mirror of
https://github.com/zebrajr/node.git
synced 2025-12-06 12:20:27 +01:00
Lazily allocate `ArrayBuffer`s for the contents of DATA frames.
Creating `ArrayBuffer`s is, sadly, not a cheap operation with V8.
This is part of performance improvements to mitigate CVE-2019-9513.
Together with the previous commit, these changes improve throughput
in the adversarial case by about 100 %, and there is little more
that we can do besides artificially limiting the rate of incoming
metadata frames (i.e. after this patch, CPU usage is virtually
exclusively in libnghttp2).
[This backport also applies changes from 83e1b97443 and required
some manual work due to the lack of `AllocatedBuffer` on v10.x.
More work was necessary for v8.x, including copying utilities
for `util.h` from more recent Node.js versions.]
Refs: https://github.com/nodejs/node/pull/26201
Backport-PR-URL: https://github.com/nodejs/node/pull/29124
PR-URL: https://github.com/nodejs/node/pull/29122
Reviewed-By: Rich Trott <rtrott@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
49 lines
1.2 KiB
JavaScript
49 lines
1.2 KiB
JavaScript
'use strict';
|
|
|
|
const common = require('../common');
|
|
if (!common.hasCrypto)
|
|
common.skip('missing crypto');
|
|
|
|
const http2 = require('http2');
|
|
|
|
// Test that maxSessionMemory Caps work
|
|
|
|
const largeBuffer = Buffer.alloc(2e6);
|
|
|
|
const server = http2.createServer({ maxSessionMemory: 1 });
|
|
|
|
server.on('stream', common.mustCall((stream) => {
|
|
stream.on('error', (err) => {
|
|
if (err.code !== 'ECONNRESET')
|
|
throw err;
|
|
});
|
|
stream.respond();
|
|
stream.end(largeBuffer);
|
|
}));
|
|
|
|
server.listen(0, common.mustCall(() => {
|
|
const client = http2.connect(`http://localhost:${server.address().port}`);
|
|
|
|
{
|
|
const req = client.request();
|
|
|
|
req.on('response', () => {
|
|
// This one should be rejected because the server is over budget
|
|
// on the current memory allocation
|
|
const req = client.request();
|
|
req.on('error', common.expectsError({
|
|
code: 'ERR_HTTP2_STREAM_ERROR',
|
|
type: Error,
|
|
message: 'Stream closed with error code NGHTTP2_ENHANCE_YOUR_CALM'
|
|
}));
|
|
req.on('close', common.mustCall(() => {
|
|
server.close();
|
|
client.destroy();
|
|
}));
|
|
});
|
|
|
|
req.resume();
|
|
req.on('close', common.mustCall());
|
|
}
|
|
}));
|