Skip to content

fix(tunnel): restore H2 TLS session resumption - #40

Merged
cppla merged 2 commits into
mainfrom
codex/h2-tls-resumption
Oct 2, 2026
Merged

cppla merged 2 commits into
mainfrom
codex/h2-tls-resumption

Conversation

@cppla

@cppla cppla commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Restore real TLS 1.3 session resumption for the cache-enabled fixed Chrome-133 H2 client using a fresh preset and uTLS's native PSK extension; empty/disabled caches keep full handshakes. Preparation stays inside HandshakeContext, with nonblocking cancellation checks.
  • Handle the pinned library's populated-PSK + HelloRetryRequest limitation narrowly: require the exact library diagnostic and genuine exported HRR/PSK state, close and join the failed physical attempt, and retry once without a ticket under the same remaining initialization budget.
  • Keep certificate/hostname verification, TLS 1.3, h2 and fresh per-physical proxy authentication. No 0-RTT, native-profile switch, global resumption disable, unrelated-error retry, dependency update or protocol-version change.

Evidence for final head 97dfb7c

  • Source-attributed macOS Go 1.25.13 offline make check and full make race passed; release-recipe suites 18+17+14 passed.
  • Real loopback resumption tests and policy controls pass. The original production-only negative control accurately fails enabled Chrome resumption while native/disabled/nil controls pass.
  • Real P256-only HRR tests pass race ×3: two healthy authenticated physical sessions, four complete TCP payload/reply + FIN tunnels, fresh bootstrap/short continuation and distinct authentication keys. Native genuinely resumes through HRR; Chrome performs a single full-handshake compatibility fallback. Same-final tests with the earlier two-production-file candidate accurately fail the warm Chrome case.
  • Boundary tests pass race ×3 (33 leaf executions): original absolute timeout, caller custom cause even when dial returns ctx.Err, client.Close, failed-old-raw close before fresh dial, fresh H2-preface cancellation, no retry loop, and no retry for certificate/ALPN/same-text-non-HRR errors. Same-final old-production negative runs compile and fail exactly the eight fallback-dependent leaves; three ordinary-error controls pass.
  • One isolated cached-image Linux/arm64 CGO-disabled component run passed: 10 new top-level names ×3 (30 executions/108 RUN entries) and 40 existing names ×1 (119 RUN entries). Exact list/RUN sets and full-source/compiler/script/binary manifests match; owned container removed. This is not Linux race or production validation.
  • Independent automated source/security/context reviews completed without a remaining must-fix finding. Final full Go/docs/module manifest SHA-256: 3b3747fa0f7ab76156413e7783484f5b32e87d37c620e231181ca2297bbfd26a.

The initial a106d1a head had green CI but was deliberately not merged after review identified the HRR gap. Final-head CI (11/11 jobs), CodeQL and Linux netem all completed successfully on pull_request attempt 1. Actual docker integration, dual-architecture OCI export and netem success logs were verified; no reruns. The confirmed HRR review thread was addressed and resolved.

Limits

No actual-browser comparison, corpus campaign, remote deployment, release or tag. No indistinguishability/classifier-advantage claim. HRR fallback is a full handshake, not successful Chrome PSK/HRR resumption; P384/cookie-only paths are source-reviewed but not exercised. TLS ticket reuse can correlate connections; caller-disable policy remains. All earlier intermediate failures/logs are retained locally; one opaque historical peer-close error remains unconfirmed rather than being retroactively labelled reset.

Merge verification

Squash-merged as 01b705234df2a9d8385013de35d85fad01dd1126. Local and remote main agree, tested tree and full-source manifests match, and the worktree is clean. Main push attempt1 CI (11/11 jobs), CodeQL and Linux netem all passed; actual container/dual-architecture OCI export and netem logs were checked. Post-main macOS race repeats of all 10 exact new top-level names ×3 passed (30 executions/108 RUN entries), with exact selection/RUN-set checks. No new release or tag.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 18:22

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Warm connections fail when a valid server triggers HelloRetryRequest because uTLS v1.8.2 cannot reprocess the populated PSK.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Restores TLS 1.3 session resumption for the fixed Chrome-133 H2 profile.

Changes:

  • Adds uTLS-native PSK/binder preparation.
  • Adds resumption, cancellation, authentication, and verification tests.
  • Documents resumption privacy and certificate-policy implications.
File Description
internal/​tunnel/​web_fingerprint.go Adds PSK-enabled Chrome-133 handshakes.
internal/​tunnel/​web_h2_resumption_test.go Tests real H2 resumption and fresh authentication.
internal/​tunnel/​web_fingerprint_resumption_policy_test.go Tests preparation, cancellation, and verification policies.
docs/​WEB_COVER.md Documents resumption behavior and limitations.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/tunnel/web_fingerprint.go
@cppla
cppla merged commit 01b7052 into main Oct 2, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants