539 | if !st.flow.add(growth) { |
| 1540 | // 6.9.2 Initial Flow Control Window Size |
| 1541 | // "An endpoint MUST treat a change to |
| 1542 | // SETTINGS_INITIAL_WINDOW_SIZE that causes any flow |
| 1543 | // control window to exceed the maximum size as a |
| 1544 | // connection error (Section 5.4.1) of type |
| 1545 | // FLOW_CONTROL_ERROR." |
| 1546 | return ConnectionError(ErrCodeFlowControl) |
| 1547 | } |
| 1548 | } |
| 1549 | return nil |
| 1550 | } |
| 1551 | |
| 1552 | func (sc *serverConn) processData(f *DataFrame) error { |
| 1553 | sc.serveG.check() |
Brad Fitzpatrick | 569280f | 2016-11-03 00:14:07 +0000 | [diff] [blame] | 1554 | if sc.inGoAway && sc.goAwayCode != ErrCodeNo { |
Brad Fitzpatrick | c33d378 | 2016-10-22 11:37:19 -0700 | [diff] [blame] | 1555 | return nil |
| 1556 | } |
Brad Fitzpatrick | 6a513af | 2016-07-26 10:19:14 +0200 | [diff] [blame] | 1557 | data := f.Data() |
| 1558 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1559 | // "If a DATA frame is received whose stream is not in "open" |
| 1560 | // or "half closed (local)" state, the recipient MUST respond |
| 1561 | // with a stream error (Section 5.4.2) of type STREAM_CLOSED." |
| 1562 | id := f.Header().StreamID |
Brad Fitzpatrick | 41c5c5c | 2016-10-21 05:57:00 -0700 | [diff] [blame] | 1563 | state, st := sc.state(id) |
| 1564 | if id == 0 || state == stateIdle { |
| 1565 | // Section 5.1: "Receiving any frame other than HEADERS |
| 1566 | // or PRIORITY on a stream in this state MUST be |
| 1567 | // treated as a connection error (Section 5.4.1) of |
| 1568 | // type PROTOCOL_ERROR." |
| 1569 | return ConnectionError(ErrCodeProtocol) |
| 1570 | } |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1571 | if st == nil || state != stateOpen || st.gotTrailerHeader || st.resetQueued { |
Brad Fitzpatrick | f3a6d9a | 2014-12-08 07:53:36 -0800 | [diff] [blame] | 1572 | // This includes sending a RST_STREAM if the stream is |
| 1573 | // in stateHalfClosedLocal (which currently means that |
| 1574 | // the http.Handler returned, so it's done reading & |
| 1575 | // done writing). Try to stop the client from sending |
| 1576 | // more DATA. |
Brad Fitzpatrick | 6a513af | 2016-07-26 10:19:14 +0200 | [diff] [blame] | 1577 | |
| 1578 | // But still enforce their connection-level flow control, |
| 1579 | // and return any flow control bytes since we're not going |
| 1580 | // to consume them. |
Brad Fitzpatrick | 35028a4 | 2016-07-31 15:09:09 -0700 | [diff] [blame] | 1581 | if sc.inflow.available() < int32(f.Length) { |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1582 | return streamError(id, ErrCodeFlowControl) |
Brad Fitzpatrick | 6a513af | 2016-07-26 10:19:14 +0200 | [diff] [blame] | 1583 | } |
| 1584 | // Deduct the flow control from inflow, since we're |
| 1585 | // going to immediately add it back in |
| 1586 | // sendWindowUpdate, which also schedules sending the |
| 1587 | // frames. |
Brad Fitzpatrick | 35028a4 | 2016-07-31 15:09:09 -0700 | [diff] [blame] | 1588 | sc.inflow.take(int32(f.Length)) |
| 1589 | sc.sendWindowUpdate(nil, int(f.Length)) // conn-level |
Brad Fitzpatrick | 6a513af | 2016-07-26 10:19:14 +0200 | [diff] [blame] | 1590 | |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1591 | if st != nil && st.resetQueued { |
| 1592 | // Already have a stream error in flight. Don't send another. |
| 1593 | return nil |
| 1594 | } |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1595 | return streamError(id, ErrCodeStreamClosed) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1596 | } |
| 1597 | if st.body == nil { |
Brad Fitzpatrick | b0a06c8 | 2014-11-26 09:21:28 -0800 | [diff] [blame] | 1598 | panic("internal error: should have a body in this state") |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1599 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1600 | |
| 1601 | // Sender sending more than they'd declared? |
| 1602 | if st.declBodyBytes != -1 && st.bodyBytes+int64(len(data)) > st.declBodyBytes { |
Brad Fitzpatrick | b7f5d98 | 2015-10-26 13:59:20 -0500 | [diff] [blame] | 1603 | st.body.CloseWithError(fmt.Errorf("sender tried to send more than declared Content-Length of %d bytes", st.declBodyBytes)) |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1604 | return streamError(id, ErrCodeStreamClosed) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1605 | } |
Brad Fitzpatrick | 35028a4 | 2016-07-31 15:09:09 -0700 | [diff] [blame] | 1606 | if f.Length > 0 { |
Brad Fitzpatrick | 068d35d | 2014-12-09 07:10:31 +1100 | [diff] [blame] | 1607 | // Check whether the client has flow control quota. |
Brad Fitzpatrick | 35028a4 | 2016-07-31 15:09:09 -0700 | [diff] [blame] | 1608 | if st.inflow.available() < int32(f.Length) { |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1609 | return streamError(id, ErrCodeFlowControl) |
Brad Fitzpatrick | 068d35d | 2014-12-09 07:10:31 +1100 | [diff] [blame] | 1610 | } |
Brad Fitzpatrick | 35028a4 | 2016-07-31 15:09:09 -0700 | [diff] [blame] | 1611 | st.inflow.take(int32(f.Length)) |
| 1612 | |
| 1613 | if len(data) > 0 { |
| 1614 | wrote, err := st.body.Write(data) |
| 1615 | if err != nil { |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1616 | return streamError(id, ErrCodeStreamClosed) |
Brad Fitzpatrick | 35028a4 | 2016-07-31 15:09:09 -0700 | [diff] [blame] | 1617 | } |
| 1618 | if wrote != len(data) { |
| 1619 | panic("internal error: bad Writer") |
| 1620 | } |
| 1621 | st.bodyBytes += int64(len(data)) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1622 | } |
Brad Fitzpatrick | 35028a4 | 2016-07-31 15:09:09 -0700 | [diff] [blame] | 1623 | |
| 1624 | // Return any padded flow control now, since we won't |
| 1625 | // refund it later on body reads. |
| 1626 | if pad := int32(f.Length) - int32(len(data)); pad > 0 { |
| 1627 | sc.sendWindowUpdate32(nil, pad) |
| 1628 | sc.sendWindowUpdate32(st, pad) |
Brad Fitzpatrick | 0218ba6 | 2014-11-26 09:36:05 -0800 | [diff] [blame] | 1629 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1630 | } |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 1631 | if f.StreamEnded() { |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1632 | st.endStream() |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1633 | } |
| 1634 | return nil |
| 1635 | } |
| 1636 | |
Tom Bergan | 87635b2 | 2016-11-07 17:51:22 -0800 | [diff] [blame] | 1637 | func (sc *serverConn) processGoAway(f *GoAwayFrame) error { |
| 1638 | sc.serveG.check() |
| 1639 | if f.ErrCode != ErrCodeNo { |
| 1640 | sc.logf("http2: received GOAWAY %+v, starting graceful shutdown", f) |
| 1641 | } else { |
| 1642 | sc.vlogf("http2: received GOAWAY %+v, starting graceful shutdown", f) |
| 1643 | } |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 1644 | sc.startGracefulShutdownInternal() |
Tom Bergan | 87635b2 | 2016-11-07 17:51:22 -0800 | [diff] [blame] | 1645 | // http://tools.ietf.org/html/rfc7540#section-6.8 |
| 1646 | // We should not create any new streams, which means we should disable push. |
| 1647 | sc.pushEnabled = false |
| 1648 | return nil |
| 1649 | } |
| 1650 | |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1651 | // isPushed reports whether the stream is server-initiated. |
| 1652 | func (st *stream) isPushed() bool { |
| 1653 | return st.id%2 == 0 |
| 1654 | } |
| 1655 | |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1656 | // endStream closes a Request.Body's pipe. It is called when a DATA |
| 1657 | // frame says a request body is over (or after trailers). |
| 1658 | func (st *stream) endStream() { |
| 1659 | sc := st.sc |
| 1660 | sc.serveG.check() |
| 1661 | |
| 1662 | if st.declBodyBytes != -1 && st.declBodyBytes != st.bodyBytes { |
| 1663 | st.body.CloseWithError(fmt.Errorf("request declared a Content-Length of %d but only wrote %d bytes", |
| 1664 | st.declBodyBytes, st.bodyBytes)) |
| 1665 | } else { |
| 1666 | st.body.closeWithErrorAndCode(io.EOF, st.copyTrailersToHandlerRequest) |
| 1667 | st.body.CloseWithError(io.EOF) |
| 1668 | } |
| 1669 | st.state = stateHalfClosedRemote |
| 1670 | } |
| 1671 | |
| 1672 | // copyTrailersToHandlerRequest is run in the Handler's goroutine in |
| 1673 | // its Request.Body.Read just before it gets io.EOF. |
| 1674 | func (st *stream) copyTrailersToHandlerRequest() { |
| 1675 | for k, vv := range st.trailer { |
| 1676 | if _, ok := st.reqTrailer[k]; ok { |
| 1677 | // Only copy it over it was pre-declared. |
| 1678 | st.reqTrailer[k] = vv |
| 1679 | } |
| 1680 | } |
| 1681 | } |
| 1682 | |
Kale Blankenship | d1e1b35 | 2016-12-29 14:47:41 -0800 | [diff] [blame] | 1683 | // onWriteTimeout is run on its own goroutine (from time.AfterFunc) |
| 1684 | // when the stream's WriteTimeout has fired. |
| 1685 | func (st *stream) onWriteTimeout() { |
| 1686 | st.sc.writeFrameFromHandler(FrameWriteRequest{write: streamError(st.id, ErrCodeInternal)}) |
| 1687 | } |
| 1688 | |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1689 | func (sc *serverConn) processHeaders(f *MetaHeadersFrame) error { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1690 | sc.serveG.check() |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1691 | id := f.StreamID |
Brad Fitzpatrick | 21896bb | 2014-11-19 16:05:21 -0800 | [diff] [blame] | 1692 | if sc.inGoAway { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1693 | // Ignore. |
| 1694 | return nil |
| 1695 | } |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1696 | // http://tools.ietf.org/html/rfc7540#section-5.1.1 |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1697 | // Streams initiated by a client MUST use odd-numbered stream |
| 1698 | // identifiers. [...] An endpoint that receives an unexpected |
| 1699 | // stream identifier MUST respond with a connection error |
| 1700 | // (Section 5.4.1) of type PROTOCOL_ERROR. |
| 1701 | if id%2 != 1 { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1702 | return ConnectionError(ErrCodeProtocol) |
| 1703 | } |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1704 | // A HEADERS frame can be used to create a new stream or |
| 1705 | // send a trailer for an open one. If we already have a stream |
| 1706 | // open, let it process its own HEADERS frame (trailers at this |
| 1707 | // point, if it's valid). |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1708 | if st := sc.streams[f.StreamID]; st != nil { |
Tom Bergan | 3d9a20a | 2016-12-08 17:01:56 -0800 | [diff] [blame] | 1709 | if st.resetQueued { |
| 1710 | // We're sending RST_STREAM to close the stream, so don't bother |
| 1711 | // processing this frame. |
| 1712 | return nil |
| 1713 | } |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1714 | return st.processTrailerHeaders(f) |
| 1715 | } |
| 1716 | |
| 1717 | // [...] The identifier of a newly established stream MUST be |
| 1718 | // numerically greater than all streams that the initiating |
| 1719 | // endpoint has opened or reserved. [...] An endpoint that |
| 1720 | // receives an unexpected stream identifier MUST respond with |
| 1721 | // a connection error (Section 5.4.1) of type PROTOCOL_ERROR. |
Tom Bergan | 55a3084 | 2016-11-04 15:18:50 -0700 | [diff] [blame] | 1722 | if id <= sc.maxClientStreamID { |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1723 | return ConnectionError(ErrCodeProtocol) |
| 1724 | } |
Tom Bergan | 55a3084 | 2016-11-04 15:18:50 -0700 | [diff] [blame] | 1725 | sc.maxClientStreamID = id |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1726 | |
Brad Fitzpatrick | c33d378 | 2016-10-22 11:37:19 -0700 | [diff] [blame] | 1727 | if sc.idleTimer != nil { |
| 1728 | sc.idleTimer.Stop() |
| 1729 | } |
| 1730 | |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1731 | // http://tools.ietf.org/html/rfc7540#section-5.1.2 |
| 1732 | // [...] Endpoints MUST NOT exceed the limit set by their peer. An |
| 1733 | // endpoint that receives a HEADERS frame that causes their |
| 1734 | // advertised concurrent stream limit to be exceeded MUST treat |
| 1735 | // this as a stream error (Section 5.4.2) of type PROTOCOL_ERROR |
| 1736 | // or REFUSED_STREAM. |
| 1737 | if sc.curClientStreams+1 > sc.advMaxStreams { |
Brad Fitzpatrick | 6a9b77b | 2014-12-03 13:56:36 -0800 | [diff] [blame] | 1738 | if sc.unackedSettings == 0 { |
| 1739 | // They should know better. |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1740 | return streamError(id, ErrCodeProtocol) |
Brad Fitzpatrick | 6a9b77b | 2014-12-03 13:56:36 -0800 | [diff] [blame] | 1741 | } |
| 1742 | // Assume it's a network race, where they just haven't |
| 1743 | // received our last SETTINGS update. But actually |
| 1744 | // this can't happen yet, because we don't yet provide |
| 1745 | // a way for users to adjust server parameters at |
| 1746 | // runtime. |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1747 | return streamError(id, ErrCodeRefusedStream) |
Brad Fitzpatrick | b3e0a87 | 2014-11-23 21:15:59 -0800 | [diff] [blame] | 1748 | } |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1749 | |
| 1750 | initialState := stateOpen |
| 1751 | if f.StreamEnded() { |
| 1752 | initialState = stateHalfClosedRemote |
| 1753 | } |
| 1754 | st := sc.newStream(id, 0, initialState) |
| 1755 | |
Tom Bergan | 65dfc08 | 2016-10-24 15:38:16 -0700 | [diff] [blame] | 1756 | if f.HasPriority() { |
| 1757 | if err := checkPriority(f.StreamID, f.Priority); err != nil { |
| 1758 | return err |
| 1759 | } |
| 1760 | sc.writeSched.AdjustStream(st.id, f.Priority) |
| 1761 | } |
Brad Fitzpatrick | b3e0a87 | 2014-11-23 21:15:59 -0800 | [diff] [blame] | 1762 | |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1763 | rw, req, err := sc.newWriterAndRequest(st, f) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1764 | if err != nil { |
| 1765 | return err |
| 1766 | } |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1767 | st.reqTrailer = req.Trailer |
| 1768 | if st.reqTrailer != nil { |
| 1769 | st.trailer = make(http.Header) |
| 1770 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1771 | st.body = req.Body.(*requestBody).pipe // may be nil |
| 1772 | st.declBodyBytes = req.ContentLength |
Brad Fitzpatrick | d8f3c68 | 2015-10-12 20:56:49 +0000 | [diff] [blame] | 1773 | |
| 1774 | handler := sc.handler.ServeHTTP |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1775 | if f.Truncated { |
Brad Fitzpatrick | d8f3c68 | 2015-10-12 20:56:49 +0000 | [diff] [blame] | 1776 | // Their header list was too long. Send a 431 error. |
| 1777 | handler = handleHeaderListTooLong |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1778 | } else if err := checkValidHTTP2RequestHeaders(req.Header); err != nil { |
Brad Fitzpatrick | af4fee9 | 2016-04-05 16:55:11 +0000 | [diff] [blame] | 1779 | handler = new400Handler(err) |
Brad Fitzpatrick | d8f3c68 | 2015-10-12 20:56:49 +0000 | [diff] [blame] | 1780 | } |
| 1781 | |
Brad Fitzpatrick | 6972930 | 2016-09-29 17:31:05 -0700 | [diff] [blame] | 1782 | // The net/http package sets the read deadline from the |
| 1783 | // http.Server.ReadTimeout during the TLS handshake, but then |
| 1784 | // passes the connection off to us with the deadline already |
Brad Fitzpatrick | b336a97 | 2016-10-27 19:58:04 +0000 | [diff] [blame] | 1785 | // set. Disarm it here after the request headers are read, |
| 1786 | // similar to how the http1 server works. Here it's |
| 1787 | // technically more like the http1 Server's ReadHeaderTimeout |
| 1788 | // (in Go 1.8), though. That's a more sane option anyway. |
Brad Fitzpatrick | 6972930 | 2016-09-29 17:31:05 -0700 | [diff] [blame] | 1789 | if sc.hs.ReadTimeout != 0 { |
| 1790 | sc.conn.SetReadDeadline(time.Time{}) |
| 1791 | } |
| 1792 | |
Brad Fitzpatrick | d8f3c68 | 2015-10-12 20:56:49 +0000 | [diff] [blame] | 1793 | go sc.runHandler(rw, req, handler) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1794 | return nil |
| 1795 | } |
| 1796 | |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1797 | func (st *stream) processTrailerHeaders(f *MetaHeadersFrame) error { |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1798 | sc := st.sc |
| 1799 | sc.serveG.check() |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1800 | if st.gotTrailerHeader { |
| 1801 | return ConnectionError(ErrCodeProtocol) |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1802 | } |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1803 | st.gotTrailerHeader = true |
| 1804 | if !f.StreamEnded() { |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1805 | return streamError(st.id, ErrCodeProtocol) |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1806 | } |
Brad Fitzpatrick | f530c4e | 2016-01-07 08:16:00 -0800 | [diff] [blame] | 1807 | |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1808 | if len(f.PseudoFields()) > 0 { |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1809 | return streamError(st.id, ErrCodeProtocol) |
Brad Fitzpatrick | f530c4e | 2016-01-07 08:16:00 -0800 | [diff] [blame] | 1810 | } |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1811 | if st.trailer != nil { |
| 1812 | for _, hf := range f.RegularFields() { |
| 1813 | key := sc.canonicalHeader(hf.Name) |
Brad Fitzpatrick | 3c5cb15 | 2016-05-19 01:21:59 +0000 | [diff] [blame] | 1814 | if !ValidTrailerHeader(key) { |
| 1815 | // TODO: send more details to the peer somehow. But http2 has |
| 1816 | // no way to send debug data at a stream level. Discuss with |
| 1817 | // HTTP folk. |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1818 | return streamError(st.id, ErrCodeProtocol) |
Brad Fitzpatrick | 3c5cb15 | 2016-05-19 01:21:59 +0000 | [diff] [blame] | 1819 | } |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1820 | st.trailer[key] = append(st.trailer[key], hf.Value) |
| 1821 | } |
| 1822 | } |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1823 | st.endStream() |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1824 | return nil |
| 1825 | } |
| 1826 | |
Tom Bergan | 65dfc08 | 2016-10-24 15:38:16 -0700 | [diff] [blame] | 1827 | func checkPriority(streamID uint32, p PriorityParam) error { |
| 1828 | if streamID == p.StreamDep { |
| 1829 | // Section 5.3.1: "A stream cannot depend on itself. An endpoint MUST treat |
| 1830 | // this as a stream error (Section 5.4.2) of type PROTOCOL_ERROR." |
| 1831 | // Section 5.3.3 says that a stream can depend on one of its dependencies, |
| 1832 | // so it's only self-dependencies that are forbidden. |
| 1833 | return streamError(streamID, ErrCodeProtocol) |
| 1834 | } |
| 1835 | return nil |
| 1836 | } |
| 1837 | |
Brad Fitzpatrick | 2ee3a49 | 2014-11-30 23:18:32 -0800 | [diff] [blame] | 1838 | func (sc *serverConn) processPriority(f *PriorityFrame) error { |
Brad Fitzpatrick | c33d378 | 2016-10-22 11:37:19 -0700 | [diff] [blame] | 1839 | if sc.inGoAway { |
| 1840 | return nil |
| 1841 | } |
Tom Bergan | 65dfc08 | 2016-10-24 15:38:16 -0700 | [diff] [blame] | 1842 | if err := checkPriority(f.StreamID, f.PriorityParam); err != nil { |
| 1843 | return err |
| 1844 | } |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 1845 | sc.writeSched.AdjustStream(f.StreamID, f.PriorityParam) |
Brad Fitzpatrick | 2ee3a49 | 2014-11-30 23:18:32 -0800 | [diff] [blame] | 1846 | return nil |
| 1847 | } |
| 1848 | |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1849 | func (sc *serverConn) newStream(id, pusherID uint32, state streamState) *stream { |
| 1850 | sc.serveG.check() |
| 1851 | if id == 0 { |
| 1852 | panic("internal error: cannot create stream with id 0") |
| 1853 | } |
| 1854 | |
| 1855 | ctx, cancelCtx := contextWithCancel(sc.baseCtx) |
| 1856 | st := &stream{ |
| 1857 | sc: sc, |
| 1858 | id: id, |
| 1859 | state: state, |
| 1860 | ctx: ctx, |
| 1861 | cancelCtx: cancelCtx, |
| 1862 | } |
| 1863 | st.cw.Init() |
| 1864 | st.flow.conn = &sc.flow // link to conn-level counter |
Tom Bergan | 906cda9 | 2017-02-18 12:36:51 -0800 | [diff] [blame] | 1865 | st.flow.add(sc.initialStreamSendWindowSize) |
| 1866 | st.inflow.conn = &sc.inflow // link to conn-level counter |
| 1867 | st.inflow.add(sc.srv.initialStreamRecvWindowSize()) |
Kale Blankenship | d1e1b35 | 2016-12-29 14:47:41 -0800 | [diff] [blame] | 1868 | if sc.hs.WriteTimeout != 0 { |
| 1869 | st.writeDeadline = time.AfterFunc(sc.hs.WriteTimeout, st.onWriteTimeout) |
| 1870 | } |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1871 | |
| 1872 | sc.streams[id] = st |
| 1873 | sc.writeSched.OpenStream(st.id, OpenStreamOptions{PusherID: pusherID}) |
| 1874 | if st.isPushed() { |
| 1875 | sc.curPushedStreams++ |
| 1876 | } else { |
| 1877 | sc.curClientStreams++ |
| 1878 | } |
Tom Bergan | 0c96df3 | 2016-12-05 22:33:37 -0800 | [diff] [blame] | 1879 | if sc.curOpenStreams() == 1 { |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1880 | sc.setConnState(http.StateActive) |
| 1881 | } |
| 1882 | |
| 1883 | return st |
| 1884 | } |
| 1885 | |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1886 | func (sc *serverConn) newWriterAndRequest(st *stream, f *MetaHeadersFrame) (*responseWriter, *http.Request, error) { |
Brad Fitzpatrick | b3e0a87 | 2014-11-23 21:15:59 -0800 | [diff] [blame] | 1887 | sc.serveG.check() |
Brad Fitzpatrick | b3e0a87 | 2014-11-23 21:15:59 -0800 | [diff] [blame] | 1888 | |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1889 | rp := requestParam{ |
| 1890 | method: f.PseudoValue("method"), |
| 1891 | scheme: f.PseudoValue("scheme"), |
| 1892 | authority: f.PseudoValue("authority"), |
| 1893 | path: f.PseudoValue("path"), |
| 1894 | } |
Brad Fitzpatrick | 961116a | 2016-01-05 14:53:21 -0800 | [diff] [blame] | 1895 | |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1896 | isConnect := rp.method == "CONNECT" |
Brad Fitzpatrick | 961116a | 2016-01-05 14:53:21 -0800 | [diff] [blame] | 1897 | if isConnect { |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1898 | if rp.path != "" || rp.scheme != "" || rp.authority == "" { |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1899 | return nil, nil, streamError(f.StreamID, ErrCodeProtocol) |
Brad Fitzpatrick | 961116a | 2016-01-05 14:53:21 -0800 | [diff] [blame] | 1900 | } |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1901 | } else if rp.method == "" || rp.path == "" || (rp.scheme != "https" && rp.scheme != "http") { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1902 | // See 8.1.2.6 Malformed Requests and Responses: |
| 1903 | // |
| 1904 | // Malformed requests or responses that are detected |
| 1905 | // MUST be treated as a stream error (Section 5.4.2) |
| 1906 | // of type PROTOCOL_ERROR." |
| 1907 | // |
| 1908 | // 8.1.2.3 Request Pseudo-Header Fields |
| 1909 | // "All HTTP/2 requests MUST include exactly one valid |
| 1910 | // value for the :method, :scheme, and :path |
| 1911 | // pseudo-header fields" |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1912 | return nil, nil, streamError(f.StreamID, ErrCodeProtocol) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1913 | } |
Brad Fitzpatrick | 961116a | 2016-01-05 14:53:21 -0800 | [diff] [blame] | 1914 | |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1915 | bodyOpen := !f.StreamEnded() |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1916 | if rp.method == "HEAD" && bodyOpen { |
Brad Fitzpatrick | c745c36 | 2015-11-24 17:14:16 -0800 | [diff] [blame] | 1917 | // HEAD requests can't have bodies |
Brad Fitzpatrick | e2ba55e | 2016-08-02 15:44:32 +0000 | [diff] [blame] | 1918 | return nil, nil, streamError(f.StreamID, ErrCodeProtocol) |
Brad Fitzpatrick | c745c36 | 2015-11-24 17:14:16 -0800 | [diff] [blame] | 1919 | } |
Brad Fitzpatrick | 961116a | 2016-01-05 14:53:21 -0800 | [diff] [blame] | 1920 | |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1921 | rp.header = make(http.Header) |
| 1922 | for _, hf := range f.RegularFields() { |
| 1923 | rp.header.Add(sc.canonicalHeader(hf.Name), hf.Value) |
| 1924 | } |
| 1925 | if rp.authority == "" { |
| 1926 | rp.authority = rp.header.Get("Host") |
| 1927 | } |
| 1928 | |
| 1929 | rw, req, err := sc.newWriterAndRequestNoBody(st, rp) |
| 1930 | if err != nil { |
| 1931 | return nil, nil, err |
| 1932 | } |
| 1933 | if bodyOpen { |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1934 | if vv, ok := rp.header["Content-Length"]; ok { |
| 1935 | req.ContentLength, _ = strconv.ParseInt(vv[0], 10, 64) |
| 1936 | } else { |
| 1937 | req.ContentLength = -1 |
| 1938 | } |
Tom Bergan | 10c134e | 2017-02-23 14:05:28 -0800 | [diff] [blame] | 1939 | req.Body.(*requestBody).pipe = &pipe{ |
| 1940 | b: &dataBuffer{expected: req.ContentLength}, |
| 1941 | } |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1942 | } |
| 1943 | return rw, req, nil |
| 1944 | } |
| 1945 | |
| 1946 | type requestParam struct { |
| 1947 | method string |
| 1948 | scheme, authority, path string |
| 1949 | header http.Header |
| 1950 | } |
| 1951 | |
| 1952 | func (sc *serverConn) newWriterAndRequestNoBody(st *stream, rp requestParam) (*responseWriter, *http.Request, error) { |
| 1953 | sc.serveG.check() |
| 1954 | |
| 1955 | var tlsState *tls.ConnectionState // nil if not scheme https |
| 1956 | if rp.scheme == "https" { |
Brad Fitzpatrick | 30b1681 | 2014-12-08 10:10:39 -0800 | [diff] [blame] | 1957 | tlsState = sc.tlsState |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 1958 | } |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 1959 | |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1960 | needsContinue := rp.header.Get("Expect") == "100-continue" |
Brad Fitzpatrick | 9d63ade | 2014-11-15 12:02:43 -0800 | [diff] [blame] | 1961 | if needsContinue { |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1962 | rp.header.Del("Expect") |
Brad Fitzpatrick | 9d63ade | 2014-11-15 12:02:43 -0800 | [diff] [blame] | 1963 | } |
Brad Fitzpatrick | b846920 | 2015-10-07 22:10:10 -0700 | [diff] [blame] | 1964 | // Merge Cookie headers into one "; "-delimited value. |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1965 | if cookies := rp.header["Cookie"]; len(cookies) > 1 { |
| 1966 | rp.header.Set("Cookie", strings.Join(cookies, "; ")) |
Brad Fitzpatrick | b846920 | 2015-10-07 22:10:10 -0700 | [diff] [blame] | 1967 | } |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1968 | |
| 1969 | // Setup Trailers |
| 1970 | var trailer http.Header |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1971 | for _, v := range rp.header["Trailer"] { |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 1972 | for _, key := range strings.Split(v, ",") { |
| 1973 | key = http.CanonicalHeaderKey(strings.TrimSpace(key)) |
| 1974 | switch key { |
| 1975 | case "Transfer-Encoding", "Trailer", "Content-Length": |
| 1976 | // Bogus. (copy of http1 rules) |
| 1977 | // Ignore. |
| 1978 | default: |
| 1979 | if trailer == nil { |
| 1980 | trailer = make(http.Header) |
| 1981 | } |
| 1982 | trailer[key] = nil |
| 1983 | } |
| 1984 | } |
| 1985 | } |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 1986 | delete(rp.header, "Trailer") |
| 1987 | |
| 1988 | var url_ *url.URL |
| 1989 | var requestURI string |
| 1990 | if rp.method == "CONNECT" { |
| 1991 | url_ = &url.URL{Host: rp.authority} |
| 1992 | requestURI = rp.authority // mimic HTTP/1 server behavior |
| 1993 | } else { |
| 1994 | var err error |
| 1995 | url_, err = url.ParseRequestURI(rp.path) |
| 1996 | if err != nil { |
| 1997 | return nil, nil, streamError(st.id, ErrCodeProtocol) |
| 1998 | } |
| 1999 | requestURI = rp.path |
| 2000 | } |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 2001 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2002 | body := &requestBody{ |
Brad Fitzpatrick | 914bad5 | 2014-11-30 21:05:26 -0800 | [diff] [blame] | 2003 | conn: sc, |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 2004 | stream: st, |
Brad Fitzpatrick | 9d63ade | 2014-11-15 12:02:43 -0800 | [diff] [blame] | 2005 | needsContinue: needsContinue, |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2006 | } |
| 2007 | req := &http.Request{ |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2008 | Method: rp.method, |
Brad Fitzpatrick | 961116a | 2016-01-05 14:53:21 -0800 | [diff] [blame] | 2009 | URL: url_, |
Brad Fitzpatrick | df959c2 | 2014-12-09 07:20:20 +1100 | [diff] [blame] | 2010 | RemoteAddr: sc.remoteAddrStr, |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2011 | Header: rp.header, |
Brad Fitzpatrick | 961116a | 2016-01-05 14:53:21 -0800 | [diff] [blame] | 2012 | RequestURI: requestURI, |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2013 | Proto: "HTTP/2.0", |
| 2014 | ProtoMajor: 2, |
| 2015 | ProtoMinor: 0, |
| 2016 | TLS: tlsState, |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2017 | Host: rp.authority, |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2018 | Body: body, |
Brad Fitzpatrick | c24de9d | 2015-12-16 17:29:56 +0000 | [diff] [blame] | 2019 | Trailer: trailer, |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2020 | } |
Brad Fitzpatrick | 8aacbec | 2016-05-18 19:54:31 +0000 | [diff] [blame] | 2021 | req = requestWithContext(req, st.ctx) |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2022 | |
| 2023 | rws := responseWriterStatePool.Get().(*responseWriterState) |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2024 | bwSave := rws.bw |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 2025 | *rws = responseWriterState{} // zero all the fields |
Brad Fitzpatrick | 914bad5 | 2014-11-30 21:05:26 -0800 | [diff] [blame] | 2026 | rws.conn = sc |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2027 | rws.bw = bwSave |
| 2028 | rws.bw.Reset(chunkWriter{rws}) |
Brad Fitzpatrick | 9e1fb3c | 2016-02-20 14:24:27 +0530 | [diff] [blame] | 2029 | rws.stream = st |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2030 | rws.req = req |
| 2031 | rws.body = body |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2032 | |
| 2033 | rw := &responseWriter{rws: rws} |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2034 | return rw, req, nil |
| 2035 | } |
| 2036 | |
| 2037 | // Run on its own goroutine. |
Brad Fitzpatrick | d8f3c68 | 2015-10-12 20:56:49 +0000 | [diff] [blame] | 2038 | func (sc *serverConn) runHandler(rw *responseWriter, req *http.Request, handler func(http.ResponseWriter, *http.Request)) { |
Brad Fitzpatrick | 74bd44b | 2015-12-15 00:47:28 +0000 | [diff] [blame] | 2039 | didPanic := true |
| 2040 | defer func() { |
Brad Fitzpatrick | 8aacbec | 2016-05-18 19:54:31 +0000 | [diff] [blame] | 2041 | rw.rws.stream.cancelCtx() |
Brad Fitzpatrick | 74bd44b | 2015-12-15 00:47:28 +0000 | [diff] [blame] | 2042 | if didPanic { |
| 2043 | e := recover() |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 2044 | sc.writeFrameFromHandler(FrameWriteRequest{ |
Brad Fitzpatrick | 74bd44b | 2015-12-15 00:47:28 +0000 | [diff] [blame] | 2045 | write: handlerPanicRST{rw.rws.stream.id}, |
| 2046 | stream: rw.rws.stream, |
| 2047 | }) |
Brad Fitzpatrick | 0e2717d | 2016-11-10 23:13:32 +0000 | [diff] [blame] | 2048 | // Same as net/http: |
| 2049 | if shouldLogPanic(e) { |
| 2050 | const size = 64 << 10 |
| 2051 | buf := make([]byte, size) |
| 2052 | buf = buf[:runtime.Stack(buf, false)] |
| 2053 | sc.logf("http2: panic serving %v: %v\n%s", sc.conn.RemoteAddr(), e, buf) |
| 2054 | } |
Brad Fitzpatrick | 74bd44b | 2015-12-15 00:47:28 +0000 | [diff] [blame] | 2055 | return |
| 2056 | } |
| 2057 | rw.handlerDone() |
| 2058 | }() |
Brad Fitzpatrick | d8f3c68 | 2015-10-12 20:56:49 +0000 | [diff] [blame] | 2059 | handler(rw, req) |
Brad Fitzpatrick | 74bd44b | 2015-12-15 00:47:28 +0000 | [diff] [blame] | 2060 | didPanic = false |
Brad Fitzpatrick | d8f3c68 | 2015-10-12 20:56:49 +0000 | [diff] [blame] | 2061 | } |
| 2062 | |
| 2063 | func handleHeaderListTooLong(w http.ResponseWriter, r *http.Request) { |
| 2064 | // 10.5.1 Limits on Header Block Size: |
| 2065 | // .. "A server that receives a larger header block than it is |
| 2066 | // willing to handle can send an HTTP 431 (Request Header Fields Too |
| 2067 | // Large) status code" |
| 2068 | const statusRequestHeaderFieldsTooLarge = 431 // only in Go 1.6+ |
| 2069 | w.WriteHeader(statusRequestHeaderFieldsTooLarge) |
| 2070 | io.WriteString(w, "<h1>HTTP Error 431</h1><p>Request Header Field(s) Too Large</p>") |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2071 | } |
| 2072 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2073 | // called from handler goroutines. |
| 2074 | // h may be nil. |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2075 | func (sc *serverConn) writeHeaders(st *stream, headerData *writeResHeaders) error { |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2076 | sc.serveG.checkNotOn() // NOT on |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2077 | var errc chan error |
Brad Fitzpatrick | f16a0b3 | 2014-11-28 13:49:30 -0800 | [diff] [blame] | 2078 | if headerData.h != nil { |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2079 | // If there's a header map (which we don't own), so we have to block on |
| 2080 | // waiting for this frame to be written, so an http.Flush mid-handler |
| 2081 | // writes out the correct value of keys, before a handler later potentially |
| 2082 | // mutates it. |
Brad Fitzpatrick | c94bffa | 2015-10-13 18:18:12 +0000 | [diff] [blame] | 2083 | errc = errChanPool.Get().(chan error) |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2084 | } |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 2085 | if err := sc.writeFrameFromHandler(FrameWriteRequest{ |
Brad Fitzpatrick | f16a0b3 | 2014-11-28 13:49:30 -0800 | [diff] [blame] | 2086 | write: headerData, |
| 2087 | stream: st, |
| 2088 | done: errc, |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2089 | }); err != nil { |
| 2090 | return err |
| 2091 | } |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2092 | if errc != nil { |
Brad Fitzpatrick | 9b41faf | 2014-11-19 10:45:13 -0800 | [diff] [blame] | 2093 | select { |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2094 | case err := <-errc: |
Brad Fitzpatrick | c94bffa | 2015-10-13 18:18:12 +0000 | [diff] [blame] | 2095 | errChanPool.Put(errc) |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2096 | return err |
Brad Fitzpatrick | 9b41faf | 2014-11-19 10:45:13 -0800 | [diff] [blame] | 2097 | case <-sc.doneServing: |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2098 | return errClientDisconnected |
Brad Fitzpatrick | c94bffa | 2015-10-13 18:18:12 +0000 | [diff] [blame] | 2099 | case <-st.cw: |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2100 | return errStreamClosed |
Brad Fitzpatrick | 9b41faf | 2014-11-19 10:45:13 -0800 | [diff] [blame] | 2101 | } |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 2102 | } |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2103 | return nil |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2104 | } |
| 2105 | |
Brad Fitzpatrick | 9d63ade | 2014-11-15 12:02:43 -0800 | [diff] [blame] | 2106 | // called from handler goroutines. |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2107 | func (sc *serverConn) write100ContinueHeaders(st *stream) { |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 2108 | sc.writeFrameFromHandler(FrameWriteRequest{ |
Brad Fitzpatrick | f16a0b3 | 2014-11-28 13:49:30 -0800 | [diff] [blame] | 2109 | write: write100ContinueHeadersFrame{st.id}, |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2110 | stream: st, |
Brad Fitzpatrick | 9d63ade | 2014-11-15 12:02:43 -0800 | [diff] [blame] | 2111 | }) |
| 2112 | } |
| 2113 | |
Brad Fitzpatrick | c8bab6a | 2014-12-07 18:51:56 -0800 | [diff] [blame] | 2114 | // A bodyReadMsg tells the server loop that the http.Handler read n |
| 2115 | // bytes of the DATA from the client on the given stream. |
| 2116 | type bodyReadMsg struct { |
| 2117 | st *stream |
| 2118 | n int |
| 2119 | } |
| 2120 | |
| 2121 | // called from handler goroutines. |
| 2122 | // Notes that the handler for the given stream ID read n bytes of its body |
| 2123 | // and schedules flow control tokens to be sent. |
Brad Fitzpatrick | 3bafa33 | 2016-10-19 14:40:54 +0000 | [diff] [blame] | 2124 | func (sc *serverConn) noteBodyReadFromHandler(st *stream, n int, err error) { |
Brad Fitzpatrick | c8bab6a | 2014-12-07 18:51:56 -0800 | [diff] [blame] | 2125 | sc.serveG.checkNotOn() // NOT on |
Brad Fitzpatrick | 3bafa33 | 2016-10-19 14:40:54 +0000 | [diff] [blame] | 2126 | if n > 0 { |
| 2127 | select { |
| 2128 | case sc.bodyReadCh <- bodyReadMsg{st, n}: |
| 2129 | case <-sc.doneServing: |
| 2130 | } |
| 2131 | } |
Brad Fitzpatrick | c8bab6a | 2014-12-07 18:51:56 -0800 | [diff] [blame] | 2132 | } |
| 2133 | |
| 2134 | func (sc *serverConn) noteBodyRead(st *stream, n int) { |
| 2135 | sc.serveG.check() |
| 2136 | sc.sendWindowUpdate(nil, n) // conn-level |
Brad Fitzpatrick | 0f1a865 | 2014-12-07 20:49:33 -0800 | [diff] [blame] | 2137 | if st.state != stateHalfClosedRemote && st.state != stateClosed { |
| 2138 | // Don't send this WINDOW_UPDATE if the stream is closed |
| 2139 | // remotely. |
| 2140 | sc.sendWindowUpdate(st, n) |
| 2141 | } |
Brad Fitzpatrick | c8bab6a | 2014-12-07 18:51:56 -0800 | [diff] [blame] | 2142 | } |
| 2143 | |
| 2144 | // st may be nil for conn-level |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2145 | func (sc *serverConn) sendWindowUpdate(st *stream, n int) { |
Brad Fitzpatrick | c8bab6a | 2014-12-07 18:51:56 -0800 | [diff] [blame] | 2146 | sc.serveG.check() |
| 2147 | // "The legal range for the increment to the flow control |
| 2148 | // window is 1 to 2^31-1 (2,147,483,647) octets." |
Brad Fitzpatrick | 068d35d | 2014-12-09 07:10:31 +1100 | [diff] [blame] | 2149 | // A Go Read call on 64-bit machines could in theory read |
| 2150 | // a larger Read than this. Very unlikely, but we handle it here |
| 2151 | // rather than elsewhere for now. |
| 2152 | const maxUint31 = 1<<31 - 1 |
| 2153 | for n >= maxUint31 { |
| 2154 | sc.sendWindowUpdate32(st, maxUint31) |
| 2155 | n -= maxUint31 |
| 2156 | } |
| 2157 | sc.sendWindowUpdate32(st, int32(n)) |
| 2158 | } |
| 2159 | |
| 2160 | // st may be nil for conn-level |
| 2161 | func (sc *serverConn) sendWindowUpdate32(st *stream, n int32) { |
| 2162 | sc.serveG.check() |
| 2163 | if n == 0 { |
| 2164 | return |
| 2165 | } |
| 2166 | if n < 0 { |
| 2167 | panic("negative update") |
| 2168 | } |
Brad Fitzpatrick | c8bab6a | 2014-12-07 18:51:56 -0800 | [diff] [blame] | 2169 | var streamID uint32 |
| 2170 | if st != nil { |
| 2171 | streamID = st.id |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2172 | } |
Tom Bergan | 4be9b97 | 2016-08-01 18:07:35 -0700 | [diff] [blame] | 2173 | sc.writeFrame(FrameWriteRequest{ |
Brad Fitzpatrick | 068d35d | 2014-12-09 07:10:31 +1100 | [diff] [blame] | 2174 | write: writeWindowUpdate{streamID: streamID, n: uint32(n)}, |
| 2175 | stream: st, |
| 2176 | }) |
| 2177 | var ok bool |
| 2178 | if st == nil { |
| 2179 | ok = sc.inflow.add(n) |
| 2180 | } else { |
| 2181 | ok = st.inflow.add(n) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2182 | } |
Brad Fitzpatrick | 068d35d | 2014-12-09 07:10:31 +1100 | [diff] [blame] | 2183 | if !ok { |
| 2184 | panic("internal error; sent too many window updates without decrements?") |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2185 | } |
| 2186 | } |
| 2187 | |
Brad Fitzpatrick | 40a0a18 | 2016-10-21 09:23:26 +0100 | [diff] [blame] | 2188 | // requestBody is the Handler's Request.Body type. |
| 2189 | // Read and Close may be called concurrently. |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2190 | type requestBody struct { |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2191 | stream *stream |
Brad Fitzpatrick | 914bad5 | 2014-11-30 21:05:26 -0800 | [diff] [blame] | 2192 | conn *serverConn |
Brad Fitzpatrick | 40a0a18 | 2016-10-21 09:23:26 +0100 | [diff] [blame] | 2193 | closed bool // for use by Close only |
| 2194 | sawEOF bool // for use by Read only |
Brad Fitzpatrick | 9d63ade | 2014-11-15 12:02:43 -0800 | [diff] [blame] | 2195 | pipe *pipe // non-nil if we have a HTTP entity message body |
| 2196 | needsContinue bool // need to send a 100-continue |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2197 | } |
| 2198 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2199 | func (b *requestBody) Close() error { |
Brad Fitzpatrick | 40a0a18 | 2016-10-21 09:23:26 +0100 | [diff] [blame] | 2200 | if b.pipe != nil && !b.closed { |
Brad Fitzpatrick | 4d07e8a | 2016-05-20 18:55:47 +0000 | [diff] [blame] | 2201 | b.pipe.BreakWithError(errClosedBody) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2202 | } |
| 2203 | b.closed = true |
| 2204 | return nil |
| 2205 | } |
| 2206 | |
| 2207 | func (b *requestBody) Read(p []byte) (n int, err error) { |
Brad Fitzpatrick | 9d63ade | 2014-11-15 12:02:43 -0800 | [diff] [blame] | 2208 | if b.needsContinue { |
| 2209 | b.needsContinue = false |
Brad Fitzpatrick | 914bad5 | 2014-11-30 21:05:26 -0800 | [diff] [blame] | 2210 | b.conn.write100ContinueHeaders(b.stream) |
Brad Fitzpatrick | 9d63ade | 2014-11-15 12:02:43 -0800 | [diff] [blame] | 2211 | } |
Brad Fitzpatrick | 40a0a18 | 2016-10-21 09:23:26 +0100 | [diff] [blame] | 2212 | if b.pipe == nil || b.sawEOF { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2213 | return 0, io.EOF |
| 2214 | } |
| 2215 | n, err = b.pipe.Read(p) |
Brad Fitzpatrick | 3bafa33 | 2016-10-19 14:40:54 +0000 | [diff] [blame] | 2216 | if err == io.EOF { |
Brad Fitzpatrick | 40a0a18 | 2016-10-21 09:23:26 +0100 | [diff] [blame] | 2217 | b.sawEOF = true |
| 2218 | } |
| 2219 | if b.conn == nil && inTests { |
| 2220 | return |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2221 | } |
Brad Fitzpatrick | 3bafa33 | 2016-10-19 14:40:54 +0000 | [diff] [blame] | 2222 | b.conn.noteBodyReadFromHandler(b.stream, n, err) |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2223 | return |
| 2224 | } |
| 2225 | |
Dmitri Shuralyov | 357296a | 2016-11-07 15:02:51 -0800 | [diff] [blame] | 2226 | // responseWriter is the http.ResponseWriter implementation. It's |
| 2227 | // intentionally small (1 pointer wide) to minimize garbage. The |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2228 | // responseWriterState pointer inside is zeroed at the end of a |
| 2229 | // request (in handlerDone) and calls on the responseWriter thereafter |
| 2230 | // simply crash (caller's mistake), but the much larger responseWriterState |
| 2231 | // and buffers are reused between multiple requests. |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2232 | type responseWriter struct { |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2233 | rws *responseWriterState |
| 2234 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2235 | |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2236 | // Optional http.ResponseWriter interfaces implemented. |
| 2237 | var ( |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2238 | _ http.CloseNotifier = (*responseWriter)(nil) |
| 2239 | _ http.Flusher = (*responseWriter)(nil) |
| 2240 | _ stringWriter = (*responseWriter)(nil) |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2241 | ) |
| 2242 | |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2243 | type responseWriterState struct { |
| 2244 | // immutable within a request: |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2245 | stream *stream |
| 2246 | req *http.Request |
| 2247 | body *requestBody // to close at end of request, if DATA frames didn't |
Brad Fitzpatrick | 914bad5 | 2014-11-30 21:05:26 -0800 | [diff] [blame] | 2248 | conn *serverConn |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2249 | |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 2250 | // TODO: adjust buffer writing sizes based on server config, frame size updates from peer, etc |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2251 | bw *bufio.Writer // writing to a chunkWriter{this *responseWriterState} |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2252 | |
| 2253 | // mutated by http.Handler goroutine: |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2254 | handlerHeader http.Header // nil until called |
| 2255 | snapHeader http.Header // snapshot of handlerHeader at WriteHeader time |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2256 | trailers []string // set in writeChunk |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 2257 | status int // status code passed to WriteHeader |
Brad Fitzpatrick | 3c8c613 | 2014-11-20 18:34:52 -0800 | [diff] [blame] | 2258 | wroteHeader bool // WriteHeader called (explicitly or implicitly). Not necessarily sent to user yet. |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2259 | sentHeader bool // have we sent the header frame? |
| 2260 | handlerDone bool // handler has finished |
Brad Fitzpatrick | fe686d4 | 2017-06-18 05:18:41 +0000 | [diff] [blame] | 2261 | dirty bool // a Write failed; don't reuse this responseWriterState |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2262 | |
Brad Fitzpatrick | c745c36 | 2015-11-24 17:14:16 -0800 | [diff] [blame] | 2263 | sentContentLen int64 // non-zero if handler set a Content-Length header |
| 2264 | wroteBytes int64 |
| 2265 | |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2266 | closeNotifierMu sync.Mutex // guards closeNotifierCh |
| 2267 | closeNotifierCh chan bool // nil until first used |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2268 | } |
| 2269 | |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2270 | type chunkWriter struct{ rws *responseWriterState } |
| 2271 | |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 2272 | func (cw chunkWriter) Write(p []byte) (n int, err error) { return cw.rws.writeChunk(p) } |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2273 | |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2274 | func (rws *responseWriterState) hasTrailers() bool { return len(rws.trailers) != 0 } |
| 2275 | |
| 2276 | // declareTrailer is called for each Trailer header when the |
| 2277 | // response header is written. It notes that a header will need to be |
| 2278 | // written in the trailers at the end of the response. |
| 2279 | func (rws *responseWriterState) declareTrailer(k string) { |
| 2280 | k = http.CanonicalHeaderKey(k) |
Brad Fitzpatrick | 3c5cb15 | 2016-05-19 01:21:59 +0000 | [diff] [blame] | 2281 | if !ValidTrailerHeader(k) { |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2282 | // Forbidden by RFC 2616 14.40. |
Brad Fitzpatrick | 3c5cb15 | 2016-05-19 01:21:59 +0000 | [diff] [blame] | 2283 | rws.conn.logf("ignoring invalid trailer %q", k) |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2284 | return |
| 2285 | } |
Brad Fitzpatrick | d513e58 | 2016-01-31 06:24:40 +0000 | [diff] [blame] | 2286 | if !strSliceContains(rws.trailers, k) { |
| 2287 | rws.trailers = append(rws.trailers, k) |
| 2288 | } |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2289 | } |
| 2290 | |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 2291 | // writeChunk writes chunks from the bufio.Writer. But because |
| 2292 | // bufio.Writer may bypass its chunking, sometimes p may be |
| 2293 | // arbitrarily large. |
| 2294 | // |
| 2295 | // writeChunk is also responsible (on the first chunk) for sending the |
| 2296 | // HEADER response. |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2297 | func (rws *responseWriterState) writeChunk(p []byte) (n int, err error) { |
| 2298 | if !rws.wroteHeader { |
| 2299 | rws.writeHeader(200) |
| 2300 | } |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2301 | |
Brad Fitzpatrick | c745c36 | 2015-11-24 17:14:16 -0800 | [diff] [blame] | 2302 | isHeadResp := rws.req.Method == "HEAD" |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2303 | if !rws.sentHeader { |
| 2304 | rws.sentHeader = true |
Brad Fitzpatrick | c745c36 | 2015-11-24 17:14:16 -0800 | [diff] [blame] | 2305 | var ctype, clen string |
| 2306 | if clen = rws.snapHeader.Get("Content-Length"); clen != "" { |
| 2307 | rws.snapHeader.Del("Content-Length") |
| 2308 | clen64, err := strconv.ParseInt(clen, 10, 64) |
| 2309 | if err == nil && clen64 >= 0 { |
| 2310 | rws.sentContentLen = clen64 |
| 2311 | } else { |
| 2312 | clen = "" |
| 2313 | } |
| 2314 | } |
Brad Fitzpatrick | 1796f9b | 2015-12-08 22:22:07 +0000 | [diff] [blame] | 2315 | if clen == "" && rws.handlerDone && bodyAllowedForStatus(rws.status) && (len(p) > 0 || !isHeadResp) { |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2316 | clen = strconv.Itoa(len(p)) |
| 2317 | } |
Brad Fitzpatrick | 1796f9b | 2015-12-08 22:22:07 +0000 | [diff] [blame] | 2318 | _, hasContentType := rws.snapHeader["Content-Type"] |
| 2319 | if !hasContentType && bodyAllowedForStatus(rws.status) { |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2320 | ctype = http.DetectContentType(p) |
| 2321 | } |
Brad Fitzpatrick | c745c36 | 2015-11-24 17:14:16 -0800 | [diff] [blame] | 2322 | var date string |
| 2323 | if _, ok := rws.snapHeader["Date"]; !ok { |
| 2324 | // TODO(bradfitz): be faster here, like net/http? measure. |
| 2325 | date = time.Now().UTC().Format(http.TimeFormat) |
| 2326 | } |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2327 | |
| 2328 | for _, v := range rws.snapHeader["Trailer"] { |
| 2329 | foreachHeaderElement(v, rws.declareTrailer) |
| 2330 | } |
| 2331 | |
| 2332 | endStream := (rws.handlerDone && !rws.hasTrailers() && len(p) == 0) || isHeadResp |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2333 | err = rws.conn.writeHeaders(rws.stream, &writeResHeaders{ |
Brad Fitzpatrick | f16a0b3 | 2014-11-28 13:49:30 -0800 | [diff] [blame] | 2334 | streamID: rws.stream.id, |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2335 | httpResCode: rws.status, |
| 2336 | h: rws.snapHeader, |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 2337 | endStream: endStream, |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2338 | contentType: ctype, |
| 2339 | contentLength: clen, |
Brad Fitzpatrick | c745c36 | 2015-11-24 17:14:16 -0800 | [diff] [blame] | 2340 | date: date, |
Brad Fitzpatrick | c94bffa | 2015-10-13 18:18:12 +0000 | [diff] [blame] | 2341 | }) |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2342 | if err != nil { |
Brad Fitzpatrick | fe686d4 | 2017-06-18 05:18:41 +0000 | [diff] [blame] | 2343 | rws.dirty = true |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2344 | return 0, err |
| 2345 | } |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 2346 | if endStream { |
Brad Fitzpatrick | 2b45947 | 2014-11-30 19:18:57 -0800 | [diff] [blame] | 2347 | return 0, nil |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 2348 | } |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2349 | } |
Brad Fitzpatrick | c745c36 | 2015-11-24 17:14:16 -0800 | [diff] [blame] | 2350 | if isHeadResp { |
| 2351 | return len(p), nil |
| 2352 | } |
Brad Fitzpatrick | 2b45947 | 2014-11-30 19:18:57 -0800 | [diff] [blame] | 2353 | if len(p) == 0 && !rws.handlerDone { |
| 2354 | return 0, nil |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2355 | } |
Brad Fitzpatrick | 5640105 | 2015-10-20 22:27:39 +0000 | [diff] [blame] | 2356 | |
Brad Fitzpatrick | d513e58 | 2016-01-31 06:24:40 +0000 | [diff] [blame] | 2357 | if rws.handlerDone { |
| 2358 | rws.promoteUndeclaredTrailers() |
| 2359 | } |
| 2360 | |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2361 | endStream := rws.handlerDone && !rws.hasTrailers() |
| 2362 | if len(p) > 0 || endStream { |
| 2363 | // only send a 0 byte DATA frame if we're ending the stream. |
| 2364 | if err := rws.conn.writeDataFromHandler(rws.stream, p, endStream); err != nil { |
Brad Fitzpatrick | fe686d4 | 2017-06-18 05:18:41 +0000 | [diff] [blame] | 2365 | rws.dirty = true |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2366 | return 0, err |
| 2367 | } |
| 2368 | } |
| 2369 | |
| 2370 | if rws.handlerDone && rws.hasTrailers() { |
| 2371 | err = rws.conn.writeHeaders(rws.stream, &writeResHeaders{ |
| 2372 | streamID: rws.stream.id, |
| 2373 | h: rws.handlerHeader, |
| 2374 | trailers: rws.trailers, |
| 2375 | endStream: true, |
| 2376 | }) |
Brad Fitzpatrick | fe686d4 | 2017-06-18 05:18:41 +0000 | [diff] [blame] | 2377 | if err != nil { |
| 2378 | rws.dirty = true |
| 2379 | } |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2380 | return len(p), err |
Brad Fitzpatrick | 3d7a3ad | 2014-11-15 21:38:23 -0800 | [diff] [blame] | 2381 | } |
Brad Fitzpatrick | 2b45947 | 2014-11-30 19:18:57 -0800 | [diff] [blame] | 2382 | return len(p), nil |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2383 | } |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2384 | |
Brad Fitzpatrick | d513e58 | 2016-01-31 06:24:40 +0000 | [diff] [blame] | 2385 | // TrailerPrefix is a magic prefix for ResponseWriter.Header map keys |
| 2386 | // that, if present, signals that the map entry is actually for |
| 2387 | // the response trailers, and not the response headers. The prefix |
| 2388 | // is stripped after the ServeHTTP call finishes and the values are |
| 2389 | // sent in the trailers. |
| 2390 | // |
| 2391 | // This mechanism is intended only for trailers that are not known |
| 2392 | // prior to the headers being written. If the set of trailers is fixed |
| 2393 | // or known before the header is written, the normal Go trailers mechanism |
| 2394 | // is preferred: |
| 2395 | // https://golang.org/pkg/net/http/#ResponseWriter |
| 2396 | // https://golang.org/pkg/net/http/#example_ResponseWriter_trailers |
| 2397 | const TrailerPrefix = "Trailer:" |
| 2398 | |
| 2399 | // promoteUndeclaredTrailers permits http.Handlers to set trailers |
| 2400 | // after the header has already been flushed. Because the Go |
| 2401 | // ResponseWriter interface has no way to set Trailers (only the |
| 2402 | // Header), and because we didn't want to expand the ResponseWriter |
| 2403 | // interface, and because nobody used trailers, and because RFC 2616 |
| 2404 | // says you SHOULD (but not must) predeclare any trailers in the |
| 2405 | // header, the official ResponseWriter rules said trailers in Go must |
| 2406 | // be predeclared, and then we reuse the same ResponseWriter.Header() |
Dmitri Shuralyov | 357296a | 2016-11-07 15:02:51 -0800 | [diff] [blame] | 2407 | // map to mean both Headers and Trailers. When it's time to write the |
Brad Fitzpatrick | d513e58 | 2016-01-31 06:24:40 +0000 | [diff] [blame] | 2408 | // Trailers, we pick out the fields of Headers that were declared as |
| 2409 | // trailers. That worked for a while, until we found the first major |
| 2410 | // user of Trailers in the wild: gRPC (using them only over http2), |
| 2411 | // and gRPC libraries permit setting trailers mid-stream without |
| 2412 | // predeclarnig them. So: change of plans. We still permit the old |
| 2413 | // way, but we also permit this hack: if a Header() key begins with |
| 2414 | // "Trailer:", the suffix of that key is a Trailer. Because ':' is an |
| 2415 | // invalid token byte anyway, there is no ambiguity. (And it's already |
| 2416 | // filtered out) It's mildly hacky, but not terrible. |
| 2417 | // |
| 2418 | // This method runs after the Handler is done and promotes any Header |
| 2419 | // fields to be trailers. |
| 2420 | func (rws *responseWriterState) promoteUndeclaredTrailers() { |
| 2421 | for k, vv := range rws.handlerHeader { |
| 2422 | if !strings.HasPrefix(k, TrailerPrefix) { |
| 2423 | continue |
| 2424 | } |
| 2425 | trailerKey := strings.TrimPrefix(k, TrailerPrefix) |
| 2426 | rws.declareTrailer(trailerKey) |
| 2427 | rws.handlerHeader[http.CanonicalHeaderKey(trailerKey)] = vv |
| 2428 | } |
Brad Fitzpatrick | 4876518 | 2016-03-22 02:00:46 +0000 | [diff] [blame] | 2429 | |
| 2430 | if len(rws.trailers) > 1 { |
| 2431 | sorter := sorterPool.Get().(*sorter) |
| 2432 | sorter.SortStrings(rws.trailers) |
| 2433 | sorterPool.Put(sorter) |
| 2434 | } |
Brad Fitzpatrick | d513e58 | 2016-01-31 06:24:40 +0000 | [diff] [blame] | 2435 | } |
| 2436 | |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2437 | func (w *responseWriter) Flush() { |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 2438 | rws := w.rws |
| 2439 | if rws == nil { |
| 2440 | panic("Header called after Handler finished") |
| 2441 | } |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2442 | if rws.bw.Buffered() > 0 { |
| 2443 | if err := rws.bw.Flush(); err != nil { |
| 2444 | // Ignore the error. The frame writer already knows. |
| 2445 | return |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 2446 | } |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2447 | } else { |
| 2448 | // The bufio.Writer won't call chunkWriter.Write |
| 2449 | // (writeChunk with zero bytes, so we have to do it |
| 2450 | // ourselves to force the HTTP response header and/or |
| 2451 | // final DATA frame (with END_STREAM) to be sent. |
| 2452 | rws.writeChunk(nil) |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 2453 | } |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 2454 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2455 | |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2456 | func (w *responseWriter) CloseNotify() <-chan bool { |
| 2457 | rws := w.rws |
| 2458 | if rws == nil { |
| 2459 | panic("CloseNotify called after Handler finished") |
| 2460 | } |
| 2461 | rws.closeNotifierMu.Lock() |
| 2462 | ch := rws.closeNotifierCh |
| 2463 | if ch == nil { |
| 2464 | ch = make(chan bool, 1) |
| 2465 | rws.closeNotifierCh = ch |
Brad Fitzpatrick | 9ef2211 | 2016-11-09 21:27:32 +0000 | [diff] [blame] | 2466 | cw := rws.stream.cw |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2467 | go func() { |
Brad Fitzpatrick | 9ef2211 | 2016-11-09 21:27:32 +0000 | [diff] [blame] | 2468 | cw.Wait() // wait for close |
Brad Fitzpatrick | bd39196 | 2014-11-17 18:58:58 -0800 | [diff] [blame] | 2469 | ch <- true |
| 2470 | }() |
| 2471 | } |
| 2472 | rws.closeNotifierMu.Unlock() |
| 2473 | return ch |
| 2474 | } |
| 2475 | |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2476 | func (w *responseWriter) Header() http.Header { |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2477 | rws := w.rws |
| 2478 | if rws == nil { |
| 2479 | panic("Header called after Handler finished") |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2480 | } |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2481 | if rws.handlerHeader == nil { |
| 2482 | rws.handlerHeader = make(http.Header) |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2483 | } |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2484 | return rws.handlerHeader |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2485 | } |
| 2486 | |
| 2487 | func (w *responseWriter) WriteHeader(code int) { |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2488 | rws := w.rws |
| 2489 | if rws == nil { |
| 2490 | panic("WriteHeader called after Handler finished") |
| 2491 | } |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2492 | rws.writeHeader(code) |
| 2493 | } |
| 2494 | |
| 2495 | func (rws *responseWriterState) writeHeader(code int) { |
| 2496 | if !rws.wroteHeader { |
| 2497 | rws.wroteHeader = true |
| 2498 | rws.status = code |
| 2499 | if len(rws.handlerHeader) > 0 { |
| 2500 | rws.snapHeader = cloneHeader(rws.handlerHeader) |
| 2501 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2502 | } |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2503 | } |
| 2504 | |
| 2505 | func cloneHeader(h http.Header) http.Header { |
| 2506 | h2 := make(http.Header, len(h)) |
| 2507 | for k, vv := range h { |
| 2508 | vv2 := make([]string, len(vv)) |
| 2509 | copy(vv2, vv) |
| 2510 | h2[k] = vv2 |
| 2511 | } |
| 2512 | return h2 |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2513 | } |
| 2514 | |
Brad Fitzpatrick | 15a4bf3 | 2014-11-14 10:56:12 -0800 | [diff] [blame] | 2515 | // The Life Of A Write is like this: |
| 2516 | // |
Brad Fitzpatrick | ed26b48 | 2014-11-26 09:16:43 -0800 | [diff] [blame] | 2517 | // * Handler calls w.Write or w.WriteString -> |
| 2518 | // * -> rws.bw (*bufio.Writer) -> |
Brad Fitzpatrick | fe686d4 | 2017-06-18 05:18:41 +0000 | [diff] [blame] | 2519 | // * (Handler might call Flush) |
Brad Fitzpatrick | ed26b48 | 2014-11-26 09:16:43 -0800 | [diff] [blame] | 2520 | // * -> chunkWriter{rws} |
| 2521 | // * -> responseWriterState.writeChunk(p []byte) |
| 2522 | // * -> responseWriterState.writeChunk (most of the magic; see comment there) |
Brad Fitzpatrick | 15a4bf3 | 2014-11-14 10:56:12 -0800 | [diff] [blame] | 2523 | func (w *responseWriter) Write(p []byte) (n int, err error) { |
| 2524 | return w.write(len(p), p, "") |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2525 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2526 | |
Brad Fitzpatrick | 15a4bf3 | 2014-11-14 10:56:12 -0800 | [diff] [blame] | 2527 | func (w *responseWriter) WriteString(s string) (n int, err error) { |
| 2528 | return w.write(len(s), nil, s) |
| 2529 | } |
| 2530 | |
| 2531 | // either dataB or dataS is non-zero. |
| 2532 | func (w *responseWriter) write(lenData int, dataB []byte, dataS string) (n int, err error) { |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2533 | rws := w.rws |
| 2534 | if rws == nil { |
| 2535 | panic("Write called after Handler finished") |
| 2536 | } |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 2537 | if !rws.wroteHeader { |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2538 | w.WriteHeader(200) |
| 2539 | } |
Brad Fitzpatrick | c745c36 | 2015-11-24 17:14:16 -0800 | [diff] [blame] | 2540 | if !bodyAllowedForStatus(rws.status) { |
| 2541 | return 0, http.ErrBodyNotAllowed |
| 2542 | } |
| 2543 | rws.wroteBytes += int64(len(dataB)) + int64(len(dataS)) // only one can be set |
| 2544 | if rws.sentContentLen != 0 && rws.wroteBytes > rws.sentContentLen { |
| 2545 | // TODO: send a RST_STREAM |
| 2546 | return 0, errors.New("http2: handler wrote more than declared Content-Length") |
| 2547 | } |
| 2548 | |
Brad Fitzpatrick | 15a4bf3 | 2014-11-14 10:56:12 -0800 | [diff] [blame] | 2549 | if dataB != nil { |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2550 | return rws.bw.Write(dataB) |
Brad Fitzpatrick | 15a4bf3 | 2014-11-14 10:56:12 -0800 | [diff] [blame] | 2551 | } else { |
Brad Fitzpatrick | 390047e | 2014-11-14 20:37:08 -0800 | [diff] [blame] | 2552 | return rws.bw.WriteString(dataS) |
Brad Fitzpatrick | 15a4bf3 | 2014-11-14 10:56:12 -0800 | [diff] [blame] | 2553 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2554 | } |
| 2555 | |
| 2556 | func (w *responseWriter) handlerDone() { |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2557 | rws := w.rws |
Brad Fitzpatrick | fe686d4 | 2017-06-18 05:18:41 +0000 | [diff] [blame] | 2558 | dirty := rws.dirty |
Brad Fitzpatrick | 520123b | 2014-11-14 15:57:37 -0800 | [diff] [blame] | 2559 | rws.handlerDone = true |
| 2560 | w.Flush() |
Brad Fitzpatrick | 729bd72 | 2014-11-13 14:09:36 -0800 | [diff] [blame] | 2561 | w.rws = nil |
Brad Fitzpatrick | fe686d4 | 2017-06-18 05:18:41 +0000 | [diff] [blame] | 2562 | if !dirty { |
| 2563 | // Only recycle the pool if all prior Write calls to |
| 2564 | // the serverConn goroutine completed successfully. If |
| 2565 | // they returned earlier due to resets from the peer |
| 2566 | // there might still be write goroutines outstanding |
| 2567 | // from the serverConn referencing the rws memory. See |
| 2568 | // issue 20704. |
| 2569 | responseWriterStatePool.Put(rws) |
| 2570 | } |
Brad Fitzpatrick | b331b81 | 2014-11-13 11:51:54 -0800 | [diff] [blame] | 2571 | } |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2572 | |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2573 | // Push errors. |
| 2574 | var ( |
| 2575 | ErrRecursivePush = errors.New("http2: recursive push not allowed") |
| 2576 | ErrPushLimitReached = errors.New("http2: push would exceed peer's SETTINGS_MAX_CONCURRENT_STREAMS") |
| 2577 | ) |
| 2578 | |
| 2579 | // pushOptions is the internal version of http.PushOptions, which we |
| 2580 | // cannot include here because it's only defined in Go 1.8 and later. |
| 2581 | type pushOptions struct { |
| 2582 | Method string |
| 2583 | Header http.Header |
| 2584 | } |
| 2585 | |
| 2586 | func (w *responseWriter) push(target string, opts pushOptions) error { |
| 2587 | st := w.rws.stream |
| 2588 | sc := st.sc |
| 2589 | sc.serveG.checkNotOn() |
| 2590 | |
| 2591 | // No recursive pushes: "PUSH_PROMISE frames MUST only be sent on a peer-initiated stream." |
| 2592 | // http://tools.ietf.org/html/rfc7540#section-6.6 |
| 2593 | if st.isPushed() { |
| 2594 | return ErrRecursivePush |
| 2595 | } |
| 2596 | |
| 2597 | // Default options. |
| 2598 | if opts.Method == "" { |
| 2599 | opts.Method = "GET" |
| 2600 | } |
| 2601 | if opts.Header == nil { |
| 2602 | opts.Header = http.Header{} |
| 2603 | } |
| 2604 | wantScheme := "http" |
| 2605 | if w.rws.req.TLS != nil { |
| 2606 | wantScheme = "https" |
| 2607 | } |
| 2608 | |
| 2609 | // Validate the request. |
| 2610 | u, err := url.Parse(target) |
| 2611 | if err != nil { |
| 2612 | return err |
| 2613 | } |
| 2614 | if u.Scheme == "" { |
| 2615 | if !strings.HasPrefix(target, "/") { |
| 2616 | return fmt.Errorf("target must be an absolute URL or an absolute path: %q", target) |
| 2617 | } |
| 2618 | u.Scheme = wantScheme |
| 2619 | u.Host = w.rws.req.Host |
| 2620 | } else { |
| 2621 | if u.Scheme != wantScheme { |
| 2622 | return fmt.Errorf("cannot push URL with scheme %q from request with scheme %q", u.Scheme, wantScheme) |
| 2623 | } |
| 2624 | if u.Host == "" { |
| 2625 | return errors.New("URL must have a host") |
| 2626 | } |
| 2627 | } |
| 2628 | for k := range opts.Header { |
| 2629 | if strings.HasPrefix(k, ":") { |
Mikio Hara | 1c5acb2 | 2016-11-16 13:55:47 +0900 | [diff] [blame] | 2630 | return fmt.Errorf("promised request headers cannot include pseudo header %q", k) |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2631 | } |
| 2632 | // These headers are meaningful only if the request has a body, |
| 2633 | // but PUSH_PROMISE requests cannot have a body. |
| 2634 | // http://tools.ietf.org/html/rfc7540#section-8.2 |
| 2635 | // Also disallow Host, since the promised URL must be absolute. |
| 2636 | switch strings.ToLower(k) { |
| 2637 | case "content-length", "content-encoding", "trailer", "te", "expect", "host": |
| 2638 | return fmt.Errorf("promised request headers cannot include %q", k) |
| 2639 | } |
| 2640 | } |
| 2641 | if err := checkValidHTTP2RequestHeaders(opts.Header); err != nil { |
| 2642 | return err |
| 2643 | } |
| 2644 | |
| 2645 | // The RFC effectively limits promised requests to GET and HEAD: |
| 2646 | // "Promised requests MUST be cacheable [GET, HEAD, or POST], and MUST be safe [GET or HEAD]" |
| 2647 | // http://tools.ietf.org/html/rfc7540#section-8.2 |
| 2648 | if opts.Method != "GET" && opts.Method != "HEAD" { |
| 2649 | return fmt.Errorf("method %q must be GET or HEAD", opts.Method) |
| 2650 | } |
| 2651 | |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 2652 | msg := &startPushRequest{ |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2653 | parent: st, |
| 2654 | method: opts.Method, |
| 2655 | url: u, |
| 2656 | header: cloneHeader(opts.Header), |
| 2657 | done: errChanPool.Get().(chan error), |
| 2658 | } |
| 2659 | |
| 2660 | select { |
| 2661 | case <-sc.doneServing: |
| 2662 | return errClientDisconnected |
| 2663 | case <-st.cw: |
| 2664 | return errStreamClosed |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 2665 | case sc.serveMsgCh <- msg: |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2666 | } |
| 2667 | |
| 2668 | select { |
| 2669 | case <-sc.doneServing: |
| 2670 | return errClientDisconnected |
| 2671 | case <-st.cw: |
| 2672 | return errStreamClosed |
| 2673 | case err := <-msg.done: |
| 2674 | errChanPool.Put(msg.done) |
| 2675 | return err |
| 2676 | } |
| 2677 | } |
| 2678 | |
| 2679 | type startPushRequest struct { |
| 2680 | parent *stream |
| 2681 | method string |
| 2682 | url *url.URL |
| 2683 | header http.Header |
| 2684 | done chan error |
| 2685 | } |
| 2686 | |
Brad Fitzpatrick | 3405706 | 2017-05-09 12:22:37 -0700 | [diff] [blame] | 2687 | func (sc *serverConn) startPush(msg *startPushRequest) { |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2688 | sc.serveG.check() |
| 2689 | |
| 2690 | // http://tools.ietf.org/html/rfc7540#section-6.6. |
| 2691 | // PUSH_PROMISE frames MUST only be sent on a peer-initiated stream that |
| 2692 | // is in either the "open" or "half-closed (remote)" state. |
| 2693 | if msg.parent.state != stateOpen && msg.parent.state != stateHalfClosedRemote { |
| 2694 | // responseWriter.Push checks that the stream is peer-initiaed. |
| 2695 | msg.done <- errStreamClosed |
| 2696 | return |
| 2697 | } |
| 2698 | |
| 2699 | // http://tools.ietf.org/html/rfc7540#section-6.6. |
| 2700 | if !sc.pushEnabled { |
| 2701 | msg.done <- http.ErrNotSupported |
| 2702 | return |
| 2703 | } |
| 2704 | |
| 2705 | // PUSH_PROMISE frames must be sent in increasing order by stream ID, so |
| 2706 | // we allocate an ID for the promised stream lazily, when the PUSH_PROMISE |
| 2707 | // is written. Once the ID is allocated, we start the request handler. |
| 2708 | allocatePromisedID := func() (uint32, error) { |
| 2709 | sc.serveG.check() |
| 2710 | |
| 2711 | // Check this again, just in case. Technically, we might have received |
| 2712 | // an updated SETTINGS by the time we got around to writing this frame. |
| 2713 | if !sc.pushEnabled { |
| 2714 | return 0, http.ErrNotSupported |
| 2715 | } |
| 2716 | // http://tools.ietf.org/html/rfc7540#section-6.5.2. |
| 2717 | if sc.curPushedStreams+1 > sc.clientMaxStreams { |
| 2718 | return 0, ErrPushLimitReached |
| 2719 | } |
| 2720 | |
| 2721 | // http://tools.ietf.org/html/rfc7540#section-5.1.1. |
| 2722 | // Streams initiated by the server MUST use even-numbered identifiers. |
Tom Bergan | 40d3034 | 2016-11-01 14:56:08 -0700 | [diff] [blame] | 2723 | // A server that is unable to establish a new stream identifier can send a GOAWAY |
| 2724 | // frame so that the client is forced to open a new connection for new streams. |
| 2725 | if sc.maxPushPromiseID+2 >= 1<<31 { |
Tom Bergan | a8e8f92 | 2017-05-15 12:29:23 -0700 | [diff] [blame] | 2726 | sc.startGracefulShutdownInternal() |
Tom Bergan | 40d3034 | 2016-11-01 14:56:08 -0700 | [diff] [blame] | 2727 | return 0, ErrPushLimitReached |
| 2728 | } |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2729 | sc.maxPushPromiseID += 2 |
| 2730 | promisedID := sc.maxPushPromiseID |
| 2731 | |
| 2732 | // http://tools.ietf.org/html/rfc7540#section-8.2. |
| 2733 | // Strictly speaking, the new stream should start in "reserved (local)", then |
| 2734 | // transition to "half closed (remote)" after sending the initial HEADERS, but |
| 2735 | // we start in "half closed (remote)" for simplicity. |
| 2736 | // See further comments at the definition of stateHalfClosedRemote. |
| 2737 | promised := sc.newStream(promisedID, msg.parent.id, stateHalfClosedRemote) |
| 2738 | rw, req, err := sc.newWriterAndRequestNoBody(promised, requestParam{ |
| 2739 | method: msg.method, |
| 2740 | scheme: msg.url.Scheme, |
| 2741 | authority: msg.url.Host, |
| 2742 | path: msg.url.RequestURI(), |
Tom Bergan | 1195a05 | 2016-12-15 09:58:54 -0800 | [diff] [blame] | 2743 | header: cloneHeader(msg.header), // clone since handler runs concurrently with writing the PUSH_PROMISE |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2744 | }) |
| 2745 | if err != nil { |
| 2746 | // Should not happen, since we've already validated msg.url. |
| 2747 | panic(fmt.Sprintf("newWriterAndRequestNoBody(%+v): %v", msg.url, err)) |
| 2748 | } |
| 2749 | |
| 2750 | go sc.runHandler(rw, req, sc.handler.ServeHTTP) |
| 2751 | return promisedID, nil |
| 2752 | } |
| 2753 | |
| 2754 | sc.writeFrame(FrameWriteRequest{ |
| 2755 | write: &writePushPromise{ |
| 2756 | streamID: msg.parent.id, |
| 2757 | method: msg.method, |
| 2758 | url: msg.url, |
| 2759 | h: msg.header, |
| 2760 | allocatePromisedID: allocatePromisedID, |
| 2761 | }, |
| 2762 | stream: msg.parent, |
| 2763 | done: msg.done, |
| 2764 | }) |
| 2765 | } |
| 2766 | |
Blake Mizerany | b4be494 | 2015-12-15 17:33:14 -0800 | [diff] [blame] | 2767 | // foreachHeaderElement splits v according to the "#rule" construction |
| 2768 | // in RFC 2616 section 2.1 and calls fn for each non-empty element. |
| 2769 | func foreachHeaderElement(v string, fn func(string)) { |
| 2770 | v = textproto.TrimString(v) |
| 2771 | if v == "" { |
| 2772 | return |
| 2773 | } |
| 2774 | if !strings.Contains(v, ",") { |
| 2775 | fn(v) |
| 2776 | return |
| 2777 | } |
| 2778 | for _, f := range strings.Split(v, ",") { |
| 2779 | if f = textproto.TrimString(f); f != "" { |
| 2780 | fn(f) |
| 2781 | } |
| 2782 | } |
| 2783 | } |
Brad Fitzpatrick | af4fee9 | 2016-04-05 16:55:11 +0000 | [diff] [blame] | 2784 | |
| 2785 | // From http://httpwg.org/specs/rfc7540.html#rfc.section.8.1.2.2 |
| 2786 | var connHeaders = []string{ |
| 2787 | "Connection", |
| 2788 | "Keep-Alive", |
| 2789 | "Proxy-Connection", |
| 2790 | "Transfer-Encoding", |
| 2791 | "Upgrade", |
| 2792 | } |
| 2793 | |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2794 | // checkValidHTTP2RequestHeaders checks whether h is a valid HTTP/2 request, |
Brad Fitzpatrick | af4fee9 | 2016-04-05 16:55:11 +0000 | [diff] [blame] | 2795 | // per RFC 7540 Section 8.1.2.2. |
| 2796 | // The returned error is reported to users. |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2797 | func checkValidHTTP2RequestHeaders(h http.Header) error { |
| 2798 | for _, k := range connHeaders { |
| 2799 | if _, ok := h[k]; ok { |
| 2800 | return fmt.Errorf("request header %q is not valid in HTTP/2", k) |
Brad Fitzpatrick | af4fee9 | 2016-04-05 16:55:11 +0000 | [diff] [blame] | 2801 | } |
| 2802 | } |
Tom Bergan | c46f265 | 2016-10-25 10:13:20 -0700 | [diff] [blame] | 2803 | te := h["Te"] |
Brad Fitzpatrick | af4fee9 | 2016-04-05 16:55:11 +0000 | [diff] [blame] | 2804 | if len(te) > 0 && (len(te) > 1 || (te[0] != "trailers" && te[0] != "")) { |
| 2805 | return errors.New(`request header "TE" may only be "trailers" in HTTP/2`) |
| 2806 | } |
| 2807 | return nil |
| 2808 | } |
| 2809 | |
| 2810 | func new400Handler(err error) http.HandlerFunc { |
| 2811 | return func(w http.ResponseWriter, r *http.Request) { |
| 2812 | http.Error(w, err.Error(), http.StatusBadRequest) |
| 2813 | } |
| 2814 | } |
Brad Fitzpatrick | 3c5cb15 | 2016-05-19 01:21:59 +0000 | [diff] [blame] | 2815 | |
| 2816 | // ValidTrailerHeader reports whether name is a valid header field name to appear |
| 2817 | // in trailers. |
| 2818 | // See: http://tools.ietf.org/html/rfc7230#section-4.1.2 |
| 2819 | func ValidTrailerHeader(name string) bool { |
| 2820 | name = http.CanonicalHeaderKey(name) |
| 2821 | if strings.HasPrefix(name, "If-") || badTrailer[name] { |
| 2822 | return false |
| 2823 | } |
| 2824 | return true |
| 2825 | } |
| 2826 | |
| 2827 | var badTrailer = map[string]bool{ |
| 2828 | "Authorization": true, |
| 2829 | "Cache-Control": true, |
| 2830 | "Connection": true, |
| 2831 | "Content-Encoding": true, |
| 2832 | "Content-Length": true, |
| 2833 | "Content-Range": true, |
| 2834 | "Content-Type": true, |
| 2835 | "Expect": true, |
| 2836 | "Host": true, |
| 2837 | "Keep-Alive": true, |
| 2838 | "Max-Forwards": true, |
| 2839 | "Pragma": true, |
| 2840 | "Proxy-Authenticate": true, |
| 2841 | "Proxy-Authorization": true, |
| 2842 | "Proxy-Connection": true, |
| 2843 | "Range": true, |
| 2844 | "Realm": true, |
| 2845 | "Te": true, |
| 2846 | "Trailer": true, |
| 2847 | "Transfer-Encoding": true, |
| 2848 | "Www-Authenticate": true, |
| 2849 | } |
Brad Fitzpatrick | 541150a | 2016-10-31 06:24:04 +0000 | [diff] [blame] | 2850 | |
Brad Fitzpatrick | 6dfeb34 | 2016-11-11 23:53:59 +0000 | [diff] [blame] | 2851 | // h1ServerKeepAlivesDisabled reports whether hs has its keep-alives |
| 2852 | // disabled. See comments on h1ServerShutdownChan above for why |
| 2853 | // the code is written this way. |
| 2854 | func h1ServerKeepAlivesDisabled(hs *http.Server) bool { |
| 2855 | var x interface{} = hs |
| 2856 | type I interface { |
| 2857 | doKeepAlives() bool |
| 2858 | } |
| 2859 | if hs, ok := x.(I); ok { |
| 2860 | return !hs.doKeepAlives() |
| 2861 | } |
| 2862 | return false |
| 2863 | } |