D support in Thrift is covered by two sets of tests: first, the unit test blocks contained in the D source files, and second, the more extensive testing applications in the test/ subdirectory, which also make use of the Thrift compiler. Both are built when running “make check”, but only the unit tests are immediately run, however – the separate test cases typically run longer or require manual intervention. It might also be prudent to run the independent tests, which typically consist of a server and a client part, against the other language implementations.
To build the unit tests on Windows, the easiest way might be to manually create a file containing an empty main() and invoke the compiler by running the following in the src/ directory (PowerShell syntax):
dmd -ofunittest -unittest -w $(dir -r -filter ‘*.d’ -name)
Using SSL with async is experimental (always has been) and the unit test “async_test –ssl” hangs. Use at your own risk.
thrift.transport.http compares a header name in full instead of by prefix, so a name that merely begins with one the transport knows no longer counts as that name: “Content-Length-Foo” and “Content-LengthX” no longer set the content length, and “Transfer-Encoding-Foo” no longer switches on chunked decoding. A header name is the whole token before the colon (RFC 9110 5.1), and no whitespace is allowed between the two, so “Content-Length : 5” is no longer read as a content length either.
Content-Length is now read against RFC 9110 8.6’s 1*DIGIT, and a value that is not such a number is refused with a TTransportException. A sign, trailing text, or a value that does not fit size_t was previously either accepted silently – “5abc” gave 5, “0x10” gave 0 – or left the transport as a std.conv exception rather than a Thrift one.
thrift.transport.http reads at most maxBodySize bytes of message body, which defaults to the 16 MB frame size limit the Thrift libraries use elsewhere. The declared content length, and the number of chunks in a chunked body, are numbers the peer chooses, and the body does not pass through the line buffer that maxHttpBufferSize already bounds. A deployment that exchanges bodies larger than that has to raise the limit on the transport.
thrift.transport.framed refuses a frame whose declared size exceeds frameSizeLimit before it allocates the read buffer for the frame. frameSizeLimit defaults to the 16 MB frame size limit the Thrift libraries use elsewhere; the frame length is a number the peer chooses, so previously a peer could make the transport reserve an arbitrary amount of memory by announcing a large frame. A deployment that exchanges framed messages larger than the limit has to raise it on the transport; a value of zero or less disables the check, restoring the previous behaviour.
thrift.server.nonblocking.TNonblockingServer defaults maxFrameSize to the 16 MB frame size limit the Thrift libraries use elsewhere, where it used to default to 256 MiB; DEFAULT_MAX_FRAME_SIZE changes accordingly. The server closes the connection of a client that announces a larger frame, so a deployment that exchanges larger frames has to raise maxFrameSize on the server, and setting it to 256 * 1024 * 1024 restores the previous behaviour. Unlike frameSizeLimit on the framed transport, a maxFrameSize of zero does not disable the check.
thrift.internal.ssl.authorize() consults the certificate’s common name only when the certificate carries no DNS subjectAltName extension. Previously the common name was consulted whenever no subjectAltName entry had returned ALLOW, so a certificate whose subjectAltName named other hosts got a second chance from a common name that matched – TDefaultClientAccessManager.verify returns SKIP for a name that does not match, which made “names other hosts” and “names no hosts” the same state at the fallthrough. RFC 6125 6.4.4 and RFC 9525 6.3 make the subjectAltName the identity once it is present. A certificate affected needs reissuing with the host in its subjectAltName.
matchName(), which backs TDefaultClientAccessManager, no longer honours a wildcard outside the leftmost label, per RFC 6125 6.4.3. Patterns such as “thrift..”, “example..com” and “a.ev.com” used to match and no longer do. A wildcard in the leftmost label still covers at most one label, unchanged, so “*.apache.org” matches “thrift.apache.org” but not “foo.bar.apache.org”. Certificates affected need reissuing with the host in their subjectAltName, which is what every other TLS client already requires of them.
thrift.transport.ssl now floors the TLS negotiation at TLS 1.2 by default, where it previously accepted whatever the OpenSSL build allowed – TLS 1.0 on older builds. A peer that can only speak an earlier protocol version no longer connects.
thrift.protocol.binary, compact and json default containerSizeLimit and stringSizeLimit to the 16 MB frame size limit the Thrift libraries use elsewhere, where both used to default to zero. A limit of zero is read as “no limit”, so a protocol built with its default arguments previously accepted a string or container of whatever length the peer declared; a declared length over the limit is now refused with a TProtocolException. The old-format (non-strict) message name in TBinaryProtocol.readMessageBegin, which used to bypass the string limit, is bounded as well. A value of zero or less still means “no limit” for a caller that asks for it, so passing zero restores the previous behaviour.