Pin the curl-rust build that enables libcurl's Apple SecTrust verifier
with the existing AWS-LC TLS backend. Leave default CA options unset
so macOS trust comes from the operating system rather than an
automatically discovered certificate file.
Preserve explicit CA files and certificate environment overrides for
origins and HTTPS proxies, including explicit-file precedence over
SSL_CERT_DIR. Keep other platforms' existing trust configuration.
Add macos-latest CI coverage for local HTTPS, WSS, and
HTTPS proxy handshakes, including native-verifier diagnostics,
rejected certificates and hostnames, and CA overrides.
Use distinct CA and server identities, blocking accepted sockets, and
bounded fixture commands. Exercise the generated chains, nonblocking
socket transition, and process deadlines in portable regression tests.
Validated on Linux with cargo fmt --all, workspace Clippy with all
targets and features, and cargo nextest run --no-fail-fast:
18447 passed, 14 skipped. macOS-specific checks run in CI.
Refs #701
Carry RequestHeaders through navigation, Fetch/XHR, workers, redirects and auth,
with explicit Unicode and ByteString conversions at protocol and WebIDL boundaries.
Share the raw curl header list with WebSocket transport and decode binary response
headers without UTF-8 replacement. Keep header memory charging concrete.
Cover opaque values, UTF-8 overrides, duplicates, redirect/auth continuation and
WebSocket handshakes with byte-level regression tests.
Include queued HTTP work in the owner's runnable decision after completions release active slots. Share the global and per-origin eligibility checks with the startup path so blocked queues still allow the owner to wait.
Add native owner regressions that consume submission wakeups before releasing a held request, then require the queued request to finish within its short deadline. Cover both scheduler limits and priority queues whose head is blocked by an origin cap.
Remove the separate WebSocket CURLSH connection cache so HTTP/1, HTTP/2 and WebSocket sockets compete for the existing host and total limits. Retain bounded session admission and message memory limits.
Pin the curl fork's connect-only eviction fix so quiet upgraded sockets remain owned until their connections close. Cover queueing, deadlines, cancellation, shutdown and HTTP/2 multiplexing under a full shared connection budget.
Write proxy header values directly into the native request and delete the
unused CONNECT string and append_proxy_connect_header helper. Native
request configuration already validates these fields before connecting.
Move rejection coverage to the native configuration entry point, covering
CR, LF and NUL in User-Agent and Proxy-Authorization. Check User-Agent on
the actual CONNECT request while retaining proxy credential isolation and
WSS tunnel coverage.
Validation: 96 package tests passed all 3 iterations; cargo fmt --all,
strict workspace/all-targets/all-features Clippy and full nextest passed
(17322 passed, 13 skipped).
Remove FrameProgress and message_kind from the browser assembler. Use
libcurl's validated chunk metadata and normalized continuation types,
checking frame and message memory limits before buffering each new frame.
Keep payload assembly, UTF-8 and Close content validation in the browser
layer.
Document the native Chunk contract and cover 31 invalid framing cases,
chunk boundaries, continuation types, empty frames and interleaved control
frames through the real transport. Strengthen browser regressions for
partial-message failure, UTF-8, Close contents and exact size limits.
Verify that a declared final frame which exceeds the message budget fails
while the bytes received are still within that budget, without waiting
for the rest of the frame payload.
Validation: cargo fmt --all; strict workspace/all-targets/all-features
Clippy; full nextest (17321 passed, 13 skipped). The 564 related tests
passed all 3 stress iterations; the strengthened message-budget boundary
test passed all 10 iterations.
Replace unused data/control send queues, admission semaphores and public
receipts with send_frame(). The browser session owns scheduling; a single
pending frame preserves partial writes and completes independently of
receive backpressure.
Reject overlapping submissions and retain submitted frames if their
waiting futures are dropped. Cover slot reuse, cancellation, transport
failure, partial writes and sends with a full receive queue.
Update curl-rust to 608f08d, which bounds native receive prefetch and fixes
the browser receive-backpressure regression exposed during validation.
Validation: cargo fmt --all; strict workspace/all-targets/all-features
Clippy; full nextest (17318 passed, 13 skipped). The unchanged browser
receive-backpressure test passed 40 stress iterations, and 561 related
tests passed all 3 stress iterations.