• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

elixir-mint / mint / c7895cb022196c77ec35570c8e873a84393ff4b8
91%

Build:
DEFAULT BRANCH: main
Ran 28 Sep 2026 09:32AM UTC
Jobs 1
Files 22
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Sep 2026 09:31AM UTC coverage: 90.483% (+0.007%) from 90.476%
c7895cb022196c77ec35570c8e873a84393ff4b8

push

github

web-flow
Merge commit from fork

* Enforce the HTTP/2 max header list size on decoded response headers

The client's SETTINGS_MAX_HEADER_LIST_SIZE was only checked against the
compressed header block while CONTINUATION frames were accumulated. An
indexed field takes one byte on the wire and decodes to a full table
entry of up to 4 KB, and join_cookie_headers copies every cookie value
into a new binary, so a 64 KB block of indexed cookie fields made the
client allocate a 266 MB cookie value. At the default limit that is
about 1 GB per response.

RFC 9113 6.5.2 defines the limit on the uncompressed size, the sum of
the name and value sizes plus 32 bytes per field. A decoded response or
trailer list over the limit now resets the stream with PROTOCOL_ERROR
and the request fails with {:max_header_list_size_exceeded, size, max}.
A promised request over the limit refuses the promised stream. The
block is still decoded first so the HPACK table stays in sync.

* Test that cookie fields are measured before they're joined

Joining the cookie fields first would count them as one field and let a
header list past max_header_list_size through. Also correct the size
arithmetic in the decoded header list test's comment.

* Test indexed, informational and CONTINUATION header lists against the limit

Add tests for dynamic table references measured by their decoded size, an
informational response and a header block split over CONTINUATION frames.
Correct the cookie test's comment, which described the cookies as indexed,
and document that a server push with oversized promised request headers is
refused.

* Use a valid promised request in the push header list size test

The promise lacked :scheme, :authority and :path, so it was already reset
for being malformed and the test passed without the size check. Also split
the CONTINUATION test's block by bytes and don't store :status in the
dynamic table test.

15 of 16 new or added lines in 1 file covered. (93.75%)

3 existing lines in 1 file now uncovered.

1778 of 1965 relevant lines covered (90.48%)

696.52 hits per line

Uncovered Changes

Lines Coverage ∆ File
1
95.53
-0.06% lib/mint/http2.ex

Coverage Regressions

Lines Coverage ∆ File
3
95.53
-0.06% lib/mint/http2.ex
Jobs
ID Job ID Ran Files Coverage
1 c7895cb022196c77ec35570c8e873a84393ff4b8.1 28 Sep 2026 09:32AM UTC 22
90.48
GitHub Action Run
Source Files on build c7895cb022196c77ec35570c8e873a84393ff4b8
  • Tree
  • List 22
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • c7895cb0 on github
  • Prev Build on main (#BF2455FB...)
  • Next Build on main (#20252CA8...)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc