Stop DateFormatter trailing token from running past the parse end - #16958
Merged
normanmaurer merged 2 commits intoJun 17, 2026
Merged
Conversation
Motivation: DateFormatter.parseHttpDate(txt, start, end) is documented to parse only the [start, end) substring, and its tokenizer loop correctly stops at end. But the trailing token (the one still open when the loop ends) was terminated at txt.length() instead of end. When end < txt.length() — e.g. a cookie "Expires" value that is followed by more attributes — and the date's last token is the one that completes the parse (RFC 6265 cookie-date tokens are order-independent, so the year or day may come last), the trailing token swallowed the bytes after end and failed to parse. Through ClientCookieDecoder this silently dropped the expiry and downgraded the cookie to a session cookie. Modification: Terminate the trailing token at end rather than txt.length(). Add a DateFormatterTest case parsing such a date as a substring. Result: parseHttpDate honours the end bound for the trailing token; valid order-independent cookie dates followed by other attributes parse correctly.
normanmaurer
approved these changes
Jun 16, 2026
bryce-anderson
approved these changes
Jun 16, 2026
Address review nit: the multi-line comments were verbose; collapse each to a single line.
Contributor
Author
|
Good call — collapsed both comments to one-liners in 434cbf4. Thanks @bryce-anderson! |
bryce-anderson
approved these changes
Jun 17, 2026
Contributor
|
Auto-port PR for 4.1: #16968 |
Contributor
|
Auto-port PR for 5.0: #16969 |
normanmaurer
pushed a commit
that referenced
this pull request
Jun 18, 2026
…e parse end (#16969) Auto-port of #16958 to 5.0 Cherry-picked commit: 692d23f --- ## Problem `DateFormatter.parseHttpDate(txt, start, end)` is documented to parse only the `[start, end)` substring. Its tokenizer loop correctly stops at `end`, but the **trailing token** — the one still open when the loop finishes — was terminated at `txt.length()` instead of `end`: ```java // terminate trailing token return tokenStart != -1 && parseToken(txt, tokenStart, txt.length()); ``` When `end < txt.length()` and the date's *last* token is the one that completes the parse, the trailing token swallows the bytes after `end` and fails to parse. This is reachable in practice through cookies. A `Set-Cookie` header like `foo=bar; Expires=<date>; Path=/` makes `ClientCookieDecoder` call `parseHttpDate(header, start, end)` with `end` pointing at the `;` before `Path`. RFC 6265 §5.1.1 cookie-date tokens are **order-independent**, so a valid date whose year (or day) is the last token — e.g. `Sun 08:49:37 06 Nov 1994` — parses fine in isolation but returns `null` as a substring, silently dropping the expiry and downgrading the cookie to a session cookie. Standard `Sun, 06 Nov 1994 08:49:37 GMT` ordering does not trigger it (the time token completes the parse mid-loop, before the trailing `GMT`), which is why existing tests miss it. ## Fix Terminate the trailing token at `end` rather than `txt.length()`. Since `end <= txt.length()` always, this only ever shrinks the trailing token to the intended bound; the full-string `parseHttpDate(txt)` path (where `end == txt.length()`) is unaffected. Added a `DateFormatterTest` case that parses such a date both in isolation and as a substring and asserts they agree. ## Result `parseHttpDate` honours the `end` bound for the trailing token; valid order-independent cookie dates followed by other attributes now parse correctly. Full `DateFormatterTest` (14) passes. Co-authored-by: Guimu <[email protected]>
normanmaurer
added a commit
that referenced
this pull request
Jun 18, 2026
…e parse end (#16968) Auto-port of #16958 to 4.1 Cherry-picked commit: 692d23f --- ## Problem `DateFormatter.parseHttpDate(txt, start, end)` is documented to parse only the `[start, end)` substring. Its tokenizer loop correctly stops at `end`, but the **trailing token** — the one still open when the loop finishes — was terminated at `txt.length()` instead of `end`: ```java // terminate trailing token return tokenStart != -1 && parseToken(txt, tokenStart, txt.length()); ``` When `end < txt.length()` and the date's *last* token is the one that completes the parse, the trailing token swallows the bytes after `end` and fails to parse. This is reachable in practice through cookies. A `Set-Cookie` header like `foo=bar; Expires=<date>; Path=/` makes `ClientCookieDecoder` call `parseHttpDate(header, start, end)` with `end` pointing at the `;` before `Path`. RFC 6265 §5.1.1 cookie-date tokens are **order-independent**, so a valid date whose year (or day) is the last token — e.g. `Sun 08:49:37 06 Nov 1994` — parses fine in isolation but returns `null` as a substring, silently dropping the expiry and downgrading the cookie to a session cookie. Standard `Sun, 06 Nov 1994 08:49:37 GMT` ordering does not trigger it (the time token completes the parse mid-loop, before the trailing `GMT`), which is why existing tests miss it. ## Fix Terminate the trailing token at `end` rather than `txt.length()`. Since `end <= txt.length()` always, this only ever shrinks the trailing token to the intended bound; the full-string `parseHttpDate(txt)` path (where `end == txt.length()`) is unaffected. Added a `DateFormatterTest` case that parses such a date both in isolation and as a substring and asserts they agree. ## Result `parseHttpDate` honours the `end` bound for the trailing token; valid order-independent cookie dates followed by other attributes now parse correctly. Full `DateFormatterTest` (14) passes. Co-authored-by: Guimu <[email protected]> Co-authored-by: Norman Maurer <[email protected]>
mergify Bot
added a commit
to ArcadeData/arcadedb
that referenced
this pull request
Jul 8, 2026
…l [skip ci] Bumps [io.netty:netty-all](https://github.com/netty/netty) from 4.2.15.Final to 4.2.16.Final. Release notes *Sourced from [io.netty:netty-all's releases](https://github.com/netty/netty/releases).* > netty-4.2.16.Final > ------------------ > > What's Changed > -------------- > > * Document Java 9 requirement for io\_uring by [`@jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904) > * Add BlockHound exception for DnsQueryIdSpace by [`@violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896) > * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901) > * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766) > * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808) > * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909) > * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910) > * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919) > * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905) > * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848) > * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739) > * Avoid logging exceptions that tests ignore by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891) > * Reject control characters at the boundary of HTTP method names by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723) > * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929) > * Try to fix/stabilize a number of flaky tests by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934) > * Fix propagation of startTls for client SslContext handlers by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931) > * Update to latest tcnative release by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936) > * Move test to shared testsuite by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928) > * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927) > * Make permessage-deflate server window size and memLevel configurable by [`@fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809) > * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950) > * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952) > * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951) > * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960) > * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932) > * Strictly validate MQTT UTF-8 Encoded String by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939) > * Stop DateFormatter trailing token from running past the parse end by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958) > * IpFilter: Deprecate constructor which use accept by default by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961) > * Add RFC 10008 QUERY Method support by [`@desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966) > * Correctly release and fail queued traffic-shaping writes on close by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959) > * Reject control characters at the boundary of the HTTP version token by [`@HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971) > * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949) > * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979) > * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982) > * Fix typo in AbstractSniHandler Javadoc by [`@coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988) > * Fix client/server inconsistency in SslCredential support matrix by [`@jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990) > * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947) > * Use Ticker in Http2MaxRstFrameListener for testability by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993) > * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991) > * FastLz: Guard decompression against truncated input by [`@yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000) > * Reject non-token characters in HTTP/2 header names by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762) > * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029) > * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027) > * Implement Adaptive Cumulator by [`@shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731) > * Allow WebSocket extension negotiation to be disabled per response by [`@mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030) > * Support QPACK sensitivity detector for Never Indexed header fields by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026) > * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037) > * Pin github actions to reduce risk by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043) ... (truncated) Commits * [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final * [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters * [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain * [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063)) * [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061)) * [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043)) * [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037)) * [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026)) * [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030)) * [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731)) * Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
mergify Bot
added a commit
to ArcadeData/arcadedb
that referenced
this pull request
Jul 8, 2026
…ip ci] Bumps `netty.version` from 4.2.15.Final to 4.2.16.Final. Updates `io.netty:netty-transport` from 4.2.15.Final to 4.2.16.Final Release notes *Sourced from [io.netty:netty-transport's releases](https://github.com/netty/netty/releases).* > netty-4.2.16.Final > ------------------ > > What's Changed > -------------- > > * Document Java 9 requirement for io\_uring by [`@jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904) > * Add BlockHound exception for DnsQueryIdSpace by [`@violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896) > * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901) > * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766) > * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808) > * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909) > * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910) > * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919) > * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905) > * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848) > * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739) > * Avoid logging exceptions that tests ignore by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891) > * Reject control characters at the boundary of HTTP method names by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723) > * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929) > * Try to fix/stabilize a number of flaky tests by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934) > * Fix propagation of startTls for client SslContext handlers by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931) > * Update to latest tcnative release by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936) > * Move test to shared testsuite by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928) > * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927) > * Make permessage-deflate server window size and memLevel configurable by [`@fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809) > * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950) > * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952) > * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951) > * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960) > * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932) > * Strictly validate MQTT UTF-8 Encoded String by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939) > * Stop DateFormatter trailing token from running past the parse end by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958) > * IpFilter: Deprecate constructor which use accept by default by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961) > * Add RFC 10008 QUERY Method support by [`@desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966) > * Correctly release and fail queued traffic-shaping writes on close by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959) > * Reject control characters at the boundary of the HTTP version token by [`@HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971) > * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949) > * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979) > * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982) > * Fix typo in AbstractSniHandler Javadoc by [`@coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988) > * Fix client/server inconsistency in SslCredential support matrix by [`@jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990) > * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947) > * Use Ticker in Http2MaxRstFrameListener for testability by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993) > * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991) > * FastLz: Guard decompression against truncated input by [`@yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000) > * Reject non-token characters in HTTP/2 header names by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762) > * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029) > * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027) > * Implement Adaptive Cumulator by [`@shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731) > * Allow WebSocket extension negotiation to be disabled per response by [`@mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030) > * Support QPACK sensitivity detector for Never Indexed header fields by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026) > * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037) > * Pin github actions to reduce risk by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043) ... (truncated) Commits * [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final * [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters * [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain * [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063)) * [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061)) * [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043)) * [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037)) * [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026)) * [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030)) * [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731)) * Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final) Updates `io.netty:netty-codec` from 4.2.15.Final to 4.2.16.Final Release notes *Sourced from [io.netty:netty-codec's releases](https://github.com/netty/netty/releases).* > netty-4.2.16.Final > ------------------ > > What's Changed > -------------- > > * Document Java 9 requirement for io\_uring by [`@jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904) > * Add BlockHound exception for DnsQueryIdSpace by [`@violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896) > * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901) > * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766) > * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808) > * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909) > * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910) > * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919) > * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905) > * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848) > * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739) > * Avoid logging exceptions that tests ignore by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891) > * Reject control characters at the boundary of HTTP method names by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723) > * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929) > * Try to fix/stabilize a number of flaky tests by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934) > * Fix propagation of startTls for client SslContext handlers by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931) > * Update to latest tcnative release by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936) > * Move test to shared testsuite by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928) > * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927) > * Make permessage-deflate server window size and memLevel configurable by [`@fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809) > * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950) > * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952) > * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951) > * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960) > * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932) > * Strictly validate MQTT UTF-8 Encoded String by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939) > * Stop DateFormatter trailing token from running past the parse end by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958) > * IpFilter: Deprecate constructor which use accept by default by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961) > * Add RFC 10008 QUERY Method support by [`@desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966) > * Correctly release and fail queued traffic-shaping writes on close by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959) > * Reject control characters at the boundary of the HTTP version token by [`@HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971) > * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949) > * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979) > * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982) > * Fix typo in AbstractSniHandler Javadoc by [`@coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988) > * Fix client/server inconsistency in SslCredential support matrix by [`@jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990) > * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947) > * Use Ticker in Http2MaxRstFrameListener for testability by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993) > * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991) > * FastLz: Guard decompression against truncated input by [`@yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000) > * Reject non-token characters in HTTP/2 header names by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762) > * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029) > * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027) > * Implement Adaptive Cumulator by [`@shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731) > * Allow WebSocket extension negotiation to be disabled per response by [`@mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030) > * Support QPACK sensitivity detector for Never Indexed header fields by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026) > * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037) > * Pin github actions to reduce risk by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043) ... (truncated) Commits * [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final * [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters * [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain * [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063)) * [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061)) * [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043)) * [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037)) * [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026)) * [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030)) * [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731)) * Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final) Updates `io.netty:netty-handler` from 4.2.15.Final to 4.2.16.Final Release notes *Sourced from [io.netty:netty-handler's releases](https://github.com/netty/netty/releases).* > netty-4.2.16.Final > ------------------ > > What's Changed > -------------- > > * Document Java 9 requirement for io\_uring by [`@jchambers`](https://github.com/jchambers) in [netty/netty#16904](https://redirect.github.com/netty/netty/pull/16904) > * Add BlockHound exception for DnsQueryIdSpace by [`@violetagg`](https://github.com/violetagg) in [netty/netty#16896](https://redirect.github.com/netty/netty/pull/16896) > * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16901](https://redirect.github.com/netty/netty/pull/16901) > * Add epoch-based chunk cache purge with ring buffer for thread-local reuse by [`@franz1981`](https://github.com/franz1981) in [netty/netty#16766](https://redirect.github.com/netty/netty/pull/16766) > * Use Splittable/ThreadLocalRandom to generate bulk data in tests by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16808](https://redirect.github.com/netty/netty/pull/16808) > * Auto-port 4.2: SingleThreadEventExecutor: document Throwable safety contract on run() by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16909](https://redirect.github.com/netty/netty/pull/16909) > * Auto-port 4.2: Make HTTP/2 frame hashCode consistent with equals by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16910](https://redirect.github.com/netty/netty/pull/16910) > * Auto-port 4.2: MQTT: Make the decodeProperties early-REPLAY check actually fire by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#16919](https://redirect.github.com/netty/netty/pull/16919) > * IoUring: fix io\_uring datagram writes with non-zero readerIndex by [`@dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16905](https://redirect.github.com/netty/netty/pull/16905) > * Exclude internal events from IoHandler.run() return value in epoll, io\_uring and kqueue by [`@franz1981`](https://github.com/franz1981) in [netty/netty#16848](https://redirect.github.com/netty/netty/pull/16848) > * IoUring: Pass IORING\_ENTER\_NO\_IOWAIT to report accurate CPU usage by [`@wineway`](https://github.com/wineway) in [netty/netty#16739](https://redirect.github.com/netty/netty/pull/16739) > * Avoid logging exceptions that tests ignore by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16891](https://redirect.github.com/netty/netty/pull/16891) > * Reject control characters at the boundary of HTTP method names by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16723](https://redirect.github.com/netty/netty/pull/16723) > * IoUring: fix TCP Fast Open initial writes with readerIndex and composites by [`@dreamlike-ocean`](https://github.com/dreamlike-ocean) in [netty/netty#16929](https://redirect.github.com/netty/netty/pull/16929) > * Try to fix/stabilize a number of flaky tests by [`@chrisvest`](https://github.com/chrisvest) in [netty/netty#16934](https://redirect.github.com/netty/netty/pull/16934) > * Fix propagation of startTls for client SslContext handlers by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16931](https://redirect.github.com/netty/netty/pull/16931) > * Update to latest tcnative release by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16936](https://redirect.github.com/netty/netty/pull/16936) > * Move test to shared testsuite by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16928](https://redirect.github.com/netty/netty/pull/16928) > * [Refactor] Useful helper method getOrDefault & cleaner abstraction by [`@sanjomo`](https://github.com/sanjomo) in [netty/netty#16927](https://redirect.github.com/netty/netty/pull/16927) > * Make permessage-deflate server window size and memLevel configurable by [`@fru1tworld`](https://github.com/fru1tworld) in [netty/netty#16809](https://redirect.github.com/netty/netty/pull/16809) > * Return early in DnsQueryContext.writeQuery when the query ID space is exhausted by [`@HwangRock`](https://github.com/HwangRock) in [netty/netty#16950](https://redirect.github.com/netty/netty/pull/16950) > * Fix HTTP 2 PUSH\_PROMISE stream association validation by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16952](https://redirect.github.com/netty/netty/pull/16952) > * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16951](https://redirect.github.com/netty/netty/pull/16951) > * Http3FrameCodec handle fragmented payloads when skipping unknown frames by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16960](https://redirect.github.com/netty/netty/pull/16960) > * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 by [`@hyperxpro`](https://github.com/hyperxpro) in [netty/netty#16932](https://redirect.github.com/netty/netty/pull/16932) > * Strictly validate MQTT UTF-8 Encoded String by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16939](https://redirect.github.com/netty/netty/pull/16939) > * Stop DateFormatter trailing token from running past the parse end by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16958](https://redirect.github.com/netty/netty/pull/16958) > * IpFilter: Deprecate constructor which use accept by default by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#16961](https://redirect.github.com/netty/netty/pull/16961) > * Add RFC 10008 QUERY Method support by [`@desiderantes`](https://github.com/desiderantes) in [netty/netty#16966](https://redirect.github.com/netty/netty/pull/16966) > * Correctly release and fail queued traffic-shaping writes on close by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16959](https://redirect.github.com/netty/netty/pull/16959) > * Reject control characters at the boundary of the HTTP version token by [`@HwangRock`](https://github.com/HwangRock) in [netty/netty#16971](https://redirect.github.com/netty/netty/pull/16971) > * FlowControlHandler: respect auto-read when toggled while dequeueing by [`@schiemon`](https://github.com/schiemon) in [netty/netty#16949](https://redirect.github.com/netty/netty/pull/16949) > * Fix leak in ReferenceCountedOpenSslEngine.addCredential by [`@jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16979](https://redirect.github.com/netty/netty/pull/16979) > * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout by [`@husseinvr97`](https://github.com/husseinvr97) in [netty/netty#16982](https://redirect.github.com/netty/netty/pull/16982) > * Fix typo in AbstractSniHandler Javadoc by [`@coderbruis`](https://github.com/coderbruis) in [netty/netty#16988](https://redirect.github.com/netty/netty/pull/16988) > * Fix client/server inconsistency in SslCredential support matrix by [`@jmcrawford45`](https://github.com/jmcrawford45) in [netty/netty#16990](https://redirect.github.com/netty/netty/pull/16990) > * Reconcile `AbstractCoalescingBufferQueue` readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames by [`@gavinbunney`](https://github.com/gavinbunney) in [netty/netty#16947](https://redirect.github.com/netty/netty/pull/16947) > * Use Ticker in Http2MaxRstFrameListener for testability by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#16993](https://redirect.github.com/netty/netty/pull/16993) > * Reset UTF-8 decode state on CR in StompSubframeDecoder by [`@vasiliy-mikhailov`](https://github.com/vasiliy-mikhailov) in [netty/netty#16991](https://redirect.github.com/netty/netty/pull/16991) > * FastLz: Guard decompression against truncated input by [`@yawkat`](https://github.com/yawkat) in [netty/netty#17000](https://redirect.github.com/netty/netty/pull/17000) > * Reject non-token characters in HTTP/2 header names by [`@daguimu`](https://github.com/daguimu) in [netty/netty#16762](https://redirect.github.com/netty/netty/pull/16762) > * Auto-port 4.2: Fix SelfSignCertificate initialization in tests by [`@netty-project-bot`](https://github.com/netty-project-bot) in [netty/netty#17029](https://redirect.github.com/netty/netty/pull/17029) > * Enable extension of Http3ClientConnectionHandler to support higher-level protocols such as WebTransport. by [`@sanjomo`](https://github.com/sanjomo) in [netty/netty#17027](https://redirect.github.com/netty/netty/pull/17027) > * Implement Adaptive Cumulator by [`@shivaspeaks`](https://github.com/shivaspeaks) in [netty/netty#16731](https://redirect.github.com/netty/netty/pull/16731) > * Allow WebSocket extension negotiation to be disabled per response by [`@mkurz`](https://github.com/mkurz) in [netty/netty#17030](https://redirect.github.com/netty/netty/pull/17030) > * Support QPACK sensitivity detector for Never Indexed header fields by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#17026](https://redirect.github.com/netty/netty/pull/17026) > * Fix maxAllocation for brotli-encoded content in HttpContentDecompressor by [`@skyguard1`](https://github.com/skyguard1) in [netty/netty#17037](https://redirect.github.com/netty/netty/pull/17037) > * Pin github actions to reduce risk by [`@normanmaurer`](https://github.com/normanmaurer) in [netty/netty#17043](https://redirect.github.com/netty/netty/pull/17043) ... (truncated) Commits * [`3703d79`](netty/netty@3703d79) [maven-release-plugin] prepare release netty-4.2.16.Final * [`63bbb2c`](netty/netty@63bbb2c) Update rust toolchain - add required parameters * [`ac06c1b`](netty/netty@ac06c1b) Update rust toolchain * [`5b68c61`](netty/netty@5b68c61) Merge branches from forks ([#17063](https://redirect.github.com/netty/netty/issues/17063)) * [`de5d276`](netty/netty@de5d276) Update lz4-java to 1.11.1 ([#17061](https://redirect.github.com/netty/netty/issues/17061)) * [`da22048`](netty/netty@da22048) Pin github actions to reduce risk ([#17043](https://redirect.github.com/netty/netty/issues/17043)) * [`0332676`](netty/netty@0332676) Fix maxAllocation for brotli-encoded content in HttpContentDecompressor ([#17037](https://redirect.github.com/netty/netty/issues/17037)) * [`7364401`](netty/netty@7364401) Support QPACK sensitivity detector for Never Indexed header fields ([#17026](https://redirect.github.com/netty/netty/issues/17026)) * [`06faf18`](netty/netty@06faf18) Allow WebSocket extension negotiation to be disabled per response ([#17030](https://redirect.github.com/netty/netty/issues/17030)) * [`bc4b983`](netty/netty@bc4b983) Implement Adaptive Cumulator ([#16731](https://redirect.github.com/netty/netty/issues/16731)) * Additional commits viewable in [compare view](netty/netty@netty-4.2.15.Final...netty-4.2.16.Final) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
DateFormatter.parseHttpDate(txt, start, end)is documented to parse only the[start, end)substring. Its tokenizer loop correctly stops atend, but the trailing token — the one still open when the loop finishes — was terminated attxt.length()instead ofend:When
end < txt.length()and the date's last token is the one that completes the parse, the trailing token swallows the bytes afterendand fails to parse.This is reachable in practice through cookies. A
Set-Cookieheader likefoo=bar; Expires=<date>; Path=/makesClientCookieDecodercallparseHttpDate(header, start, end)withendpointing at the;beforePath. RFC 6265 §5.1.1 cookie-date tokens are order-independent, so a valid date whose year (or day) is the last token — e.g.Sun 08:49:37 06 Nov 1994— parses fine in isolation but returnsnullas a substring, silently dropping the expiry and downgrading the cookie to a session cookie.Standard
Sun, 06 Nov 1994 08:49:37 GMTordering does not trigger it (the time token completes the parse mid-loop, before the trailingGMT), which is why existing tests miss it.Fix
Terminate the trailing token at
endrather thantxt.length(). Sinceend <= txt.length()always, this only ever shrinks the trailing token to the intended bound; the full-stringparseHttpDate(txt)path (whereend == txt.length()) is unaffected.Added a
DateFormatterTestcase that parses such a date both in isolation and as a substring and asserts they agree.Result
parseHttpDatehonours theendbound for the trailing token; valid order-independent cookie dates followed by other attributes now parse correctly. FullDateFormatterTest(14) passes.