Log malformed HTTP/2 requests - #13059
Conversation
There was a problem hiding this comment.
Pull request overview
This PR adds a “pre-transaction” access logging path for malformed HTTP/2 request headers that are rejected before HttpSM is created, so these failures can still be recorded in squid.log (similar to HTTP/1 behavior).
Changes:
- Add
LogAccess::PreTransactionLogDataand extendLogAccessto support access log marshaling without anHttpSM. - Emit a best-effort access log entry from the HTTP/2 layer when rejecting malformed HEADERS/CONTINUATION input.
- Add gold and unit tests validating both malformed and valid HTTP/2 request logging.
Reviewed changes
Copilot reviewed 9 out of 9 changed files in this pull request and generated 4 comments.
Show a summary per file
| File | Description |
|---|---|
| tests/gold_tests/connect/replays/h2_malformed_request_logging.replay.yaml | Adds replay traffic for valid HTTP/2 GET and CONNECT cases used by the gold test. |
| tests/gold_tests/connect/malformed_h2_request_client.py | Adds a low-level client to send deliberately malformed HTTP/2 requests on the wire. |
| tests/gold_tests/connect/h2_malformed_request_logging.test.py | Adds an integration test that asserts malformed HTTP/2 requests are access logged and do not reach origin. |
| src/proxy/logging/unit-tests/test_LogAccess.cc | Adds Catch2 unit tests covering pre-transaction LogAccess marshaling behavior. |
| src/proxy/logging/LogAccess.cc | Implements pre-transaction initialization and adds guards/fallbacks for marshaling without HttpSM. |
| src/proxy/logging/CMakeLists.txt | Registers the new test_LogAccess executable in CMake when testing is enabled. |
| src/proxy/http2/Http2ConnectionState.cc | Logs malformed decoded request headers via Log::access() before stream reset/GOAWAY. |
| include/proxy/logging/LogAccess.h | Defines PreTransactionLogData and adds support helpers for pre-transaction logging mode. |
| include/proxy/http2/Http2Stream.h | Exposes a const accessor for the decoded receive header (get_receive_header()). |
93a7fba to
fa9178b
Compare
maskit
left a comment
There was a problem hiding this comment.
It's good that this narrows the gap between H1 and H2 in terms of logging.
Suggestions for future improvement:
- I'm pretty sure H3 has the same issue. It would be nice if ProxyTransaction could take care of this pre-transaction scenario .
- A cleaner interface would be having just
LogAccess(LogData *data)for both. The subclasses ofLogDatawould beTransactionLogDatathat copies data fromHttpSM, andPreTransactionLogDatathat copies data fromProxyTransaction(orHttp2Stream). The subclasses would be defined in http or http2 module. Then we may be able to remove the the circular dependency (http <-> logging).
fa9178b to
03e7c09
Compare
|
Converting to a draft while I work on @maskit 's comments. I'll un-draft when the patch is in better shape. |
03e7c09 to
9ef2a82
Compare
45d1858 to
9801fc9
Compare
maskit
left a comment
There was a problem hiding this comment.
The copies are concerning. Otherwise, looks good.
4613682 to
d5ceca7
Compare
Unlike HTTP/1 transactions, malformed HTTP/2 requests are rejected before HttpSM creation, so they bypassed the normal transaction logging path. That left malformed h2 traffic out of squid.log even when similar h1 failures were visible. This adds a pre-transaction LogAccess path for malformed h2 request headers and emits a best-effort access log entry before resetting the stream.
d5ceca7 to
c374c0c
Compare
|
10.2.x backport PR: #13105 |
Unlike HTTP/1 transactions, malformed HTTP/2 requests are rejected before HttpSM creation, so they bypassed the normal transaction logging path. That left malformed h2 traffic out of squid.log even when similar h1 failures were visible. This adds a pre-transaction LogAccess path for malformed h2 request headers and emits a best-effort access log entry before resetting the stream. (cherry picked from commit 05554ca)
Unlike HTTP/1 transactions, malformed HTTP/2 requests are rejected before HttpSM creation, so they bypassed the normal transaction logging path. That left malformed h2 traffic out of squid.log even when similar h1 failures were visible. This adds a pre-transaction LogAccess path for malformed h2 request headers and emits a best-effort access log entry before resetting the stream. (cherry picked from commit 05554ca)
|
Added to milestone 10.2.0 via #13105 |
This addresses a performance regression added by apache#13059. Malformed pre-transaction logging introduced an extra virtual data interface on the normal access log path. That made every completed transaction pay for indirection that is only needed for rare protocol-layer failures. This replaces the virtual hierarchy with a concrete composed TransactionLogData wrapper. This keeps LogAccess using one data object while routing the common HttpSM path through direct getters and falling back to owned pre-transaction data only when no HttpSM exists.
This addresses a performance regression added by apache#13059. Malformed pre-transaction logging introduced an extra virtual data interface on the normal access log path. That made every completed transaction pay for indirection that is only needed for rare protocol-layer failures. This replaces the virtual hierarchy with a concrete composed TransactionLogData wrapper. This keeps LogAccess using one data object while routing the common HttpSM path through direct getters and falling back to owned pre-transaction data only when no HttpSM exists.
This addresses a performance regression added by #13059. Malformed pre-transaction logging introduced an extra virtual data interface on the normal access log path. That made every completed transaction pay for indirection that is only needed for rare protocol-layer failures. This replaces the virtual hierarchy with a concrete composed TransactionLogData wrapper. This keeps LogAccess using one data object while routing the common HttpSM path through direct getters and falling back to owned pre-transaction data only when no HttpSM exists. (cherry picked from commit 05a916f)
This addresses a performance regression added by #13059. Malformed pre-transaction logging introduced an extra virtual data interface on the normal access log path. That made every completed transaction pay for indirection that is only needed for rare protocol-layer failures. This replaces the virtual hierarchy with a concrete composed TransactionLogData wrapper. This keeps LogAccess using one data object while routing the common HttpSM path through direct getters and falling back to owned pre-transaction data only when no HttpSM exists.
m_http_sm was removed from LogAccess by #13059 (TransactionLogData).
Malformed HTTP/2 parse errors can hit this path during normal bad-client traffic, and logging each one at ERROR keeps diags noisy. PR #13059 now emits transaction log entries for these malformed requests, so operators can diagnose the rejected request without this default error log noise. This downgrades the stream creation failure message to the existing HTTP/2 session debug path. Operators can still enable the http2_cs debug tag when they need the protocol-level detail.
Malformed client HTTP/2 streams can produce noisy error-level diagnostics even though the malformed parse details are now available in transaction logs via apache#13059. The original downgrade targeted the outbound session stream creation path, which can hide origin-side signals such as concurrent stream limit failures. This downgrades the inbound rcv_frame stream-error diagnostic to Http2StreamDebug while leaving outbound stream creation errors at Error level. This also updates the malformed request AuTest to look for the debug diagnostic in traffic.out.
Malformed client HTTP/2 streams can produce noisy error-level diagnostics even though the malformed parse details are now available in transaction logs via apache#13059. This downgrades the inbound rcv_frame stream-error diagnostic to Http2StreamDebug while leaving outbound stream creation errors at Error level. This also updates the malformed request AuTest to look for the debug diagnostic in traffic.out and relies on Http2StreamDebug to include the session and stream identifiers.
Malformed client HTTP/2 streams can produce noisy error-level diagnostics even though the malformed parse details are now available in transaction logs via #13059. This downgrades the inbound rcv_frame stream-error diagnostic to Http2StreamDebug while leaving outbound stream creation errors at Error level. This also updates the malformed request AuTest to look for the debug diagnostic in traffic.out and relies on Http2StreamDebug to include the session and stream identifiers.
This addresses a performance regression added by apache#13059. Malformed pre-transaction logging introduced an extra virtual data interface on the normal access log path. That made every completed transaction pay for indirection that is only needed for rare protocol-layer failures. This replaces the virtual hierarchy with a concrete composed TransactionLogData wrapper. This keeps LogAccess using one data object while routing the common HttpSM path through direct getters and falling back to owned pre-transaction data only when no HttpSM exists.
m_http_sm was removed from LogAccess by apache#13059 (TransactionLogData).
Malformed HTTP/2 parse errors can hit this path during normal bad-client traffic, and logging each one at ERROR keeps diags noisy. PR apache#13059 now emits transaction log entries for these malformed requests, so operators can diagnose the rejected request without this default error log noise. This downgrades the stream creation failure message to the existing HTTP/2 session debug path. Operators can still enable the http2_cs debug tag when they need the protocol-level detail.
Malformed client HTTP/2 streams can produce noisy error-level diagnostics even though the malformed parse details are now available in transaction logs via apache#13059. This downgrades the inbound rcv_frame stream-error diagnostic to Http2StreamDebug while leaving outbound stream creation errors at Error level. This also updates the malformed request AuTest to look for the debug diagnostic in traffic.out and relies on Http2StreamDebug to include the session and stream identifiers.
Malformed client HTTP/2 streams can produce noisy error-level diagnostics even though the malformed parse details are now available in transaction logs via apache#13059. This downgrades the inbound rcv_frame stream-error diagnostic to Http2StreamDebug while leaving outbound stream creation errors at Error level. This also updates the malformed request AuTest to look for the debug diagnostic in traffic.out and relies on Http2StreamDebug to include the session and stream identifiers. (cherry picked from commit 87cf5ec)
Unlike HTTP/1 transactions, malformed HTTP/2 requests are rejected before HttpSM creation, so they bypassed the normal transaction logging path. That left malformed h2 traffic out of squid.log even when similar h1 failures were visible.
This adds a pre-transaction LogAccess path for malformed h2 request headers and emits a best-effort access log entry before resetting the stream.