|
31 | 31 | import java.util.concurrent.CountDownLatch; |
32 | 32 | import java.util.concurrent.TimeUnit; |
33 | 33 | import java.util.concurrent.atomic.AtomicReference; |
| 34 | +import org.junit.jupiter.api.Test; |
34 | 35 | import org.junit.jupiter.params.ParameterizedTest; |
35 | 36 | import org.junit.jupiter.params.provider.ValueSource; |
36 | 37 |
|
@@ -92,6 +93,130 @@ private void doEnforceInboundFrameMax(int frameMax, int openOkPayloadSize, boole |
92 | 93 | } |
93 | 94 | } |
94 | 95 |
|
| 96 | + // A negotiated frame_max of 0 means "no limit" (client requests 0, the default, and the |
| 97 | + // broker also declares 0). The configured message body cap must still be enforced in that |
| 98 | + // case, instead of being silently discarded in favor of an effectively unbounded frame size. |
| 99 | + @ParameterizedTest |
| 100 | + @ValueSource(ints = {8192, 10_000}) |
| 101 | + void bodySizeCapShouldPassWhenEqualToLimitAndNegotiatedFrameMaxIsUnlimited( |
| 102 | + int maxInboundMessageBodySize) throws Exception { |
| 103 | + int openOkPayloadSize = maxInboundMessageBodySize - AMQCommand.EMPTY_FRAME_SIZE; |
| 104 | + doEnforceInboundFrameMaxWithUnlimitedNegotiatedFrameMax( |
| 105 | + maxInboundMessageBodySize, openOkPayloadSize, false); |
| 106 | + } |
| 107 | + |
| 108 | + @ParameterizedTest |
| 109 | + @ValueSource(ints = {8192, 10_000}) |
| 110 | + void bodySizeCapShouldNotPassWhenAboveLimitAndNegotiatedFrameMaxIsUnlimited( |
| 111 | + int maxInboundMessageBodySize) throws Exception { |
| 112 | + int openOkPayloadSize = maxInboundMessageBodySize - AMQCommand.EMPTY_FRAME_SIZE + 1; |
| 113 | + doEnforceInboundFrameMaxWithUnlimitedNegotiatedFrameMax( |
| 114 | + maxInboundMessageBodySize, openOkPayloadSize, true); |
| 115 | + } |
| 116 | + |
| 117 | + private void doEnforceInboundFrameMaxWithUnlimitedNegotiatedFrameMax( |
| 118 | + int maxInboundMessageBodySize, int openOkPayloadSize, boolean shouldFail) throws Exception { |
| 119 | + |
| 120 | + CountDownLatch serverDone = new CountDownLatch(1); |
| 121 | + AtomicReference<Throwable> serverError = new AtomicReference<>(); |
| 122 | + |
| 123 | + try (ServerSocket server = new ServerSocket(0, 1, InetAddress.getByName("127.0.0.1"))) { |
| 124 | + int port = server.getLocalPort(); |
| 125 | + // frame_max of 0 in connection.tune means "no limit" |
| 126 | + Thread peer = |
| 127 | + new Thread( |
| 128 | + () -> runFakeBroker(server, serverDone, serverError, 0, openOkPayloadSize), |
| 129 | + "fake-amqp-broker"); |
| 130 | + peer.setDaemon(true); |
| 131 | + peer.start(); |
| 132 | + |
| 133 | + ConnectionFactory factory = TestUtils.connectionFactory(); |
| 134 | + factory.setHost("127.0.0.1"); |
| 135 | + factory.setPort(port); |
| 136 | + // requested frame max of 0 (the client default) is what allows the negotiated |
| 137 | + // frame_max to come out to 0 when the broker also declares 0 |
| 138 | + factory.setRequestedFrameMax(0); |
| 139 | + factory.setMaxInboundMessageBodySize(maxInboundMessageBodySize); |
| 140 | + factory.setHandshakeTimeout(5000); |
| 141 | + factory.setConnectionTimeout(5000); |
| 142 | + factory.setRequestedHeartbeat(0); |
| 143 | + |
| 144 | + if (shouldFail) { |
| 145 | + assertThatThrownBy(() -> factory.newConnection()).isInstanceOf(IOException.class); |
| 146 | + } else { |
| 147 | + try (Connection connection = factory.newConnection()) { |
| 148 | + assertThat(connection.getFrameMax()).isEqualTo(0); |
| 149 | + } |
| 150 | + } |
| 151 | + } |
| 152 | + assertThat(serverDone.await(5, TimeUnit.SECONDS)).isTrue(); |
| 153 | + if (!shouldFail) { |
| 154 | + assertThat(serverError.get()).isNull(); |
| 155 | + } |
| 156 | + } |
| 157 | + |
| 158 | + // connection.tune's frame_max is parsed as a signed 32-bit value; a broker (or a |
| 159 | + // misconfigured client requesting a nonzero frame max) can drive the negotiated value |
| 160 | + // negative, which must be rejected rather than silently accepted as a bogus limit. |
| 161 | + @Test |
| 162 | + void negativeNegotiatedFrameMaxShouldBeRejected() throws Exception { |
| 163 | + CountDownLatch serverDone = new CountDownLatch(1); |
| 164 | + AtomicReference<Throwable> serverError = new AtomicReference<>(); |
| 165 | + |
| 166 | + try (ServerSocket server = new ServerSocket(0, 1, InetAddress.getByName("127.0.0.1"))) { |
| 167 | + int port = server.getLocalPort(); |
| 168 | + Thread peer = |
| 169 | + new Thread( |
| 170 | + () -> runFakeBrokerWithNegativeFrameMax(server, serverDone, serverError), |
| 171 | + "fake-amqp-broker"); |
| 172 | + peer.setDaemon(true); |
| 173 | + peer.start(); |
| 174 | + |
| 175 | + ConnectionFactory factory = TestUtils.connectionFactory(); |
| 176 | + factory.setHost("127.0.0.1"); |
| 177 | + factory.setPort(port); |
| 178 | + // a nonzero requested frame max is needed for negotiatedMaxValue to take the |
| 179 | + // Math.min(positive, negative) branch, instead of laundering the broker's negative |
| 180 | + // value into 0 ("no limit") the way it would if the client requested 0 |
| 181 | + factory.setRequestedFrameMax(131_072); |
| 182 | + factory.setAutomaticRecoveryEnabled(false); |
| 183 | + factory.setHandshakeTimeout(5000); |
| 184 | + factory.setConnectionTimeout(5000); |
| 185 | + factory.setRequestedHeartbeat(0); |
| 186 | + |
| 187 | + // asserting on the message, not just the type, matters here: on the Netty transport, |
| 188 | + // an unguarded negative frame max reaches Netty's frame decoder and trips its own |
| 189 | + // IllegalArgumentException ("maxFrameLength ... expected: > 0") for an unrelated |
| 190 | + // reason, which would otherwise make this test pass without the fix in place |
| 191 | + assertThatThrownBy(() -> factory.newConnection()) |
| 192 | + .isInstanceOf(IllegalArgumentException.class) |
| 193 | + .hasMessageContaining("Negotiated frame max cannot be negative"); |
| 194 | + } |
| 195 | + assertThat(serverDone.await(5, TimeUnit.SECONDS)).isTrue(); |
| 196 | + assertThat(serverError.get()).isNull(); |
| 197 | + } |
| 198 | + |
| 199 | + private static void runFakeBrokerWithNegativeFrameMax( |
| 200 | + ServerSocket server, CountDownLatch done, AtomicReference<Throwable> error) { |
| 201 | + try (Socket socket = server.accept()) { |
| 202 | + socket.setSoTimeout(5000); |
| 203 | + DataInputStream in = new DataInputStream(socket.getInputStream()); |
| 204 | + DataOutputStream out = new DataOutputStream(socket.getOutputStream()); |
| 205 | + |
| 206 | + byte[] header = new byte[8]; |
| 207 | + in.readFully(header); |
| 208 | + writeMethodFrame(out, startPayload()); |
| 209 | + readFrame(in); |
| 210 | + writeMethodFrame(out, tunePayload(-1)); |
| 211 | + // the client must reject the negotiated frame max before replying, so no further |
| 212 | + // frames are expected |
| 213 | + } catch (Throwable t) { |
| 214 | + error.set(t); |
| 215 | + } finally { |
| 216 | + done.countDown(); |
| 217 | + } |
| 218 | + } |
| 219 | + |
95 | 220 | private static void runFakeBroker( |
96 | 221 | ServerSocket server, |
97 | 222 | CountDownLatch done, |
|
0 commit comments