Re: Invalid HTTP2 preface handling?
Mark Nottingham <mnot@mnot.net> Wed, 11 February 2015 11:51 UTC
Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 978B81A884F for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Wed, 11 Feb 2015 03:51:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.912
X-Spam-Level:
X-Spam-Status: No, score=-6.912 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nvHFaNWmqYte for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Wed, 11 Feb 2015 03:51:11 -0800 (PST)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 370061A8847 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Wed, 11 Feb 2015 03:51:08 -0800 (PST)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1YLVkN-0000HT-5U for ietf-http-wg-dist@listhub.w3.org; Wed, 11 Feb 2015 11:46:23 +0000
Resent-Date: Wed, 11 Feb 2015 11:46:23 +0000
Resent-Message-Id: <E1YLVkN-0000HT-5U@frink.w3.org>
Received: from lisa.w3.org ([128.30.52.41]) by frink.w3.org with esmtp (Exim 4.80) (envelope-from <mnot@mnot.net>) id 1YLVkH-0000Fs-Aj for ietf-http-wg@listhub.w3.org; Wed, 11 Feb 2015 11:46:17 +0000
Received: from mxout-07.mxes.net ([216.86.168.182]) by lisa.w3.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.72) (envelope-from <mnot@mnot.net>) id 1YLVkG-0004zU-4A for ietf-http-wg@w3.org; Wed, 11 Feb 2015 11:46:17 +0000
Received: from [192.168.1.73] (unknown [59.167.195.195]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.mxes.net (Postfix) with ESMTPSA id 30A7422E261; Wed, 11 Feb 2015 06:45:51 -0500 (EST)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2070.6\))
From: Mark Nottingham <mnot@mnot.net>
In-Reply-To: <19907.1423641715@critter.freebsd.dk>
Date: Wed, 11 Feb 2015 22:45:48 +1100
Cc: Greg Wilkins <gregw@intalio.com>, HTTP Working Group <ietf-http-wg@w3.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <487B2856-0BF9-4114-96A8-57263C3EC6B8@mnot.net>
References: <CAH_y2NE5Sa625XEec5WXJ7LdjK+h1b4M=Fc-_iGj2ZQKa1q_jg@mail.gmail.com> <19907.1423641715@critter.freebsd.dk>
To: Poul-Henning Kamp <phk@phk.freebsd.dk>
X-Mailer: Apple Mail (2.2070.6)
Received-SPF: pass client-ip=216.86.168.182; envelope-from=mnot@mnot.net; helo=mxout-07.mxes.net
X-W3C-Hub-Spam-Status: No, score=-3.4
X-W3C-Hub-Spam-Report: AWL=-0.799, BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001
X-W3C-Scan-Sig: lisa.w3.org 1YLVkG-0004zU-4A 384add334ae1f3c77d106e14812a076a
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Invalid HTTP2 preface handling?
Archived-At: <http://www.w3.org/mid/487B2856-0BF9-4114-96A8-57263C3EC6B8@mnot.net>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/28822
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>
> On 11 Feb 2015, at 7:01 pm, Poul-Henning Kamp <phk@phk.freebsd.dk> wrote: > >> I'm wondering what would be the problem if on an invalid preface, the >> server check if it is actually a valid HTTP/1 request and if so, then to >> proceed on that basis? > > If by "proceed" you mean "Send back a HTTP/1 response that will > help people at the far end diagnose the problem and then close", > you'll be fine. Anything more ambitious is on shaky ground. Makes sense — and sounds like a perfect use of 505 HTTP Version Not Supported. -- Mark Nottingham https://www.mnot.net/
- Invalid HTTP2 preface handling? Greg Wilkins
- Re: Invalid HTTP2 preface handling? Mark Nottingham
- Re: Invalid HTTP2 preface handling? Amos Jeffries
- Re: Invalid HTTP2 preface handling? Greg Wilkins
- Re: Invalid HTTP2 preface handling? Amos Jeffries
- Re: Invalid HTTP2 preface handling? Michael Sweet
- Re: Invalid HTTP2 preface handling? Greg Wilkins
- Re: Invalid HTTP2 preface handling? Martin Thomson
- Re: Invalid HTTP2 preface handling? Willy Tarreau
- Re: Invalid HTTP2 preface handling? Julian Reschke
- Re: Invalid HTTP2 preface handling? Poul-Henning Kamp
- Re: Invalid HTTP2 preface handling? Mark Nottingham
- Re: Invalid HTTP2 preface handling? Greg Wilkins