Repository navigation
fix(tunnel): restore H2 TLS session resumption - #40
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Warm connections fail when a valid server triggers HelloRetryRequest because uTLS v1.8.2 cannot reprocess the populated PSK.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Restores TLS 1.3 session resumption for the fixed Chrome-133 H2 profile.
Changes:
- Adds uTLS-native PSK/binder preparation.
- Adds resumption, cancellation, authentication, and verification tests.
- Documents resumption privacy and certificate-policy implications.
| File | Description |
|---|---|
internal/tunnel/web_fingerprint.go |
Adds PSK-enabled Chrome-133 handshakes. |
internal/tunnel/web_h2_resumption_test.go |
Tests real H2 resumption and fresh authentication. |
internal/tunnel/web_fingerprint_resumption_policy_test.go |
Tests preparation, cancellation, and verification policies. |
docs/WEB_COVER.md |
Documents resumption behavior and limitations. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Evidence for final head 97dfb7c
make checkand fullmake racepassed; release-recipe suites 18+17+14 passed.3b3747fa0f7ab76156413e7783484f5b32e87d37c620e231181ca2297bbfd26a.The initial a106d1a head had green CI but was deliberately not merged after review identified the HRR gap. Final-head CI (11/11 jobs), CodeQL and Linux netem all completed successfully on pull_request attempt 1. Actual docker integration, dual-architecture OCI export and netem success logs were verified; no reruns. The confirmed HRR review thread was addressed and resolved.
Limits
No actual-browser comparison, corpus campaign, remote deployment, release or tag. No indistinguishability/classifier-advantage claim. HRR fallback is a full handshake, not successful Chrome PSK/HRR resumption; P384/cookie-only paths are source-reviewed but not exercised. TLS ticket reuse can correlate connections; caller-disable policy remains. All earlier intermediate failures/logs are retained locally; one opaque historical peer-close error remains unconfirmed rather than being retroactively labelled reset.
Merge verification
Squash-merged as
01b705234df2a9d8385013de35d85fad01dd1126. Local and remote main agree, tested tree and full-source manifests match, and the worktree is clean. Main push attempt1 CI (11/11 jobs), CodeQL and Linux netem all passed; actual container/dual-architecture OCI export and netem logs were checked. Post-main macOS race repeats of all 10 exact new top-level names ×3 passed (30 executions/108 RUN entries), with exact selection/RUN-set checks. No new release or tag.