Protocol handlers, sockets và HTTP correctness
Connector là boundary giữa network và container; timeout, keep-alive, parsing limit và socket capacity vừa là performance controls vừa là security controls.
Coyote
Protocol handlers
HTTP/1.1 NIO là lựa chọn phổ biến; NIO2 dùng asynchronous channel APIs. HTTP/2 được cấu hình qua UpgradeProtocol và multiplex streams trên connection nhưng request work vẫn tiêu executor/downstream resources. APR/native history không nên áp vào version hiện tại mà không đọc documentation tương ứng.
Connection lifecycle
Acceptor nhận connection, Poller theo dõi readiness, processor parse/serialize protocol và executor chạy container work. Keep-alive giảm handshake nhưng giữ connection state. maxConnections, acceptCount và kernel queues là các layer khác nhau.
Parser và limits
Header count/size, request line, body/swallow behavior, upload timeout và relaxed characters ảnh hưởng interoperability và request-smuggling/DoS surface. Chỉ nới limit theo contract đo được; proxy và Tomcat phải thống nhất cách parse.
Timeout model
Connection, keep-alive, upload, async và application/downstream timeouts không thay thế nhau. Deadline nên giảm dần qua call chain; timeout mà không cancel work có thể biến request timeout thành background overload.