Skip to content

fix(web): align combined H3 cover Alt-Svc with bound listener - #41

Merged
cppla merged 1 commit into
mainfrom
codex/public-h3-alt-svc
Oct 2, 2026
Merged

cppla merged 1 commit into
mainfrom
codex/public-h3-alt-svc

Conversation

@cppla

@cppla cppla commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Give the combined ListenWeb H1/H2/H3 public cover the same immutable bound-port Alt-Svc policy, including informational and final/implicit responses. Upstream stale/unrelated alternative services no longer bypass that policy on H3.
  • Only the Cover handler is wrapped. Authenticated H2/H3 responses retain the original writer/proof behavior and no public Alt-Svc; standalone ListenWebH3 retains its configured cover's advertisement policy.
  • Synchronize exactly one existing combined-listener H3 header expectation with the new policy; its 12 healthy tunnel flows and other assertions are unchanged. Add a separate real-wire regression matrix and documentation.

Validation for head 99ffa5c

  • Final-source offline macOS Go1.25.13 make check and full make race passed, including release suites 18+17+14.
  • Four new real-wire tests pass race count3: 43 leaf cases per iteration / 129 total (12 top executions, 156 RUN entries). Seven cover commit modes across real H1/H2/H3 include one/repeated 1xx, explicit status, Write, Flush, ReaderFrom, implicit empty and cleared headers. Ordinary status/body/end-to-end fields are preserved.
  • Real fixed-origin reverse-proxy visitor/invalid-credential/invalid CONNECT-UDP probes verify identical same-protocol final metadata, no private proof/challenge, and target dial/resolution/forwarded-credential counters0/0/0.
  • Authenticated H2/H3 controls verify actual healthy TCP payload/reply with bootstrap proof and distinct signed502 destination failures; neither gets Alt-Svc or touches Cover. Standalone real H3 retains upstream multiple advertisement values.
  • Same final test source with only the old production web_server.go overlaid actually compiles/runs: exactly14 combined-H3 public leaves fail the Alt-Svc oracle; H1/H2, authenticated and standalone controls pass. Earlier candidate fixture mistakes/logs are retained, not promoted to negative evidence.
  • One isolated cached-image Linux/arm64 Go1.25.13 CGO-disabled component run passed: 4 exact new names ×3 (156 RUN entries), 22 selected existing names ×1 (57 RUN entries). Exact test.list/RUN sets and source/compiler/script/binary manifests match; owned container removed. This is not Linux race or production validation.
  • Independent automated source/security/test review found no remaining must-fix in this snapshot. Full198-entry Go/docs/module manifest SHA-256: a4ad9adc7dc2d09941e94c2920ab985faaf8f2042ae669965c6ba8e6dd05fef0.

Final-head gates verified on exact head99ffa5: CI37052177557 completed/success, latest attempt2 view has11 successful jobs. Only the failed OCI job was requested again once; GitHub's latest view assigns new IDs/run_attempt2 to all jobs, while the ten other jobs retain their original attempt1 execution timestamps. Original attempt1 OCI download failure is retained and not relabelled as success. Rerun OCI110989564061 completed both linux/amd64 and linux/arm64 compilation, manifest/index and tarball export; actual docker integration passed marker is present. CodeQL37052177521 and Linux netem37052177546 completed/success attempt1; actual netem integration passed marker is present. Both integration logs check out PR merge af59f69 of exact head99ffa5 into base01b705. No inline review threads or findings remain. PR41 merged with expected-head guard as main cb74137. Local main fast-forward and tree/source-manifest equality verified; post-main exact4-name race count3 passed (12 tops/156 RUN/129 leaves, no skips). Main push CI37053090883 (11 jobs), CodeQL37053091049 and netem37053091109 all completed/success, attempt1, on exact cb74137. Actual main OCI110991021275 and netem110991022657 logs independently confirm checkout cb74137, docker/netem completion markers and both-platform OCI index/tarball DONE. No main rerun or new release/tag.

Limits

No release/tag, dependency update, remote deployment, actual-browser/corpus campaign or classifier-quality claim. Equal advertisement is a functional/routing consistency result, not browser indistinguishability. Arbitrary custom H3 cover extension interfaces and late header mutations beyond the standard ResponseWriter contract are not promised. WebSocket upgrade/lifecycle changes are intentionally separate; this patch does not enable them.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 19:08

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation is narrowly scoped and comprehensively validates public, authenticated, and standalone behavior.

Review effort: Balanced
Findings: None

What changed in this PR

Aligns combined H1/H2/H3 cover responses to advertise the bound HTTP/3 listener consistently.

Changes:

  • Applies the bound-port Alt-Svc wrapper to combined-listener H3 cover traffic.
  • Adds comprehensive protocol, response-mode, authentication, and standalone-H3 regression tests.
  • Documents the advertisement policy.
File Description
internal/​tunnel/​web_server.go Shares the bound Alt-Svc cover wrapper with H2 and H3.
internal/​tunnel/​web_server_test.go Updates the combined-listener H3 expectation.
internal/​tunnel/​web_h3_alt_svc_consistency_test.go Adds real-wire consistency and isolation coverage.
docs/​WEB_COVER.md Documents combined and standalone H3 behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@cppla
cppla merged commit cb74137 into main Oct 2, 2026
25 of 26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants