Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

http: keep trailers TE header instead of removing it #32255

Merged
merged 23 commits into from
Feb 12, 2024
Merged
Show file tree
Hide file tree
Changes from 14 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions changelogs/current.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@ date: Pending

behavior_changes:
# *Changes that are expected to cause an incompatibility if applicable; deployment changes are likely required*
- area: http
change: |
Remove the hop by hop TE header from downstream request headers if it's not set to `trailers`. This change can be temporarily
reverted by setting ``envoy.reloadable_features.sanitize_te`` to false.

minor_behavior_changes:
# *Changes that may cause incompatibilities for some users, but should not for most*
Expand Down
32 changes: 29 additions & 3 deletions source/common/http/conn_manager_utility.cc
Original file line number Diff line number Diff line change
Expand Up @@ -92,9 +92,8 @@ ConnectionManagerUtility::MutateRequestHeadersResult ConnectionManagerUtility::m
if (!Utility::isUpgrade(request_headers)) {
request_headers.removeConnection();
request_headers.removeUpgrade();
if (Runtime::runtimeFeatureEnabled("envoy.reloadable_features.sanitize_te")) {
request_headers.removeTE();
}

sanitizeTEHeader(request_headers);
}

// Clean proxy headers.
Expand Down Expand Up @@ -292,6 +291,33 @@ ConnectionManagerUtility::MutateRequestHeadersResult ConnectionManagerUtility::m
return {final_remote_address, absl::nullopt};
}

void ConnectionManagerUtility::sanitizeTEHeader(RequestHeaderMap& request_headers) {
if (!Runtime::runtimeFeatureEnabled("envoy.reloadable_features.sanitize_te")) {
return;
}

std::string te_header = request_headers.getTEValue();
if (te_header.empty()) {
return;
}

bool has_trailers_te = false;

std::vector<std::string> te_values = absl::StrSplit(te_header, ',');
for (const auto& teValue : te_values) {
quantumsheep marked this conversation as resolved.
Show resolved Hide resolved
if (absl::StripAsciiWhitespace(teValue) == Http::Headers::get().TEValues.Trailers) {
has_trailers_te = true;
quantumsheep marked this conversation as resolved.
Show resolved Hide resolved
break;
}
}

if (has_trailers_te) {
request_headers.setTE(Http::Headers::get().TEValues.Trailers);
} else {
request_headers.removeTE();
}
}

void ConnectionManagerUtility::cleanInternalHeaders(
RequestHeaderMap& request_headers, bool edge_request,
const std::list<Http::LowerCaseString>& internal_only_headers) {
Expand Down
1 change: 1 addition & 0 deletions source/common/http/conn_manager_utility.h
Original file line number Diff line number Diff line change
Expand Up @@ -141,6 +141,7 @@ class ConnectionManagerUtility {
static void mutateXfccRequestHeader(RequestHeaderMap& request_headers,
Network::Connection& connection,
ConnectionManagerConfig& config);
static void sanitizeTEHeader(RequestHeaderMap& request_headers);
static void cleanInternalHeaders(RequestHeaderMap& request_headers, bool edge_request,
const std::list<Http::LowerCaseString>& internal_only_headers);
};
Expand Down
37 changes: 37 additions & 0 deletions test/common/http/conn_manager_utility_test.cc
Original file line number Diff line number Diff line change
Expand Up @@ -2237,5 +2237,42 @@ TEST_F(ConnectionManagerUtilityTest, DoNotOverwriteXForwardedPortFromUntrustedHo
EXPECT_EQ("80", headers.getForwardedPortValue());
}

// Verify when TE header is present, the value should be preserved only if it's equal to "trailers".
TEST_F(ConnectionManagerUtilityTest, KeepTrailersTEHeaderSimple) {
TestRequestHeaderMapImpl headers{{"te", "trailers"}};
callMutateRequestHeaders(headers, Protocol::Http2);

EXPECT_EQ("trailers", headers.getTEValue());
}

// Verify when TE header is present, the value should be preserved only if it contains "trailers".
TEST_F(ConnectionManagerUtilityTest, KeepTrailersTEHeaderMultipleValuesAndWeigthted) {
TestRequestHeaderMapImpl headers{{"te", "chunked;q=0.8 , trailers ,deflate "}};
callMutateRequestHeaders(headers, Protocol::Http2);

EXPECT_EQ("trailers", headers.getTEValue());
}

// Verify when TE header is present, the value should be discarded if it doesn't contains
// "trailers".
TEST_F(ConnectionManagerUtilityTest, DiscardTEHeaderWithoutTrailers) {
TestRequestHeaderMapImpl headers{{"te", "gzip"}};
callMutateRequestHeaders(headers, Protocol::Http2);

EXPECT_EQ("", headers.getTEValue());
}

// Verify when TE header is present, the value should be kept if the reloadable feature
// "sanitize_te" is enabled.
TEST_F(ConnectionManagerUtilityTest, KeepTrailersTEHeaderSimple) {
TestScopedRuntime scoped_runtime;
scoped_runtime.mergeValues({{"envoy.reloadable_features.sanitize_te", "false"}});

TestRequestHeaderMapImpl headers{{"te", "gzip"}};
callMutateRequestHeaders(headers, Protocol::Http2);

EXPECT_EQ("gzip", headers.getTEValue());
}

} // namespace Http
} // namespace Envoy
46 changes: 46 additions & 0 deletions test/integration/protocol_integration_test.cc
Original file line number Diff line number Diff line change
Expand Up @@ -809,6 +809,52 @@ TEST_P(DownstreamProtocolIntegrationTest, TeSanitization) {
EXPECT_EQ("", upstream_headers->getTEValue());
}

TEST_P(DownstreamProtocolIntegrationTest, TeSanitizationTrailers) {
if (downstreamProtocol() != Http::CodecType::HTTP1) {
return;
}

autonomous_upstream_ = true;
config_helper_.addRuntimeOverride("envoy.reloadable_features.sanitize_te", "true");

default_request_headers_.setTE("trailers");

initialize();
codec_client_ = makeHttpConnection(lookupPort("http"));
auto response = codec_client_->makeHeaderOnlyRequest(default_request_headers_);
ASSERT_TRUE(response->waitForEndStream());
EXPECT_TRUE(response->complete());
EXPECT_EQ("200", response->headers().getStatusValue());

auto upstream_headers =
reinterpret_cast<AutonomousUpstream*>(fake_upstreams_[0].get())->lastRequestHeaders();
EXPECT_TRUE(upstream_headers != nullptr);
EXPECT_EQ("trailers", upstream_headers->getTEValue());
}

TEST_P(DownstreamProtocolIntegrationTest, TeSanitizationTrailersMultipleValuesAndWeigthted) {
if (downstreamProtocol() != Http::CodecType::HTTP1) {
return;
}

autonomous_upstream_ = true;
config_helper_.addRuntimeOverride("envoy.reloadable_features.sanitize_te", "true");

default_request_headers_.setTE("chunked;q=0.8 , trailers ,deflate ");

initialize();
codec_client_ = makeHttpConnection(lookupPort("http"));
auto response = codec_client_->makeHeaderOnlyRequest(default_request_headers_);
ASSERT_TRUE(response->waitForEndStream());
EXPECT_TRUE(response->complete());
EXPECT_EQ("200", response->headers().getStatusValue());

auto upstream_headers =
reinterpret_cast<AutonomousUpstream*>(fake_upstreams_[0].get())->lastRequestHeaders();
EXPECT_TRUE(upstream_headers != nullptr);
EXPECT_EQ("trailers", upstream_headers->getTEValue());
}

// Regression test for https://github.com/envoyproxy/envoy/issues/10270
TEST_P(ProtocolIntegrationTest, LongHeaderValueWithSpaces) {
// Header with at least 20kb of spaces surrounded by non-whitespace characters to ensure that
Expand Down
Loading