Go to file
Norman Maurer 7003dbdc08
HTTP2: Guard against empty DATA frames (without end_of_stream flag) set (#9461)
Motivation:

It is possible for a remote peer to flood the server / client with empty DATA frames (without end_of_stream flag) set and so cause high CPU usage without the possibility to ever hit a limit. We need to guard against this.

See CVE-2019-9518

Modifications:

- Add a new config option to AbstractHttp2ConnectionBuilder and sub-classes which allows to set the max number of consecutive empty DATA frames (without end_of_stream flag). After this limit is hit we will close the connection. A limit of 10 is used by default.
- Add unit tests

Result:

Guards against CVE-2019-9518
2019-08-13 19:07:10 +02:00
.github Change the netty.io homepage scheme(http -> https) (#9344) 2019-07-09 21:09:42 +02:00
.mvn support publishing snapshots from docker based ci (#8634) 2018-12-07 05:43:06 +01:00
all [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
bom [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
buffer Use alloc().heapBuffer(...) to allocate new heap buffer. 2019-08-13 10:52:11 +02:00
codec [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
codec-dns [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
codec-haproxy [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
codec-http Set the ORIGIN header from a custom headers if present (#9435) 2019-08-11 08:22:17 +02:00
codec-http2 HTTP2: Guard against empty DATA frames (without end_of_stream flag) set (#9461) 2019-08-13 19:07:10 +02:00
codec-memcache [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
codec-mqtt [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
codec-redis [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
codec-smtp [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
codec-socks [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
codec-stomp [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
codec-xml [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
common Try to load native linux libraries with matching classifier first (#9411) 2019-08-12 08:37:27 +02:00
dev-tools [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
docker Use delegated docker mount option to speedup builds (#9441) 2019-08-13 10:27:21 +02:00
example [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
handler Always wrap X509ExtendedTrustManager when using OpenSSL and JDK < 11 (#9443) 2019-08-13 10:26:13 +02:00
handler-proxy [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
license Use Table lookup for HPACK decoder (#9307) 2019-07-02 20:09:44 +02:00
microbench [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
resolver [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
resolver-dns [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
tarball [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
testsuite [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
testsuite-autobahn [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
testsuite-http2 [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
testsuite-native-image [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
testsuite-osgi [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
testsuite-shading [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
transport #7285 Improved "Discarded inbound message" warning for embedded channel (#9414) 2019-08-03 12:20:41 +02:00
transport-native-epoll Do not cache local/remote address when creating EpollDatagramChannel with InternetProtocolFamily (#9436) 2019-08-11 08:42:58 +02:00
transport-native-kqueue Fix native-build/target/lib wanted but build in native-build/target/lib64 (#9410) 2019-08-07 09:56:28 +02:00
transport-native-unix-common [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
transport-native-unix-common-tests [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
transport-rxtx [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
transport-sctp [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
transport-udt [maven-release-plugin] prepare for next development iteration 2019-07-24 09:05:57 +00:00
.fbprefs Updated Find Bugs configuration 2009-03-04 10:33:09 +00:00
.gitattributes Include mvn wrapper to make setup of development env easier 2018-01-26 08:13:17 +01:00
.gitignore Add .gitignore for docker-sync stuff 2019-03-19 14:03:15 +01:00
CONTRIBUTING.md Change the netty.io homepage scheme(http -> https) (#9344) 2019-07-09 21:09:42 +02:00
LICENSE.txt Relicensed to Apache License v2 2009-08-28 07:15:49 +00:00
mvnw Include mvn wrapper to make setup of development env easier 2018-01-26 08:13:17 +01:00
mvnw.cmd Include mvn wrapper to make setup of development env easier 2018-01-26 08:13:17 +01:00
NOTICE.txt Change the netty.io homepage scheme(http -> https) (#9344) 2019-07-09 21:09:42 +02:00
pom.xml Try to load native linux libraries with matching classifier first (#9411) 2019-08-12 08:37:27 +02:00
README.md Change the netty.io homepage scheme(http -> https) (#9344) 2019-07-09 21:09:42 +02:00
run-example.sh Add UptimeServer and adjust UptimeClient's code style. 2017-04-28 07:41:07 +02:00

Netty Project

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients.

How to build

For the detailed information about building and developing Netty, please visit the developer guide. This page only gives very basic information.

You require the following to build Netty:

Note that this is build-time requirement. JDK 5 (for 3.x) or 6 (for 4.0+) is enough to run your Netty-based application.

Branches to look

Development of all versions takes place in each branch whose name is identical to <majorVersion>.<minorVersion>. For example, the development of 3.9 and 4.0 resides in the branch '3.9' and the branch '4.0' respectively.

Usage with JDK 9

Netty can be used in modular JDK9 applications as a collection of automatic modules. The module names follow the reverse-DNS style, and are derived from subproject names rather than root packages due to historical reasons. They are listed below:

  • io.netty.all
  • io.netty.buffer
  • io.netty.codec
  • io.netty.codec.dns
  • io.netty.codec.haproxy
  • io.netty.codec.http
  • io.netty.codec.http2
  • io.netty.codec.memcache
  • io.netty.codec.mqtt
  • io.netty.codec.redis
  • io.netty.codec.smtp
  • io.netty.codec.socks
  • io.netty.codec.stomp
  • io.netty.codec.xml
  • io.netty.common
  • io.netty.handler
  • io.netty.handler.proxy
  • io.netty.resolver
  • io.netty.resolver.dns
  • io.netty.transport
  • io.netty.transport.epoll (native omitted - reserved keyword in Java)
  • io.netty.transport.kqueue (native omitted - reserved keyword in Java)
  • io.netty.transport.unix.common (native omitted - reserved keyword in Java)
  • io.netty.transport.rxtx
  • io.netty.transport.sctp
  • io.netty.transport.udt

Automatic modules do not provide any means to declare dependencies, so you need to list each used module separately in your module-info file.