diff --git a/api/server/server.go b/api/server/server.go index 71dcb664c7..a1449555ec 100644 --- a/api/server/server.go +++ b/api/server/server.go @@ -6,6 +6,7 @@ import ( "net" "net/http" "strings" + "time" "github.com/docker/docker/api/server/httpstatus" "github.com/docker/docker/api/server/httputils" @@ -57,7 +58,8 @@ func (s *Server) Accept(addr string, listeners ...net.Listener) { for _, listener := range listeners { httpServer := &HTTPServer{ srv: &http.Server{ - Addr: addr, + Addr: addr, + ReadHeaderTimeout: 5 * time.Minute, // "G112: Potential Slowloris Attack (gosec)"; not a real concern for our use, so setting a long timeout. }, l: listener, } diff --git a/cmd/dockerd/metrics.go b/cmd/dockerd/metrics.go index 4ea8321b5d..a13a5d2670 100644 --- a/cmd/dockerd/metrics.go +++ b/cmd/dockerd/metrics.go @@ -4,6 +4,7 @@ import ( "net" "net/http" "strings" + "time" metrics "github.com/docker/go-metrics" "github.com/sirupsen/logrus" @@ -24,7 +25,11 @@ func startMetricsServer(addr string) error { mux.Handle("/metrics", metrics.Handler()) go func() { logrus.Infof("metrics API listening on %s", l.Addr()) - if err := http.Serve(l, mux); err != nil && !strings.Contains(err.Error(), "use of closed network connection") { + srv := &http.Server{ + Handler: mux, + ReadHeaderTimeout: 5 * time.Minute, // "G112: Potential Slowloris Attack (gosec)"; not a real concern for our use, so setting a long timeout. + } + if err := srv.Serve(l); err != nil && !strings.Contains(err.Error(), "use of closed network connection") { logrus.WithError(err).Error("error serving metrics API") } }() diff --git a/daemon/metrics_unix.go b/daemon/metrics_unix.go index 7869712541..6acc469c9c 100644 --- a/daemon/metrics_unix.go +++ b/daemon/metrics_unix.go @@ -8,6 +8,7 @@ import ( "net/http" "path/filepath" "strings" + "time" "github.com/docker/docker/pkg/plugingetter" "github.com/docker/docker/pkg/plugins" @@ -31,7 +32,11 @@ func (daemon *Daemon) listenMetricsSock() (string, error) { mux.Handle("/metrics", metrics.Handler()) go func() { logrus.Debugf("metrics API listening on %s", l.Addr()) - if err := http.Serve(l, mux); err != nil && !strings.Contains(err.Error(), "use of closed network connection") { + srv := &http.Server{ + Handler: mux, + ReadHeaderTimeout: 5 * time.Minute, // "G112: Potential Slowloris Attack (gosec)"; not a real concern for our use, so setting a long timeout. + } + if err := srv.Serve(l); err != nil && !strings.Contains(err.Error(), "use of closed network connection") { logrus.WithError(err).Error("error serving metrics API") } }()