Skip to content

mux: framing read deadlines + bounded payload growth (Fixes #617 — slowloris stall) - #650

Open
Kiryuumaru wants to merge 3 commits into
masterfrom
fix/617-framing-liveness
Open

Kiryuumaru wants to merge 3 commits into
masterfrom
fix/617-framing-liveness

Conversation

@Kiryuumaru

Copy link
Copy Markdown
Owner

Fixes #617.

Slowloris-style stall: frame and payload reads had no read deadline, letting a trickling peer hold a stream open indefinitely.

What this changes:

  • Adds MultiplexerOptions.FrameReadTimeout plus a payload growth rate knob for bounded incremental buffering.
  • StreamMultiplexer reader loop enforces read deadlines with incremental bounded growth.
  • MuxHandshake passes timeouts through with growth handling.

Tests: FramePayloadLivenessTests, 14/14 passing. Full suite and multi-TFM build green prior to commit.

Docs: ADR-0002 plus framing-protocol, multiplexer-options, and scope updates.

Kiryuumaru and others added 3 commits September 17, 2026 10:14
Slowloris-style stall: frame/payload reads had no read deadline, letting a trickling peer hold a stream open indefinitely.

Adds MultiplexerOptions.FrameReadTimeout plus payload growth rate knob; StreamMultiplexer reader loop enforces deadlines with incremental bounded growth; MuxHandshake passes timeouts through with growth. Tests: FramePayloadLivenessTests (14/14). Docs: ADR-0002 plus framing-protocol, multiplexer-options, scope updates.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security: framing slowloris - 16MB rent with no read timeout

1 participant