Skip to content

docs: record bounded H2 browser endpoint observations - #76

Merged
cppla merged 1 commit into
mainfrom
codex/h2-browser-observation
Oct 9, 2026
Merged

cppla merged 1 commit into
mainfrom
codex/h2-browser-observation

Conversation

@cppla

@cppla cppla commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Summary

  • Record a bounded macOS endpoint-decrypted HTTP/2 diagnostic against production source 0c17d9f and installed Chrome 154.0.8037.95.
  • Document concrete SETTINGS/window/header-name observations and link the report from the H2 fingerprint boundary.
  • Keep the result insufficient_evidence: this is documentation only, with no production behavior, dependency, profile, or release-gate changes.

Evidence and limitations

  • 9/9 AutoCAR observations (3 per native/chrome-133/chrome-155), each with a response and the exact expected authentication rejection. The nonforwarding observer intentionally supplies no authentication proof; successful tunnels: 0.
  • 3 browser page loads and complete endpoint observations. Only 2/3 browser Resource Timing/product records were saved: the first inspector aborted on a rejected CDP command-line query. All three command-line queries were unavailable. Original failure and instrumentation amendment are retained, with no replacement samples/retries.
  • GET and CONNECT are different workloads; separate ephemeral origins/certificates were used between modes. This is not passive classification, a Chrome 155 browser comparison, or completed browser acceptance.
  • Local ignored collector, tests, plan, logs and result hashes are identified explicitly as retained local—not independently hosted—evidence. Header values and private keys were not serialized; all lab sessions/listeners were closed.

Validation

  • make check: passed.
  • Local observer go test -race -count=10: passed.
  • Independent source/evidence review; frozen collector and Chrome hashes match before/after.
  • No remote deployment or release tag.

Copilot AI balanced review requested due to automatic review settings October 9, 2026 02:45

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@cppla
cppla merged commit 24d97d7 into main Oct 9, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants