Commit Graph
46 Commits
Author SHA1 Message Date
ldm0 261b4f3052 test: fix macOS workspace test failures 2026-09-23 22:24:26 +08:00
ldm0 71c46d6606 test(tls): install macOS trust fixture in system keychain 2026-09-23 14:07:31 +08:00
ldm0 2d5b88b3dc fix(tls): use Apple SecTrust by default on macOS
Pin the curl-rust build that enables libcurl's Apple SecTrust verifier
with the existing AWS-LC TLS backend. Leave default CA options unset
so macOS trust comes from the operating system rather than an
automatically discovered certificate file.

Preserve explicit CA files and certificate environment overrides for
origins and HTTPS proxies, including explicit-file precedence over
SSL_CERT_DIR. Keep other platforms' existing trust configuration.

Add macos-latest CI coverage for local HTTPS, WSS, and
HTTPS proxy handshakes, including native-verifier diagnostics,
rejected certificates and hostnames, and CA overrides.

Use distinct CA and server identities, blocking accepted sockets, and
bounded fixture commands. Exercise the generated chains, nonblocking
socket transition, and process deadlines in portable regression tests.

Validated on Linux with cargo fmt --all, workspace Clippy with all
targets and features, and cargo nextest run --no-fail-fast:
18447 passed, 14 skipped. macOS-specific checks run in CI.

Refs #701
2026-09-23 14:07:31 +08:00
lanyue-llk bcf420f622 revert: undo split PR 640 merges (#734-#740) 2026-09-22 20:02:07 +08:00
mini llk e30ca4aea4 fix(reliability): harden diagnostics and test infrastructure (#734) 2026-09-22 19:39:41 +08:00
ldm0 796376878b refactor(curl): use owned byte header lists from curl-rust 2026-09-21 05:37:28 +08:00
ldm0 932a7225ac refactor(network): preserve request header bytes across interception
Carry RequestHeaders through navigation, Fetch/XHR, workers, redirects and auth,
with explicit Unicode and ByteString conversions at protocol and WebIDL boundaries.
Share the raw curl header list with WebSocket transport and decode binary response
headers without UTF-8 replacement. Keep header memory charging concrete.

Cover opaque values, UTF-8 overrides, duplicates, redirect/auth continuation and
WebSocket handshakes with byte-level regression tests.
2026-09-21 03:54:12 +08:00
ldm0 26ca39c382 fix: match curl no-proxy dot normalization 2026-09-18 14:13:58 +08:00
ldm0 493d50e8cf fix: align no-proxy port and wildcard matching with curl 2026-09-18 14:13:58 +08:00
ldm0 2faf89e5c5 fix: restore HTTPS proxy default port 2026-09-18 14:13:58 +08:00
ldm0 8980a1cb41 fix: align proxy DNS pinning with curl ports 2026-09-18 14:13:58 +08:00
ldm0 3363d9dc5f docs: explain DNS and proxy invariants 2026-09-18 14:13:58 +08:00
ldm0 f220ffc53a test: keep failed proxy DNS outside curl 2026-09-18 14:13:58 +08:00
ldm0 90c0ede829 fix: verify HTTPS proxy connections 2026-09-18 14:13:58 +08:00
ldm0 7184290d9f fix: match Chromium SOCKS proxy semantics 2026-09-18 14:13:58 +08:00
ldm0 ad0599b6a9 fix: pin proxy endpoint resolution 2026-09-18 14:13:58 +08:00
ldm0 86d0f1c5c4 refactor: generalize shared DNS endpoints 2026-09-18 14:13:58 +08:00
ldm0 5417fe675e refactor: share proxy route selection 2026-09-18 14:13:58 +08:00
ldm0 6aff3c598f refactor: clarify shared DNS resolution state 2026-09-18 14:13:58 +08:00
ldm0 fcc7168925 fix: prevent DNS rebinding in network policy 2026-09-18 14:13:58 +08:00
ldm0 6956e5cf3c fix(curl): resume eligible HTTP jobs after completions
Include queued HTTP work in the owner's runnable decision after completions release active slots. Share the global and per-origin eligibility checks with the startup path so blocked queues still allow the owner to wait.

Add native owner regressions that consume submission wakeups before releasing a held request, then require the queued request to finish within its short deadline. Cover both scheduler limits and priority queues whose head is blocked by an origin cap.
2026-09-11 11:43:15 +08:00
ldm0 4b3b8993bb refactor(curl): share HTTP and WebSocket connection limits
Remove the separate WebSocket CURLSH connection cache so HTTP/1, HTTP/2 and WebSocket sockets compete for the existing host and total limits. Retain bounded session admission and message memory limits.

Pin the curl fork's connect-only eviction fix so quiet upgraded sockets remain owned until their connections close. Cover queueing, deadlines, cancellation, shutdown and HTTP/2 multiplexing under a full shared connection budget.
2026-09-11 01:47:10 +08:00
ldm0 0fde20db42 refactor(curl): organize runtime and protocol modules 2026-09-11 01:47:10 +08:00
ldm0 4e63c1e8c6 test(curl): cover shared HTTP and WebSocket workloads 2026-09-11 01:47:10 +08:00
ldm0 7f1617dad2 refactor(curl): separate request handles from runtime ownership 2026-09-11 01:47:10 +08:00
ldm0 150c01436a refactor(curl): drive HTTP and WebSocket on one owner 2026-09-11 01:47:10 +08:00
ldm0 d9ce1e216b chore(curl): add opt-in WebSocket owner diagnostics 2026-09-11 01:47:10 +08:00
ldm0 06e0c320be perf(curl): reuse receive storage after would-block 2026-09-11 01:47:10 +08:00
ldm0 14fed394be fix(websocket): schedule native I/O by readiness 2026-09-11 01:47:10 +08:00
ldm0 cd3a2b1679 refactor(websocket): encapsulate native session lifecycle 2026-09-11 01:47:10 +08:00
ldm0 2fa5cff3ce refactor(websocket): remove unused CONNECT header assembly
Write proxy header values directly into the native request and delete the
unused CONNECT string and append_proxy_connect_header helper. Native
request configuration already validates these fields before connecting.

Move rejection coverage to the native configuration entry point, covering
CR, LF and NUL in User-Agent and Proxy-Authorization. Check User-Agent on
the actual CONNECT request while retaining proxy credential isolation and
WSS tunnel coverage.

Validation: 96 package tests passed all 3 iterations; cargo fmt --all,
strict workspace/all-targets/all-features Clippy and full nextest passed
(17322 passed, 13 skipped).
2026-09-10 14:37:03 +08:00
ldm0 31bb71c430 refactor(websocket): rely on native frame validation
Remove FrameProgress and message_kind from the browser assembler. Use
libcurl's validated chunk metadata and normalized continuation types,
checking frame and message memory limits before buffering each new frame.
Keep payload assembly, UTF-8 and Close content validation in the browser
layer.

Document the native Chunk contract and cover 31 invalid framing cases,
chunk boundaries, continuation types, empty frames and interleaved control
frames through the real transport. Strengthen browser regressions for
partial-message failure, UTF-8, Close contents and exact size limits.

Verify that a declared final frame which exceeds the message budget fails
while the bytes received are still within that budget, without waiting
for the rest of the frame payload.

Validation: cargo fmt --all; strict workspace/all-targets/all-features
Clippy; full nextest (17321 passed, 13 skipped). The 564 related tests
passed all 3 stress iterations; the strengthened message-budget boundary
test passed all 10 iterations.
2026-09-10 14:37:03 +08:00
ldm0 10b242f855 refactor(websocket): keep a single native frame in flight
Replace unused data/control send queues, admission semaphores and public
receipts with send_frame(). The browser session owns scheduling; a single
pending frame preserves partial writes and completes independently of
receive backpressure.

Reject overlapping submissions and retain submitted frames if their
waiting futures are dropped. Cover slot reuse, cancellation, transport
failure, partial writes and sends with a full receive queue.

Update curl-rust to 608f08d, which bounds native receive prefetch and fixes
the browser receive-backpressure regression exposed during validation.

Validation: cargo fmt --all; strict workspace/all-targets/all-features
Clippy; full nextest (17318 passed, 13 skipped). The unchanged browser
receive-backpressure test passed 40 stress iterations, and 561 related
tests passed all 3 stress iterations.
2026-09-10 14:37:03 +08:00
ldm0 33108fcffd refactor(websocket): separate native send admission and completion 2026-09-10 14:37:03 +08:00
ldm0 0c116aa350 fix(websocket): decouple send progress from event delivery 2026-09-10 14:37:03 +08:00
ldm0 7ed1ce8a93 feat(websocket): inherit browser TLS credentials 2026-09-10 14:37:03 +08:00
ldm0 6832d179d9 refactor(curl): share TLS certificate configuration 2026-09-10 14:37:03 +08:00
ldm0 49848795c4 test(websocket): cover browser lifecycle and transport backpressure 2026-09-10 14:37:03 +08:00
ldm0 391742c14b feat(websocket): use native curl transport 2026-09-10 14:37:03 +08:00
ldm0 7bc35983c1 feat(curl): add persistent websocket session runtime 2026-09-10 14:37:03 +08:00
ldm0 6a8a4d7b98 fix(fetch): enforce deadlines before transfer start 2026-09-01 00:12:24 +08:00
ldm0 18f412a746 refactor(curl): split runtime into focused modules 2026-08-30 17:31:29 +08:00
ldm0 491e6bb481 refactor(curl): carry transfer identity through runtime 2026-08-30 17:31:29 +08:00
ldm0 1f97225733 build(crypto): replace vendored OpenSSL with AWS-LC 2026-08-27 02:04:51 +08:00
ldm0 6566674ac7 fix(network): preserve curl completion order 2026-08-26 03:29:40 +08:00
ldm0 27b5135cb6 Public preview 2026-08-11 00:10:12 +08:00