Skip to content

Validate HTTP/2 response semantics - #518

Merged
ericmj merged 2 commits into
mainfrom
http2-response-semantics
Sep 27, 2026
Merged

ericmj merged 2 commits into
mainfrom
http2-response-semantics

Conversation

@ericmj

@ericmj ericmj commented Sep 27, 2026

Copy link
Copy Markdown
Member

Two commits, meant to be rebase-merged rather than squashed.

  • A RST_STREAM with NO_ERROR on a stream Mint still tracks is now reported as {:error, ref, %Mint.HTTPError{reason: {:server_closed_request, :no_error}}} instead of {:done, ref}. Streams are removed once the server ends them with END_STREAM, so the response is incomplete at that point. A server that sends a complete response with END_STREAM followed by RST_STREAM NO_ERROR (RFC 9113 8.1) is unaffected.
  • Responses, interim responses and trailers with connection-specific headers (connection, keep-alive, proxy-connection, te, transfer-encoding, upgrade) are a stream error (RFC 9113 8.2.2). Previously they were delivered, or silently dropped from trailers.
  • :status 101 is a stream error (RFC 9113 8.6) instead of being delivered as an interim response, and :status values below 100 are rejected as in HTTP/1.

Streams are removed as soon as the server ends them with END_STREAM, so
a RST_STREAM frame on a stream still being tracked means the response
is incomplete. With the NO_ERROR code it was reported as {:done, ref},
both before any headers and in the middle of a body with a declared
content-length. It now produces {:server_closed_request, :no_error}.
…ed status codes

RFC 9113 8.2.2 makes a message containing connection, keep-alive,
proxy-connection, transfer-encoding or upgrade malformed, which is a
stream error. The te header is only allowed in requests, so it's
rejected in responses and trailers as well.

A :status of 101 is not supported in HTTP/2 (RFC 9113 8.6) and used to
be delivered as an interim response, and :status values below 100 were
accepted although HTTP/1 rejects them; both are now stream errors.
@coveralls

Copy link
Copy Markdown

Coverage Report for CI Build 5

Coverage increased (+0.09%) to 89.646%

Details

  • Coverage increased (+0.09%) from the base build.
  • Patch coverage: 10 of 10 lines across 1 file are fully covered (100%).
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 1893
Covered Lines: 1697
Line Coverage: 89.65%
Coverage Strength: 644.28 hits per line

💛 - Coveralls

@ericmj
ericmj marked this pull request as ready for review September 27, 2026 18:50
@ericmj
ericmj merged commit e159932 into main Sep 27, 2026
3 checks passed
@ericmj
ericmj deleted the http2-response-semantics branch September 27, 2026 19:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants