Re: Invalid HTTP2 preface handling?

Willy Tarreau <w@1wt.eu> Wed, 11 February 2015 06:12 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C00291A7D85 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 10 Feb 2015 22:12:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.912
X-Spam-Level:
X-Spam-Status: No, score=-6.912 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6c5DYtMhUZ_z for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 10 Feb 2015 22:12:38 -0800 (PST)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C82A91A7113 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Tue, 10 Feb 2015 22:12:38 -0800 (PST)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1YLQTn-0003QP-V4 for ietf-http-wg-dist@listhub.w3.org; Wed, 11 Feb 2015 06:08:55 +0000
Resent-Date: Wed, 11 Feb 2015 06:08:55 +0000
Resent-Message-Id: <E1YLQTn-0003QP-V4@frink.w3.org>
Received: from lisa.w3.org ([128.30.52.41]) by frink.w3.org with esmtp (Exim 4.80) (envelope-from <w@1wt.eu>) id 1YLQTh-0003Pe-KS for ietf-http-wg@listhub.w3.org; Wed, 11 Feb 2015 06:08:49 +0000
Received: from 1wt.eu ([62.212.114.60]) by lisa.w3.org with esmtp (Exim 4.72) (envelope-from <w@1wt.eu>) id 1YLQTg-0006G9-DM for ietf-http-wg@w3.org; Wed, 11 Feb 2015 06:08:49 +0000
Received: (from willy@localhost) by pcw.home.local (8.14.3/8.14.3/Submit) id t1B68Box009762; Wed, 11 Feb 2015 07:08:11 +0100
Date: Wed, 11 Feb 2015 07:08:11 +0100
From: Willy Tarreau <w@1wt.eu>
To: Greg Wilkins <gregw@intalio.com>
Cc: Amos Jeffries <squid3@treenet.co.nz>, HTTP Working Group <ietf-http-wg@w3.org>
Message-ID: <20150211060811.GA9759@1wt.eu>
References: <CAH_y2NE5Sa625XEec5WXJ7LdjK+h1b4M=Fc-_iGj2ZQKa1q_jg@mail.gmail.com> <5C91DE2C-BC82-4142-B292-815EED3627EC@mnot.net> <54DAA3A4.8060608@treenet.co.nz> <CAH_y2NG0_Y9nnDjLd2Fc_5wBessfy0DOfKBfkH8NiKjyzAiRVg@mail.gmail.com> <54DABF12.70609@treenet.co.nz> <CAH_y2NG5DtZ3zBP7FsUy392i8pcaHvTWvOdHODSi2gZ9vEZ_7g@mail.gmail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <CAH_y2NG5DtZ3zBP7FsUy392i8pcaHvTWvOdHODSi2gZ9vEZ_7g@mail.gmail.com>
User-Agent: Mutt/1.4.2.3i
Received-SPF: pass client-ip=62.212.114.60; envelope-from=w@1wt.eu; helo=1wt.eu
X-W3C-Hub-Spam-Status: No, score=-3.0
X-W3C-Hub-Spam-Report: AWL=-3.026, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01
X-W3C-Scan-Sig: lisa.w3.org 1YLQTg-0006G9-DM 6d763e5b901975e1121f9740b0d00266
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Invalid HTTP2 preface handling?
Archived-At: <http://www.w3.org/mid/20150211060811.GA9759@1wt.eu>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/28813
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

Hi Greg,

On Wed, Feb 11, 2015 at 03:15:38PM +1100, Greg Wilkins wrote:
> Anyway, I've got my answer.  There is no specific threat, just a preference
> to not allow such a simple upgrade/downgrade for the sake of prudence.    I
> can accept that and while I'm still considering supporting a preface based
> version switch, it will be a use-at-own-risk private feature.

In fact, we all want to be strict on this in order to ensure that no lazy
implementer would notice it works well without the preface and decides not
to emit it. That's where the trouble could start.

Cheers,
Willy