• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

elixir-mint / mint / 65fe496e7fd9ea184ea38d0c87a8c7a35f4a0186
91%

Build:
DEFAULT BRANCH: main
Ran 27 Sep 2026 01:57PM UTC
Jobs 1
Files 22
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

27 Sep 2026 01:56PM UTC coverage: 89.56% (+0.1%) from 89.465%
65fe496e7fd9ea184ea38d0c87a8c7a35f4a0186

push

github

web-flow
Validate HTTP/2 DATA, padding, SETTINGS and extension frames (#512)

* Validate HTTP/2 DATA frames against flow control padding and message order

The flow-control accounting for a padded DATA frame counted the data
and the padding but not the Pad Length byte, while RFC 9113 6.1 says the
whole payload is flow controlled. The server's view of the receive
window drifted by one byte per padded frame, and once the drift passed
the WINDOW_UPDATE threshold the server saw an empty window that the
client never refilled.

A DATA frame arriving before the response HEADERS frame was delivered
as a :data response with no preceding :status. RFC 9113 8.1 defines a
response as HEADERS followed by DATA, and 8.1.1 makes a malformed
response a stream error, so the stream is now reset with PROTOCOL_ERROR
and the caller receives an error response.

* Validate HTTP/2 frame padding and SETTINGS before using them

A DATA, HEADERS or PUSH_PROMISE frame with the PADDED flag and an empty
payload has no Pad Length field and is a FRAME_SIZE_ERROR (RFC 9113 6.1),
a SETTINGS frame with the ACK flag and a payload is a FRAME_SIZE_ERROR
(RFC 9113 6.5), and SETTINGS_ENABLE_PUSH is only valid as 0 or 1 and must
not be set to 1 by a server (RFC 9113 6.5.2). All three used to be
accepted.

* Accept HTTP/2 PRIORITY frames on idle streams and reject extension frames in header blocks

PRIORITY frames on a client stream ID the client hadn't opened yet were
treated as a connection error, but RFC 9113 5.1 allows PRIORITY on idle
streams. They are now accepted.

Extension frames received in the middle of a header block were ignored
instead of being treated as the PROTOCOL_ERROR RFC 9113 5.5 requires.

38 of 39 new or added lines in 2 files covered. (97.44%)

1690 of 1887 relevant lines covered (89.56%)

659.45 hits per line

Uncovered Changes

Lines Coverage ∆ File
1
99.07
0.03% lib/mint/http2/frame.ex
Jobs
ID Job ID Ran Files Coverage
1 65fe496e7fd9ea184ea38d0c87a8c7a35f4a0186.1 27 Sep 2026 01:57PM UTC 22
89.56
GitHub Action Run
Source Files on build 65fe496e7fd9ea184ea38d0c87a8c7a35f4a0186
  • Tree
  • List 22
  • Changed 2
  • Source Changed 0
  • Coverage Changed 2
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 65fe496e on github
  • Prev Build on main (#F5FCED56...)
  • Next Build on main (#4D163E4B...)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc