Commit Graph
57 Commits
Author SHA1 Message Date
ldm0 db2e6f84f9 fix(iframe): reuse referrer policy for explicit about blank navigation 2026-09-27 03:27:28 +08:00
ldm0 92c678bf54 fix(fetch): request identity encoding for HTTP ranges
Select Accept-Encoding: identity when a Range header is present, while preserving explicit embedder encoding preferences. Exercise buffered, HTML and raw transports, malformed and empty ranges, redirects, repeated requests and response decompression.
2026-09-25 10:33:04 +08:00
ldm0 33672a12ea fix(fetch): include underlying curl errors in failure reports
Preserve the full error chain in network failure reasons and the CLI fallback so curl error codes and detailed TLS, DNS, and connection failures remain visible. Keep the concise two-line CLI presentation and typed readiness timeout handling.

Test TLS failures across all fetch transports, network error classifications, and CLI connection failures. Validated with cargo fmt --all, workspace Clippy with all targets and features, and cargo nextest run --no-fail-fast (18444 passed).

Refs #701
2026-09-23 14:07:31 +08:00
ldm0 6d08975a69 refactor(fetch): preserve response header bytes end to end
Carry raw response header values through fetch, caches, redirects,
renderer delivery, workers, and protocol records. Convert explicitly
at WebIDL and protocol text boundaries while preserving opaque bytes.

Keep legacy CacheStorage and service worker metadata readable, and
advance the HTTP cache format for raw header values.

Validation:
- cargo fmt --all
- cargo clippy --workspace --all-targets --all-features -- -D warnings
- cargo nextest run --no-fail-fast
2026-09-23 02:02:54 +08:00
lanyue-llk bcf420f622 revert: undo split PR 640 merges (#734-#740) 2026-09-22 20:02:07 +08:00
mini llk 1be735d5c5 fix(network): preserve request metadata and response evidence (#737) 2026-09-22 19:45:58 +08:00
mini llk e30ca4aea4 fix(reliability): harden diagnostics and test infrastructure (#734) 2026-09-22 19:39:41 +08:00
ldm0 7241328085 refactor(fetch): separate curl header encoding from suppression 2026-09-22 02:11:36 +08:00
ldm0 14f6d073be fix(fetch): preserve explicit empty Content-Type headers 2026-09-22 02:11:36 +08:00
ldm0 de1093d9c1 fix(fetch): preserve inherited header lists and cover transport
Keep duplicate header entries in storage and copy inherited Request headers from private state. Apply sort-and-combine only at the relevant consumer boundaries, while explicit HeadersInit values retain WebIDL iterable conversion.

Run no-cors cases through real Window and Worker fetch transports, preserve empty fields on the wire, and correct the local Request getter propagation fixture.
2026-09-21 21:48:05 +08:00
ldm0 796376878b refactor(curl): use owned byte header lists from curl-rust 2026-09-21 05:37:28 +08:00
ldm0 29283fd86a fix(network): scope CDP header overrides and preserve BiDi byte values
Restore original headers on redirect while preserving current-hop overrides
for authentication retries and keeping Network event identity intact.

Preserve raw BiDi Cookie, Set-Cookie, and extra header values through page,
navigation, and worker policies. Apply CDP's last-value behavior for duplicate
request header names.

Add coverage for header bytes, redirects, authentication, and event sequences.
2026-09-21 05:37:28 +08:00
ldm0 932a7225ac refactor(network): preserve request header bytes across interception
Carry RequestHeaders through navigation, Fetch/XHR, workers, redirects and auth,
with explicit Unicode and ByteString conversions at protocol and WebIDL boundaries.
Share the raw curl header list with WebSocket transport and decode binary response
headers without UTF-8 replacement. Keep header memory charging concrete.

Cover opaque values, UTF-8 overrides, duplicates, redirect/auth continuation and
WebSocket handshakes with byte-level regression tests.
2026-09-21 03:54:12 +08:00
ldm0 04302d49fb fix(cors): parse Content-Type parameters without rejecting commas
Extracted from b57d75e801791c4d9b6d682f2aae254d3acd3c53.

Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings. Runtime tests were not run for this split.
2026-09-20 18:03:07 +08:00
ldm0 4ed30be874 fix(fetch): distinguish request header bytes from UTF-8 strings 2026-09-20 14:03:33 +08:00
ldm0 ba11283d57 fix(fetch): preserve HTTP header bytes across the transport
Extracted from f25578c2a9c188d3437e88f337ebaae9da49a246.

Validation: cargo fmt --all; cargo clippy --workspace --all-targets
--all-features -- -D warnings. Runtime tests were not run for this split.
2026-09-20 14:03:33 +08:00
ldm0 493d50e8cf fix: align no-proxy port and wildcard matching with curl 2026-09-18 14:13:58 +08:00
ldm0 90c0ede829 fix: verify HTTPS proxy connections 2026-09-18 14:13:58 +08:00
ldm0 7184290d9f fix: match Chromium SOCKS proxy semantics 2026-09-18 14:13:58 +08:00
ldm0 ad0599b6a9 fix: pin proxy endpoint resolution 2026-09-18 14:13:58 +08:00
ldm0 86d0f1c5c4 refactor: generalize shared DNS endpoints 2026-09-18 14:13:58 +08:00
ldm0 5417fe675e refactor: share proxy route selection 2026-09-18 14:13:58 +08:00
ldm0 fbb6e06874 fix: reject prefixed host resolve syntax 2026-09-18 14:13:58 +08:00
ldm0 6aff3c598f refactor: clarify shared DNS resolution state 2026-09-18 14:13:58 +08:00
ldm0 d0f4ec8a3e refactor: drop redundant curl DNS cache timeout 2026-09-18 14:13:58 +08:00
ldm0 0abe983cc1 fix: unify HTTP proxy route selection 2026-09-18 14:13:58 +08:00
ldm0 fcc7168925 fix: prevent DNS rebinding in network policy 2026-09-18 14:13:58 +08:00
ldm0 a4fd2b9701 fix(fetch): send zero content length for bodyless PUT requests
Configure an empty upload for a bodyless PUT and suppress libcurl’s implicit Content-Type on that path. Recompute framing across redirects, retaining PUT for 301/302/307/308 and dropping the body headers when 303 changes it to GET.

Source: f84c99d671
2026-09-16 15:39:45 +08:00
ldm0 312b0ffc6b feat(emulation): support worker user agent overrides 2026-09-15 16:54:51 +08:00
ldm0 c0a87c6960 fix(fetch): preserve committed origins for document subresources 2026-09-14 06:48:28 +08:00
ldm0 8630dea13b perf(fetch): avoid copying response bytes for module consumers
Use byte-only decomposition for Response and NavigationResponse instead of
discarding the text returned by into_parts(). Module, dedicated worker, and
service worker consumers now transfer the existing exact byte allocation.

Verify storage transfer for UTF-8 and non-UTF-8 payloads.

Source: e32030e484
2026-09-14 06:45:16 +08:00
ldm0 53f790c13a fix(fetch): require browser origins and unify SW request state
Keep request origin independent of URL resolution and referrer context,
including local blob fetches and inherited or sandboxed srcdoc documents.
Reject missing browser origins at the resource client boundary and retain
one Request across Service Worker redirects and network fallback.

Cover dispatch rejection, wire Origin/Cookie headers, memory-cache
partitioning and preserved Service Worker request metadata.

Validation: workspace fmt and Clippy passed; Nextest passed 17,517 tests
with 13 existing skips. Renderer test debug symbols were disabled to fit
available build memory; tests and debug assertions were unchanged.
2026-09-13 16:14:50 +08:00
ldm0 77783ece9d fix(fetch): enforce request modes and CORS before redirects 2026-09-13 16:14:50 +08:00
ldm0 4a1e6fd196 fix(fetch): unify script headers and CORS response validation
Generate Origin independently of browser destination metadata, and attach script
metadata at classic, module, and preload request builders. Share redirect URL-list
rules across request generation and response validation, and remove final-only
CORS validation from manifests, stylesheets, and request interception.

