Skip to content

Fix H2 stream flow control overflow - #708

Open
arturobernalg wants to merge 1 commit into
apache:masterfrom
arturobernalg:h2-window-update-stream-overflow
Open

arturobernalg wants to merge 1 commit into
apache:masterfrom
arturobernalg:h2-window-update-stream-overflow

Conversation

@arturobernalg

Copy link
Copy Markdown
Member

RFC 9113 Section 6.9.1 requires a sender to ensure that a flow-control window does not exceed 2^31-1 octets. If a WINDOW_UPDATE causes the maximum flow-control window size to be exceeded, the affected stream or connection must be terminated as appropriate.

For a stream, RFC 9113 requires RST_STREAM with FLOW_CONTROL_ERROR. For the connection, it requires GOAWAY with FLOW_CONTROL_ERROR.

The connection-level path already reports a connection FLOW_CONTROL_ERROR. The stream-level path currently throws H2ConnectionException as well, which escalates a stream-specific flow-control error to the entire connection.

This change resets only the affected stream with FLOW_CONTROL_ERROR and updates the existing overflow test to verify the stream-level error scope.

RFC 9113 Section 6.9.1:
https://www.rfc-editor.org/rfc/rfc9113.html#section-6.9.1

Reset the affected stream when WINDOW_UPDATE overflows its window.
Keep connection-level overflow as a connection error.
@arturobernalg
arturobernalg requested a review from ok2c September 29, 2026 11:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant