http2: fixing upstream sending metadata after ending the stream#14061
Merged
mattklein123 merged 7 commits intoenvoyproxy:masterfrom Nov 19, 2020
Merged
http2: fixing upstream sending metadata after ending the stream#14061mattklein123 merged 7 commits intoenvoyproxy:masterfrom
mattklein123 merged 7 commits intoenvoyproxy:masterfrom
Conversation
Signed-off-by: Adi Suissa-Peleg <adip@google.com>
Signed-off-by: Adi Suissa-Peleg <adip@google.com>
Signed-off-by: Adi Suissa-Peleg <adip@google.com>
Signed-off-by: Adi Suissa-Peleg <adip@google.com>
…oder_bug Signed-off-by: Adi Suissa-Peleg <adip@google.com>
Signed-off-by: Adi Suissa-Peleg <adip@google.com>
…oder_bug Signed-off-by: Adi Suissa-Peleg <adip@google.com>
Contributor
Author
|
@asraa Thanks for the comments. |
yanavlasov
approved these changes
Nov 18, 2020
Contributor
Author
|
/retest |
|
Retrying Azure Pipelines: |
andreyprezotto
pushed a commit
to andreyprezotto/envoy
that referenced
this pull request
Nov 24, 2020
…yproxy#14061) Signed-off-by: Adi Suissa-Peleg <adip@google.com>
qqustc
pushed a commit
to qqustc/envoy
that referenced
this pull request
Nov 24, 2020
…yproxy#14061) Signed-off-by: Adi Suissa-Peleg <adip@google.com> Signed-off-by: Qin Qin <qqin@google.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Commit Message: fixing upstream sending metadata after ending the stream.
Additional Description:
A fuzz test detected that when upstream ends the stream, and the proceeds to send metadata, the response decoder is accessed after it was freed.
This happens when either the
UpstreamRequestor theActiveRequestare destroyed (as in the added integration test, and the failed fuzz test, respectively), and a following metadata frame sent by upstream is being processed byConnectionImpl::onMetadataFrameComplete.This PR verifies that a stream was not remotely closed before processing the metadata frame.
Risk Level: Medium - changes to codec (Metadata processing only).
Testing: Added an integration test and the fuzz test that detected the issue.
Docs Changes: N/A.
Release Notes: N/A.
Platform Specific Features: N/A.
Fixes fuzz issue: 26834
Signed-off-by: Adi Suissa-Peleg adip@google.com