Commit Graph
47 Commits
Author SHA1 Message Date
ldm0 c3c01f20ea refactor(curl): use owned byte header lists from curl-rust 2026-09-21 04:26:40 +08:00
ldm0 fbfc213d82 fix(network): scope CDP header overrides and preserve BiDi byte values
Restore original headers on redirect while preserving current-hop overrides
for authentication retries and keeping Network event identity intact.

Preserve raw BiDi Cookie, Set-Cookie, and extra header values through page,
navigation, and worker policies. Apply CDP's last-value behavior for duplicate
request header names.

Add coverage for header bytes, redirects, authentication, and event sequences.
2026-09-21 03:58:53 +08:00
ldm0 932a7225ac refactor(network): preserve request header bytes across interception
Carry RequestHeaders through navigation, Fetch/XHR, workers, redirects and auth,
with explicit Unicode and ByteString conversions at protocol and WebIDL boundaries.
Share the raw curl header list with WebSocket transport and decode binary response
headers without UTF-8 replacement. Keep header memory charging concrete.

Cover opaque values, UTF-8 overrides, duplicates, redirect/auth continuation and
WebSocket handshakes with byte-level regression tests.
2026-09-21 03:54:12 +08:00
ldm0 04302d49fb fix(cors): parse Content-Type parameters without rejecting commas
Extracted from b57d75e801791c4d9b6d682f2aae254d3acd3c53.

Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings. Runtime tests were not run for this split.
2026-09-20 18:03:07 +08:00
ldm0 4ed30be874 fix(fetch): distinguish request header bytes from UTF-8 strings 2026-09-20 14:03:33 +08:00
ldm0 ba11283d57 fix(fetch): preserve HTTP header bytes across the transport
Extracted from f25578c2a9c188d3437e88f337ebaae9da49a246.

Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings. Runtime tests were not run for this split.
2026-09-20 14:03:33 +08:00
ldm0 493d50e8cf fix: align no-proxy port and wildcard matching with curl 2026-09-18 14:13:58 +08:00
ldm0 90c0ede829 fix: verify HTTPS proxy connections 2026-09-18 14:13:58 +08:00
ldm0 7184290d9f fix: match Chromium SOCKS proxy semantics 2026-09-18 14:13:58 +08:00
ldm0 ad0599b6a9 fix: pin proxy endpoint resolution 2026-09-18 14:13:58 +08:00
ldm0 86d0f1c5c4 refactor: generalize shared DNS endpoints 2026-09-18 14:13:58 +08:00
ldm0 5417fe675e refactor: share proxy route selection 2026-09-18 14:13:58 +08:00
ldm0 fbb6e06874 fix: reject prefixed host resolve syntax 2026-09-18 14:13:58 +08:00
ldm0 6aff3c598f refactor: clarify shared DNS resolution state 2026-09-18 14:13:58 +08:00
ldm0 d0f4ec8a3e refactor: drop redundant curl DNS cache timeout 2026-09-18 14:13:58 +08:00
ldm0 0abe983cc1 fix: unify HTTP proxy route selection 2026-09-18 14:13:58 +08:00
ldm0 fcc7168925 fix: prevent DNS rebinding in network policy 2026-09-18 14:13:58 +08:00
ldm0 a4fd2b9701 fix(fetch): send zero content length for bodyless PUT requests
Configure an empty upload for a bodyless PUT and suppress libcurl’s implicit Content-Type on that path. Recompute framing across redirects, retaining PUT for 301/302/307/308 and dropping the body headers when 303 changes it to GET.

Source: f84c99d671
2026-09-16 15:39:45 +08:00
ldm0 312b0ffc6b feat(emulation): support worker user agent overrides 2026-09-15 16:54:51 +08:00
ldm0 c0a87c6960 fix(fetch): preserve committed origins for document subresources 2026-09-14 06:48:28 +08:00
ldm0 8630dea13b perf(fetch): avoid copying response bytes for module consumers
Use byte-only decomposition for Response and NavigationResponse instead of
discarding the text returned by into_parts(). Module, dedicated worker, and
service worker consumers now transfer the existing exact byte allocation.

Verify storage transfer for UTF-8 and non-UTF-8 payloads.

Source: e32030e484
2026-09-14 06:45:16 +08:00
ldm0 53f790c13a fix(fetch): require browser origins and unify SW request state
Keep request origin independent of URL resolution and referrer context,
including local blob fetches and inherited or sandboxed srcdoc documents.
Reject missing browser origins at the resource client boundary and retain
one Request across Service Worker redirects and network fallback.

Cover dispatch rejection, wire Origin/Cookie headers, memory-cache
partitioning and preserved Service Worker request metadata.

Validation: workspace fmt and Clippy passed; Nextest passed 17,517 tests
with 13 existing skips. Renderer test debug symbols were disabled to fit
available build memory; tests and debug assertions were unchanged.
2026-09-13 16:14:50 +08:00
ldm0 77783ece9d fix(fetch): enforce request modes and CORS before redirects 2026-09-13 16:14:50 +08:00
ldm0 4a1e6fd196 fix(fetch): unify script headers and CORS response validation
Generate Origin independently of browser destination metadata, and attach script
metadata at classic, module, and preload request builders. Share redirect URL-list
rules across request generation and response validation, and remove final-only
CORS validation from manifests, stylesheets, and request interception.

Reject failed CORS checks even without supported integrity metadata. Preserve CSP
reporting before dynamic script fetches and use committed Window origins for
srcdoc and sandboxed child script/module requests.

Add wire-level Origin, Cookie, and Fetch Metadata regressions, plus manifest,
stylesheet CSSOM, CSP, and child module/preload coverage.
2026-09-13 04:46:51 +08:00
ldm0 b63197ff8a fix(fetch): retain redirect state across service worker fallback
Keep redirect history in Request so Service Worker handoffs, network
redirects, preflights, Origin serialization, cookies, and TLS credentials
share the same state. Avoid reusing another request's response URL list
from the renderer memory cache.

Validate and filter network responses using their full history while
preserving readable Service Worker response filters across streaming and
buffered delivery. Returning to the initiating origin keeps network CORS
tainting; worker-produced responses retain their own filtering.

Add wire-header, credentials, cache, and worker response regressions, and
correct the local Fetch/XHR redirect fixtures to authorize and expose CORS
responses after a cross-origin round trip.
2026-09-13 04:46:51 +08:00
ldm0 c1412b76b9 fix(fetch): preserve redirect response provenance
Distinguish network, service worker, and browser-internal redirects so synthetic responses are not subjected to network CORS checks. Preserve every hop for redirect taint and Origin validation, including across navigation response conversions.

Add seven cross-origin service worker script scenarios and guard CORS checks for cached network redirects without ExtraInfo. The new integration regression fails before the fix and passes afterward.

Validated with cargo fmt --all, workspace Clippy across all targets and features with warnings denied, and cargo nextest run --no-fail-fast: 17459 passed, 13 skipped. Used one build job for the full test run after a parallel-build rustc process was killed.
2026-09-13 04:46:51 +08:00
ldm0 4b3b8993bb refactor(curl): share HTTP and WebSocket connection limits
Remove the separate WebSocket CURLSH connection cache so HTTP/1, HTTP/2 and WebSocket sockets compete for the existing host and total limits. Retain bounded session admission and message memory limits.

Pin the curl fork's connect-only eviction fix so quiet upgraded sockets remain owned until their connections close. Cover queueing, deadlines, cancellation, shutdown and HTTP/2 multiplexing under a full shared connection budget.
2026-09-11 01:47:10 +08:00
ldm0 4e63c1e8c6 test(curl): cover shared HTTP and WebSocket workloads 2026-09-11 01:47:10 +08:00
ldm0 7f1617dad2 refactor(curl): separate request handles from runtime ownership 2026-09-11 01:47:10 +08:00
ldm0 544c08cffe refactor(websocket): use the browser fetch transport 2026-09-11 01:47:10 +08:00
ldm0 7ed1ce8a93 feat(websocket): inherit browser TLS credentials 2026-09-10 14:37:03 +08:00
ldm0 6832d179d9 refactor(curl): share TLS certificate configuration 2026-09-10 14:37:03 +08:00
ldm0 114508118a fix(fetch): honor credentials mode for TLS client identities 2026-09-09 19:44:04 +08:00
SpringCorel 1b1969624d feat: support custom TLS certificates 2026-09-09 19:44:04 +08:00
ldm0 b67156a651 perf(fetch): reuse valid UTF-8 response storage 2026-09-05 22:57:54 +08:00
ldm0 e5adfb4120 fix(cdp): align multi-page policy with Chromium 2026-09-01 00:12:24 +08:00
ldm0 6a8a4d7b98 fix(fetch): enforce deadlines before transfer start 2026-09-01 00:12:24 +08:00
ldm0 491e6bb481 refactor(curl): carry transfer identity through runtime 2026-08-30 17:31:29 +08:00
ldm0 1f97225733 build(crypto): replace vendored OpenSSL with AWS-LC 2026-08-27 02:04:51 +08:00
Duang777 3cbc3c2b49 fix(fetch): honor host-resolve overrides in network blocking 2026-08-25 21:41:59 +08:00
ldm0 54f453cdd0 fix(fetch): preserve readiness deadlines and diagnostics
Apply one absolute deadline across response headers, streaming raw bodies, page creation, and later readiness waits. Report the active timeout phase without extending the caller's budget and reject raw documents from Page APIs before an unusable body can stall.

Give CLI fetch failures a stable two-line Error/Reason presentation while retaining full anyhow chains for non-fetch failures, including raw-document page-wait errors.
2026-08-23 04:45:50 +08:00
ldm0 595a538bcf Refactor network fetch errors as anyhow context 2026-08-18 17:38:12 +08:00
ldm0 ce7fa9cd17 feat: implement Web Bot Auth signing 2026-08-16 15:19:40 +08:00
ldm0 f2a2095751 fix(navigation): stabilize sequential CDP lifecycle 2026-08-13 07:07:00 +08:00
ldm0 d4860e4884 fix: scope vendored OpenSSL to Windows 2026-08-11 14:34:42 +08:00
ldm0 0e4971a2b4 fix: vendor OpenSSL for Windows builds 2026-08-11 14:34:42 +08:00
ldm0 27b5135cb6 Public preview 2026-08-11 00:10:12 +08:00