MagicStack / MagicStack/httptools
[Bug] Request body lost when Upgrade: h2c + Transfer-Encoding: chunked is used
Chưa có ai nhận issue này.
- Ngôn ngữ chính
- Python
- Star
- 1.3k
- Fork
- 107
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
Overview
When sending a POST request from a Java RestClient (Spring Boot 3.2+, Java 21) to a FastAPI backend running on Uvicorn + httptools, we encountered a strange issue where the request body was missing.
The request looked like this:
POST /endpoint HTTP/1.1
Host: my-api.com
Upgrade: h2c
Connection: Upgrade, HTTP2-Settings
Transfer-Encoding: chunked
Content-Type: application/json
3\r\nabc\r\n0\r\n\r\n
On the server side, Uvicorn logs showed:
Unsupported upgrade requestNo request bodyInvalid HTTP request received
But when we routed the same request through ngrok or used RestTemplate instead of RestClient, it worked fine.
🔍 Root Cause
After analyzing Uvicorn’s httptools_impl.py and httptools parser behavior, we found this:
Upgrade: h2cis ignored by Uvicorn (as expected).- But internally,
httptoolsstill enters the upgrade state. - Since the upgrade is ignored and the parser is not reset, no body is parsed.
- This violates RFC 7230 §6.7, which allows the server to ignore upgrades and proceed normally.
Proposed Fix
Patch parser.pyx to resume HTTP/1.1 parsing after upgrade is ignored:
cdef int cb_on_headers_complete(cparser.llhttp_t* parser) except -1:
cdef HttpParser pyparser = <HttpParser>parser.data
try:
if parser.upgrade and not pyparser._should_upgrade():
cparser.llhttp_resume_after_upgrade(parser)
pyparser._on_headers_complete()
except BaseException as ex:
pyparser._last_error = ex
return -1
return 0
Also expose this from Python:
def resume_after_upgrade(self):
httptools.llhttp_resume_after_upgrade(self.cparser)
Then frameworks like Uvicorn can call it in:
def on_headers_complete(self):
if self.upgrade and self.upgrade.lower() != b"websocket":
self.parser.resume_after_upgrade()
Reproducible Test
def test_chunked_body_with_ignored_upgrade():
headers = {
"Upgrade": "h2c",
"Connection": "Upgrade",
"Transfer-Encoding": "chunked"
}
body = b"4\r\ntest\r\n0\r\n\r\n"
request = b"POST / HTTP/1.1\r\n" + headers_to_bytes(headers) + b"\r\n" + body
parser = HttpRequestParser(TestProtocol())
parser.feed_data(request)
assert protocol.body == b"test"
Why it matters
This is RFC-compliant behavior that should be supported.
RestClient in Java 21+ sends Upgrade: h2c by default.
Any server not resetting its parser state will lose the body.
This breaks many interop scenarios between Spring Boot and Python ASGI apps.
I'm happy to submit a PR if maintainers are open to it. Thanks for your time and for maintaining this great project!
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Hướng nghiên cứu
Callback của parser nằm trong parser.pyx; trước tiên hãy lần theo cb_on_headers_complete và phần xử lý upgrade hiện có, sau đó kiểm tra wrapper parser Python và bài kiểm thử parser có thể tái hiện. Tái hiện yêu cầu h2c được chia thành các chunk và xác minh rằng body vẫn được giữ lại sau một upgrade bị bỏ qua, với các bài kiểm thử parser liên quan đều vượt qua.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- python
- Lĩnh vực
- backend, networking
- Loại issue
- Lỗi
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 42/100