|
|
1ba31c |
diff --git a/src/http/v2/ngx_http_v2.c b/src/http/v2/ngx_http_v2.c
|
|
|
1ba31c |
index 638ffaf..8b5975c 100644
|
|
|
1ba31c |
--- a/src/http/v2/ngx_http_v2.c
|
|
|
1ba31c |
+++ b/src/http/v2/ngx_http_v2.c
|
|
|
1ba31c |
@@ -4065,6 +4065,8 @@ ngx_http_v2_close_stream(ngx_http_v2_stream_t *stream, ngx_int_t rc)
|
|
|
1ba31c |
*/
|
|
|
1ba31c |
pool = stream->pool;
|
|
|
1ba31c |
|
|
|
1ba31c |
+ h2c->frames -= stream->frames;
|
|
|
1ba31c |
+
|
|
|
1ba31c |
ngx_http_free_request(stream->request, rc);
|
|
|
1ba31c |
|
|
|
1ba31c |
if (pool != h2c->state.pool) {
|
|
|
1ba31c |
diff --git a/src/http/v2/ngx_http_v2.h b/src/http/v2/ngx_http_v2.h
|
|
|
1ba31c |
index 6c42fee..282de8f 100644
|
|
|
1ba31c |
--- a/src/http/v2/ngx_http_v2.h
|
|
|
1ba31c |
+++ b/src/http/v2/ngx_http_v2.h
|
|
|
1ba31c |
@@ -181,6 +181,8 @@ struct ngx_http_v2_stream_s {
|
|
|
1ba31c |
|
|
|
1ba31c |
ngx_buf_t *preread;
|
|
|
1ba31c |
|
|
|
1ba31c |
+ ngx_uint_t frames;
|
|
|
1ba31c |
+
|
|
|
1ba31c |
ngx_http_v2_out_frame_t *free_frames;
|
|
|
1ba31c |
ngx_chain_t *free_frame_headers;
|
|
|
1ba31c |
ngx_chain_t *free_bufs;
|
|
|
1ba31c |
diff --git a/src/http/v2/ngx_http_v2_filter_module.c b/src/http/v2/ngx_http_v2_filter_module.c
|
|
|
1ba31c |
index dac5046..e1928d1 100644
|
|
|
1ba31c |
--- a/src/http/v2/ngx_http_v2_filter_module.c
|
|
|
1ba31c |
+++ b/src/http/v2/ngx_http_v2_filter_module.c
|
|
|
1ba31c |
@@ -1017,22 +1017,34 @@ static ngx_http_v2_out_frame_t *
|
|
|
1ba31c |
ngx_http_v2_filter_get_data_frame(ngx_http_v2_stream_t *stream,
|
|
|
1ba31c |
size_t len, ngx_chain_t *first, ngx_chain_t *last)
|
|
|
1ba31c |
{
|
|
|
1ba31c |
- u_char flags;
|
|
|
1ba31c |
- ngx_buf_t *buf;
|
|
|
1ba31c |
- ngx_chain_t *cl;
|
|
|
1ba31c |
- ngx_http_v2_out_frame_t *frame;
|
|
|
1ba31c |
+ u_char flags;
|
|
|
1ba31c |
+ ngx_buf_t *buf;
|
|
|
1ba31c |
+ ngx_chain_t *cl;
|
|
|
1ba31c |
+ ngx_http_v2_out_frame_t *frame;
|
|
|
1ba31c |
+ ngx_http_v2_connection_t *h2c;
|
|
|
1ba31c |
|
|
|
1ba31c |
frame = stream->free_frames;
|
|
|
1ba31c |
+ h2c = stream->connection;
|
|
|
1ba31c |
|
|
|
1ba31c |
if (frame) {
|
|
|
1ba31c |
stream->free_frames = frame->next;
|
|
|
1ba31c |
|
|
|
1ba31c |
- } else {
|
|
|
1ba31c |
+ } else if (h2c->frames < 10000) {
|
|
|
1ba31c |
frame = ngx_palloc(stream->request->pool,
|
|
|
1ba31c |
sizeof(ngx_http_v2_out_frame_t));
|
|
|
1ba31c |
if (frame == NULL) {
|
|
|
1ba31c |
return NULL;
|
|
|
1ba31c |
}
|
|
|
1ba31c |
+
|
|
|
1ba31c |
+ stream->frames++;
|
|
|
1ba31c |
+ h2c->frames++;
|
|
|
1ba31c |
+
|
|
|
1ba31c |
+ } else {
|
|
|
1ba31c |
+ ngx_log_error(NGX_LOG_INFO, h2c->connection->log, 0,
|
|
|
1ba31c |
+ "http2 flood detected");
|
|
|
1ba31c |
+
|
|
|
1ba31c |
+ h2c->connection->error = 1;
|
|
|
1ba31c |
+ return NULL;
|
|
|
1ba31c |
}
|
|
|
1ba31c |
|
|
|
1ba31c |
flags = last->buf->last_buf ? NGX_HTTP_V2_END_STREAM_FLAG : 0;
|