plugin/https: Add max_streams to limit HTTP/2 concurrent streams (#8522)

Add a max_streams option to the *https* plugin to limit the number of
concurrent HTTP/2 streams per DoH connection. This lets operators cap
per-connection concurrency (guarding against resource exhaustion) or
raise it above the Go default for high-fan-in clients that multiplex
many requests over a single connection.

Semantics match the existing *https3* plugin's max_streams:
- omitted  -> Go HTTP/2 server default is used
- 0        -> use the underlying HTTP/2 transport default
- positive -> advertise exactly that many concurrent streams
- negative -> rejected at config parse time

The limit is applied via the standard library http.Server.HTTP2
(HTTP2Config.MaxConcurrentStreams) so it is advertised in the server's
SETTINGS frame.

Signed-off-by: Mekias Yohannes <mmyohannes@gmail.com>
This commit is contained in:
myohannes
2026-09-06 22:16:44 -04:00
committed by GitHub
parent 558c9757a9
commit 2b8c305203
9 changed files with 392 additions and 3 deletions

View File

@@ -105,6 +105,19 @@ func TestPropagateConfigParamsMaxTCPQueries(t *testing.T) {
}
}
func TestPropagateConfigParamsMaxHTTPSStreams(t *testing.T) {
n := 7
first := &Config{MaxHTTPSStreams: &n}
first.firstConfigInBlock = first
second := &Config{firstConfigInBlock: first}
propagateConfigParams([]*Config{first, second})
if second.MaxHTTPSStreams == nil || *second.MaxHTTPSStreams != n {
t.Fatalf("expected MaxHTTPSStreams to propagate to second config as %d, got %v", n, second.MaxHTTPSStreams)
}
}
func TestPropagateConfigParamsAllowedOpcodes(t *testing.T) {
first := &Config{}
first.firstConfigInBlock = first