-
Notifications
You must be signed in to change notification settings - Fork 7
test OOM by control frames attack #615
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
4d93c65 to
63e2a8c
Compare
|
and you need to add these tests to |
- they are no stress tests anymore, now they are tests for `max_queued_control_frames` directive. We don't need a stress tests because TempestaFW has ways to protect against such an attack; - all tests work on DeproxyClientH2; - add tests for default and other values;
…p2_general/test_max_queued_control_frames.py`
change expected number of dmesg warnings. TempestaFW doesn't always output a warning in dmesg
69fef44 to
1e3e12e
Compare
| client.send_bytes(client.h2_connection.data_to_send()) | ||
| self.assertTrue(client.wait_for_ack_settings()) | ||
|
|
||
| client.make_request(client.create_request(method="GET", headers=[])) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There is no need to request a large response now, because the sockbuf is already set to a small enough size. Also we don't need the backend, because control-frame-slow-read does not involve the backend.
fb27281 to
11076fe
Compare
11076fe to
fcd22dc
Compare
| }, | ||
| { | ||
| "name": "t_stress.test_flood.TestH2ControlFramesFlood.test_reset_stream", | ||
| "reason": "Disabled by test issue #612" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please comment test cases with CVE number and name of attack that we can easily grep test suite for the attack scenarios. Even better to name the tests according to the emulated attacks.
part of #612
tests for tempesta-tech/tempesta#2108