Reject failed CORS checks even without supported integrity metadata. Preserve CSP
reporting before dynamic script fetches and use committed Window origins for
srcdoc and sandboxed child script/module requests.

Add wire-level Origin, Cookie, and Fetch Metadata regressions, plus manifest,
stylesheet CSSOM, CSP, and child module/preload coverage.
2026-09-13 04:46:51 +08:00
ldm0 b63197ff8a fix(fetch): retain redirect state across service worker fallback
Keep redirect history in Request so Service Worker handoffs, network
redirects, preflights, Origin serialization, cookies, and TLS credentials
share the same state. Avoid reusing another request's response URL list
from the renderer memory cache.

Validate and filter network responses using their full history while
preserving readable Service Worker response filters across streaming and
buffered delivery. Returning to the initiating origin keeps network CORS
tainting; worker-produced responses retain their own filtering.

Add wire-header, credentials, cache, and worker response regressions, and
correct the local Fetch/XHR redirect fixtures to authorize and expose CORS
responses after a cross-origin round trip.
2026-09-13 04:46:51 +08:00
ldm0 c1412b76b9 fix(fetch): preserve redirect response provenance
Distinguish network, service worker, and browser-internal redirects so synthetic responses are not subjected to network CORS checks. Preserve every hop for redirect taint and Origin validation, including across navigation response conversions.

Add seven cross-origin service worker script scenarios and guard CORS checks for cached network redirects without ExtraInfo. The new integration regression fails before the fix and passes afterward.

Validated with cargo fmt --all, workspace Clippy across all targets and features with warnings denied, and cargo nextest run --no-fail-fast: 17459 passed, 13 skipped. Used one build job for the full test run after a parallel-build rustc process was killed.
2026-09-13 04:46:51 +08:00
ldm0 4b3b8993bb refactor(curl): share HTTP and WebSocket connection limits
Remove the separate WebSocket CURLSH connection cache so HTTP/1, HTTP/2 and WebSocket sockets compete for the existing host and total limits. Retain bounded session admission and message memory limits.

Pin the curl fork's connect-only eviction fix so quiet upgraded sockets remain owned until their connections close. Cover queueing, deadlines, cancellation, shutdown and HTTP/2 multiplexing under a full shared connection budget.
2026-09-11 01:47:10 +08:00
ldm0 4e63c1e8c6 test(curl): cover shared HTTP and WebSocket workloads 2026-09-11 01:47:10 +08:00
ldm0 7f1617dad2 refactor(curl): separate request handles from runtime ownership 2026-09-11 01:47:10 +08:00
ldm0 544c08cffe refactor(websocket): use the browser fetch transport 2026-09-11 01:47:10 +08:00
ldm0 7ed1ce8a93 feat(websocket): inherit browser TLS credentials 2026-09-10 14:37:03 +08:00
ldm0 6832d179d9 refactor(curl): share TLS certificate configuration 2026-09-10 14:37:03 +08:00
ldm0 114508118a fix(fetch): honor credentials mode for TLS client identities 2026-09-09 19:44:04 +08:00
SpringCorel 1b1969624d feat: support custom TLS certificates 2026-09-09 19:44:04 +08:00
ldm0 b67156a651 perf(fetch): reuse valid UTF-8 response storage 2026-09-05 22:57:54 +08:00
ldm0 e5adfb4120 fix(cdp): align multi-page policy with Chromium 2026-09-01 00:12:24 +08:00
ldm0 6a8a4d7b98 fix(fetch): enforce deadlines before transfer start 2026-09-01 00:12:24 +08:00
ldm0 491e6bb481 refactor(curl): carry transfer identity through runtime 2026-08-30 17:31:29 +08:00
ldm0 1f97225733 build(crypto): replace vendored OpenSSL with AWS-LC 2026-08-27 02:04:51 +08:00
Duang777 3cbc3c2b49 fix(fetch): honor host-resolve overrides in network blocking 2026-08-25 21:41:59 +08:00