Skip to content

fix(web): preserve global OPTIONS and cover metadata boundaries - #43

Merged
cppla merged 1 commit into
mainfrom
codex/web-cover-request-target-trailer-policy
Oct 2, 2026
Merged

cppla merged 1 commit into
mainfrom
codex/web-cover-request-target-trailer-policy

Conversation

@cppla

@cppla cppla commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Changes

  • Route real OPTIONS * through the configured cover on H1/H2/H3. Static cover returns its normal 405/Allow and combined bound Alt-Svc; fixed-origin cover preserves * without attaching a configured resource prefix/query.
  • Capture original response Connection nominations at the transport boundary, before standard ReverseProxy removes them. Keep immutable nomination policy for initial and late/replacement trailers, preserving streaming and concurrent Read/Close behavior.
  • Remove relay-owned Proxy-Authentication-Info from public cover request headers and upstream informational/final/trailer/validated-WebSocket responses. Preserve ordinary Authentication-Info/WWW-Authenticate unless explicitly connection-nominated.
  • Keep visitor Origin/Referer/CSRF policy, fixed upstream authority, authenticated tunnel proof handling and default/native transport unchanged. Documentation labels these as source-build changes after v1.0.1.

Verification

  • Real old-production baselines reproduce the selected defects. Exact final tests with the old production overlay: 33 intended failing logical leaves and 19 passing controls; no build/launch/timeout/race substitute.
  • Local full make check and make race pass (Go 1.25.13).
  • All ten new test names run three times under Go 1.25.13 and 1.27.1 race instrumentation: 52 logical leaf names / 156 leaf executions per version; actual H1/H2/H3 requests verify fixed origin, early streaming and complete EOF payload, safe metadata preservation, zero tunnel target dial/resolution, and owned worker joins.
  • Frozen Linux/arm64 CGO0 isolated Docker component checks pass: 624 RUN/PASS entries, including three runs of all new tests and 103 existing controls. Exact source/tool/script/binary manifests stay unchanged and the owned container is removed. Linux component execution is separate from race coverage.
  • Independent scoped production/fixture reviews found no blockers. Final-head CI (all 11 jobs), CodeQL, and Linux netem pass on pull_request attempt 1. Actual CI checkout is the PR merge commit with the exact feature tree and base/head parents; container integration and both OCI architectures complete. Netem evidence is native-only, not impaired web/H2/H3 coverage. One Copilot COMMENTED overview reports no findings; there are no inline threads, not a formal APPROVED review.

Limits

No release/tag, production deployment, old remote-machine use, or large capture campaign. This is ordinary HTTP compatibility and metadata-boundary evidence, not real-browser fingerprint equivalence or comparative traffic-identification evidence. The native upstream parser's documented Connection-close nomination information-loss limit is unchanged.

Post-merge verification

Merged as bd4efe25405e7ff5fccb7031d9eeedc3d757154b with the exact tested tree. Main push attempt 1 CI (11/11), CodeQL and native Linux netem all pass. Main's actual container integration and amd64/arm64 OCI export complete; the local clean main tree equals the frozen source and all ten new regression names pass three more race runs. No release or production deployment was performed.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 20:46

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The security-sensitive metadata and concurrent body-wrapper changes span multiple HTTP protocol implementations and warrant final human review.

Review effort: Balanced
Findings: None

What changed in this PR

Routes global OPTIONS * through cover handlers and hardens cover metadata filtering across HTTP protocols.

Changes:

  • Preserves OPTIONS * semantics for static and fixed-origin covers.
  • Retains original connection nominations when filtering late trailers.
  • Removes relay-owned authentication metadata from public cover traffic.
File Description
internal/​tunnel/​web_h2.go Disables automatic OPTIONS interception.
internal/​tunnel/​web_cover_options_test.go Tests OPTIONS behavior across H1/H2/H3.
internal/​tunnel/​web_cover_metadata_test.go Tests metadata filtering and streaming.
internal/​cover/​metadata_policy_test.go Covers nomination and authentication policies.
internal/​cover/​handler.go Implements routing and metadata filtering.
docs/​WEB_COVER.md Documents the new behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@cppla
cppla merged commit bd4efe2 into main Oct 2, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants