Skip to content

Fail unprocessed local streams on GOAWAY - #711

Merged
ok2c merged 1 commit into
apache:masterfrom
rp-arielrodriguez:h2-goaway-received-streams
Sep 30, 2026
Merged

ok2c merged 1 commit into
apache:masterfrom
rp-arielrodriguez:h2-goaway-received-streams

Conversation

@rp-arielrodriguez

@rp-arielrodriguez rp-arielrodriguez commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

We found this with HTTP/2 multiplexing in HttpClient 5: when the server sent
GOAWAY(NO_ERROR) during a restart, requests on the same connection that the
server did not process were not failed. They waited until the server closed
the connection.

On GOAWAY(NO_ERROR), AbstractH2StreamMultiplexer must fail the local streams
with an id greater than Last-Stream-ID with RequestNotExecutedException
(RFC 9113, section 6.8). The check used !streams.isSameSide(...), so it
selected streams initiated by the peer instead.

Fix: drop the negation (one line).

Measured with an end-to-end test (real client, raw-frame server that sends
GOAWAY last-stream-id=1 with stream 3 in flight and closes the connection 3s
later):

Stream 3 (not processed) Result
master ConnectionClosedException after ~3.2s (at connection close)
with fix RequestNotExecutedException immediately

Stream 1 completes normally in both cases. I did not include that test, to keep
the change small; I can add it if you want it.

The same line is on 5.4.x, so the fix applies there as is.

Tests:

  • New: testGoAwayNoErrorFailsUnprocessedLocalStreamsOnly: local stream 3 fails,
    local stream 1 and remote stream 2 do not (fails on master, passes with the fix).
  • Changed: testGoAwayReservedBitInLastStreamIdAffectsStreamCulling used remote
    streams, so it depended on the inverted check. It now uses local streams and
    still checks that the reserved bit is masked.
  • ./mvnw -pl httpcore5-h2,httpcore5-testing -am test: all pass (httpcore5-h2
    387, httpcore5-testing 443 with 4 skipped). Checkstyle and RAT pass.

I used an AI assistant (Claude Code) for this change. I reviewed all of it and
I can answer questions about it.

@rp-arielrodriguez
rp-arielrodriguez force-pushed the h2-goaway-received-streams branch from 6c4a091 to 868347d Compare September 29, 2026 22:50
On GOAWAY(NO_ERROR), streams initiated by this endpoint with an id
greater than Last-Stream-ID were not processed by the peer and must
fail with RequestNotExecutedException (RFC 9113, section 6.8).

The check used !isSameSide, so it selected streams initiated by the
peer instead. Unprocessed local requests stayed active until the
connection was closed and then failed with ConnectionClosedException.
@rp-arielrodriguez
rp-arielrodriguez force-pushed the h2-goaway-received-streams branch from 868347d to 8c7dc59 Compare September 30, 2026 13:16
@ok2c
ok2c merged commit 7f2c8a3 into apache:master Sep 30, 2026
12 checks passed
@ok2c

ok2c commented Sep 30, 2026

Copy link
Copy Markdown
Member

@rp-arielrodriguez Cherry-picked to 5.4.x though I had to port the tests manually. Please double-check.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants