This repository was archived by the owner on Feb 16, 2026. It is now read-only.
h2: Add a rate limit facility for h/2 RST handling ("Rapid reset" mitigation)#3997
Merged
Conversation
|
Hi @daghf, i think default 3600 resets per minute is pretty generous while keeping varnish relatively safe. I tested that this limit keeps memory consumption at acceptable values during rapid reset attack. As you said, if the server is under attack, admins can restrict this to a lower value. |
Member
|
@TomasKorbar thank you for the early testing. Could you please test it in conjunction with #3998 ? |
|
@dridi sure. Give me some time please. |
daghf
force-pushed
the
h2_rst_allowance
branch
3 times, most recently
from
October 17, 2023 11:42
4d540b4 to
392a551
Compare
This adds parameters h2_rst_allowance and h2_rst_allowance_period, which govern the rate of which we allow clients to reset h/2 streams. If the limit is exceeded the connection is closed. Mitigates: varnishcache#3996
Only RST frames received earlier than this duration will be considered rapid.
daghf
force-pushed
the
h2_rst_allowance
branch
from
October 17, 2023 13:27
ea4d5d0 to
e5c5abf
Compare
nigoroll
approved these changes
Oct 17, 2023
This was referenced Oct 18, 2023
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This adds parameters
h2_rst_allowanceandh2_rst_allowance_period, which govern the rate of which we allow clients to reset h/2 streams.If the limit is exceeded the connection is closed.
The functionality is currently disabled by default (
h2_rst_allowance = 0). This is the kind of mitigation that will always need refinement, so it might be hard to come up with a one-size-fits-all kind of default here. It needs to be generous enough to not impact regular traffic, while at the same time low enough to meaningfully mitigate malicious clients. We may come up with some sort of generous number here, and give a recommendation for users to tune this down if under attack.Mitigates: #3996