>In HeaderDiff we chose to let the encoder decide how the buffer is managed
>(regarding additions and removals). These decisions are encoded on the wire
> and applied by the decoder on its own buffer. We think this choice has
> several advantages.

Has this been analysed from a denial-of-service perspective ?

Anything in the protocol where the client can cause memory allocation
on the server/proxy/whatever, should be scrutinized in a DoS perspective.

