Repository navigation
Add opt-in web-H3 session resumption with maintained QUIC fork - #77
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
Adopt the reviewed, published AutoCAR-maintained QUIC compatibility fork while keeping native transport on official QUIC. The default
chrome-2026-10full-handshake profile stays unchanged.Changes
chrome-2026-10-resumefor opt-in TLS 1.3 ticket resumption on web H3.Verification
Exact Go 1.27.2:
make check, fullmake race, module/checksum verification, dependency-boundary offline regressions and source vulnerability scan, plus separate original-uTLS and official-QUIC advisory queries.The small Linux/ARM64 functional suite runs as the same cross-compiled test binary both in isolated local Docker and on the authorized ARM Linux host. It covers cold/resumed TLS, TCP and CONNECT-UDP reauthentication, cancellation, cache isolation and observable absence of 0-RTT.
The source scan reports no imported/reachable vulnerability. The module-only GO-2026-5932 OpenPGP advisory is not imported by the checked graph; this is not a claim that every dependency is vulnerability-free.
Limits
This is bounded functional and packet-header validation, not a real-browser traffic equivalence study. No large PCAP corpus was resumed, no service was deployed or replaced, and no release tag was created.
Merge only after the exact reviewed head's checks pass; verify the merged tree and its CI separately.
Final dependency and Linux validation
c1cae948af15a90ec8c3929fb336b9bcd7165bc7, with 22 successful reviewed-head checks and all 11 exact post-merge checks successful. The merged tree matches the reviewed tree.14c2a4cb1403d9ad48120936a1fb4e8efe825ad4, with pre/post-merge CI successful.make check, fullmake race, checksum and source-scan gates passed using the published remote replacements, without development modfiles.54b33af029c117436cfcbbe67b0dc17297b32b6af93fb86ef107237fb23a54a5. Both isolated Docker and ARM Linux passed all eight selected top-level groups; cold and resumed runs observed zero 0-RTT packets. This is loopback integration on those hosts, not a WAN benchmark.