Skip to content

fix(h1): prevent panic on non-UTF-8 response headers in trace logging (#1023) - #1039

Open
Aditya-9-6 wants to merge 2 commits into
cloudflare:mainfrom
Aditya-9-6:fix/h1-client-trace-utf8-panic-1023
Open

Aditya-9-6 wants to merge 2 commits into
cloudflare:mainfrom
Aditya-9-6:fix/h1-client-trace-utf8-panic-1023

Conversation

@Aditya-9-6

Copy link
Copy Markdown

Description

In pingora-core/src/protocols/http/v1/client.rs (read_response_task), raw response header bytes were parsed using str::from_utf8(self.get_headers_raw()).unwrap() inside a trace! statement.

When an upstream server returns response headers with non-UTF-8 bytes (such as ISO-8859-1 encodings or binary payloads), this .unwrap() triggers a panic and aborts the proxy process. Furthermore, because arguments to logging macros can be evaluated eagerly when log level filters admit trace or dynamic filtering is used, this posed a major reliability risk in production.

Fix

  • Replace str::from_utf8(self.get_headers_raw()).unwrap() with String::from_utf8_lossy(self.get_headers_raw()). This borrows zero-copy when valid UTF-8 and safely replaces invalid byte sequences with replacement characters without ever panicking.
  • Added a unit test read_response_header_non_utf8 in pingora-core/src/protocols/http/v1/client.rs verifying that non-UTF-8 response headers (\xff) are processed safely by read_response_task().

Verification

  • cargo fmt --all -- --check passed cleanly.
  • cargo clippy -p pingora-core --lib passed with 0 warnings.
  • cargo test -p pingora-core --lib read_response_header_non_utf8 passed successfully.

Closes #1023

When an upstream backend returns response headers containing non-UTF-8
bytes (e.g. ISO-8859-1 encoding or binary residue), 'str::from_utf8().unwrap()'
in 'read_response_task' causes a panic.

Replace 'str::from_utf8(...).unwrap()' with 'String::from_utf8_lossy(...)'
so raw response header bytes are logged safely without risking process panics.

Closes cloudflare#1023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Title: Panic in trace! call due to unwrap() on non-UTF-8 bytes in protocols/http/v1/client.rs:818

1 participant