Repository navigation
Shared SSLContext can race between HTTP/1.1 and HTTP/2 connections via ALPN mutation #1123
Unanswered
MaciejZet
asked this question in
Potential Issue
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Summary
The current
mastermutates a caller-providedssl.SSLContextinHTTPConnection._connect():When two concurrent connections share the same context, one configured with
http2=Falseand one withhttp2=True, the ALPN configuration can race.Reproduction
Using current master at
10a658221deb38a4c5b16db55ab554b0bf731707, a deterministicfake network backend synchronizes both
start_tls()calls.Observed:
The HTTP/1.1 connection receives the ALPN list written by the concurrent HTTP/2
connection.
The same behavior reproduces in:
Expected behavior
One connection should not change the TLS protocol configuration observed by
another connection merely because they share a caller-provided
SSLContext.Question
Is sharing a caller-provided
SSLContextbetween connections with differenthttp2settings supported? If so, should httpcore isolate the ALPN configurationper connection instead of mutating the shared context?
All reactions