moonchen opened a new pull request, #13753:
URL: https://github.com/apache/trafficserver/pull/13753

   Fixes a crash, a leak and a needlessly slow brotli setting in 
stats_over_http. The gzip, deflate and br encoders copied the whole rendered 
body into a stack array of its size and compressed it into a second one, so on 
a host with several thousand metrics a compressed response overflowed the 
default 1 MiB thread stack and crashed Traffic Server. They now stream the body 
into newly allocated IOBuffer blocks. The br encoder also ignored the quality 
and window that the plugin configures and compressed at brotli's slowest 
setting; it now uses the configured encoder. Finally, the intercept released 
nothing when a request ended early, whether the transaction ended before the 
intercept connected or the client closed before or during the response, so each 
such request leaked its buffers, its connection and any compression state.
   
   Any client that asks for compressed statistics could crash a large host, and 
Prometheus asks for gzip on every scrape, so pointing a stock Prometheus at the 
plugin's Prometheus output was enough. The leak grew with each request that a 
client abandoned, such as a scrape that timed out.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to