mirror of
https://github.com/pgsty/minio.git
synced 2026-10-06 01:35:57 +03:00
fix(http): enforce absolute read header timeout against slow HTTP DoS
Slow HTTP DoS scanners (issue #183) hold connections open by dribbling request bytes, and two inherited gaps let them: 1. deadlineconn re-extended the read deadline on every partial read, converting net/http's absolute ReadHeaderTimeout into an inter-byte activity timeout that a trickle bypasses entirely. 2. the --read-header-timeout flag (default 30s) was never copied into the server context, so the server actually ran with header timeout disabled (upstream shares this bug). Keep deadlineconn on the write side only so response writes stay activity-based, and leave ReadTimeout at zero now that native read deadlines are honored, since an absolute cap would terminate large uploads. Request bodies keep an activity-based bound instead via a per-read deadline refresh in xhttp, and the flag is wired through common-main. With this, a slow-header connection is cut at ReadHeaderTimeout (verified live: 33s kill vs. unlimited before), while slow progressing uploads (32s for 2 MiB), stalled bodies (30s cleanup), slow readers (~30s write cutoff) and plain S3 traffic are unaffected. Fixes #183 Signed-off-by: Feng Ruohang <rh@vonng.com>
This commit is contained in:
+5
-1
@@ -905,7 +905,11 @@ func serverMain(ctx *cli.Context) {
|
||||
UseHandler(setCriticalErrorHandler(corsHandler(handler))).
|
||||
UseTLSConfig(newTLSConfig(getCert)).
|
||||
UseIdleTimeout(globalServerCtxt.IdleTimeout).
|
||||
UseReadTimeout(globalServerCtxt.IdleTimeout).
|
||||
// WriteTimeout only resets the activity-based write deadline
|
||||
// that deadlineconn enforces per response write. ReadTimeout is
|
||||
// left at zero: with native read deadlines honored again it would
|
||||
// cap the whole request including large uploads; request bodies
|
||||
// are bounded per-read by xhttp instead.
|
||||
UseWriteTimeout(globalServerCtxt.IdleTimeout).
|
||||
UseReadHeaderTimeout(globalServerCtxt.ReadHeaderTimeout).
|
||||
UseBaseContext(GlobalContext).
|
||||
|
||||
Reference in New Issue
Block a user