Commit Graph

77 Commits (a5fe135a76aea6b2b2170d443885e7de403bc025)

Author SHA1 Message Date
Lin a5fe135a76 net/spdy: fail closed on invalid CONNECT response headers
OnHeadersReceived() ignored the return value of
SpdyHeadersToHttpResponse(); on a malformed CONNECT response the
response_ headers stayed null and DoReadReplyComplete() dereferenced
them.

Guard response_.headers in DoReadReplyComplete() and fail the tunnel
with ERR_TUNNEL_CONNECTION_FAILED. Both the normal CONNECT path and
the Fast Open path funnel through DoReadReplyComplete(), so a single
null check covers both, and OnHeadersReceived() stays unchanged from
upstream.

Closes audit finding F2 (SPDY OnHeadersReceived null dereference).

(cherry picked from commit afce211960e3ec092aa5347bbe6b9e2d63691d34)
2026-09-08 01:40:04 +08:00
Zgrams 769aaa53c3
Fix insufficient resources error handling (#819)
When naive DoAccept failed on ERR_INSUFFICIENT_RESOURCES, rv is passed
to DoAcceptComplete, if rv is not OK, this function sets next state to
DoAccept again, when naive reaches system wide file discriptor limits,
and a pending CONNECT in queue, naive will be trapped in an infinite
busy spinning loop and can not recover as resources are not reclaimed.
2026-09-06 09:35:08 +08:00
klzgrad 3ba967e2d3 Add continuous integration and tests 2026-07-02 23:06:54 +08:00
klzgrad a7daa5b386 Support debug build 2026-07-02 23:06:54 +08:00
klzgrad a3dd7ff510 Add apk build 2026-07-02 22:58:43 +08:00
klzgrad 5fa9bf9f76 Add build scripts 2026-07-02 22:58:43 +08:00
klzgrad dc95308bc4 Add README 2026-07-02 22:58:43 +08:00
klzgrad 743e42c12a Add source import tool 2026-07-02 22:58:43 +08:00
klzgrad 94e9f3c63b Add Naive 2026-07-02 22:58:43 +08:00
klzgrad f51bcebc49 musl: Disable copy_file_range 2026-07-02 22:58:43 +08:00
klzgrad 6d115831bf musl: third_party/perfetto: Support old Musl with missing pthread_getname_np
Following base/sampling_heap_profiler/sampling_heap_profiler.cc,
Linux can use prctl for this directly.
2026-07-02 22:58:43 +08:00
klzgrad 2f5f7b6980 musl: third_party/lss: Fix missing sgidefs.h 2026-07-02 22:58:43 +08:00
klzgrad 979095b706 musl: net: Fix DNS res_init 2026-07-02 22:58:43 +08:00
klzgrad dcaafad8e0 musl: allocator: Disable ifunc on aarch64 2026-07-02 22:58:43 +08:00
klzgrad 6bc72e845a musl: allocator: Disable memory tagging 2026-07-02 22:58:43 +08:00
klzgrad fb2392ea89 musl: allocator: Avoid deadlock in pthread_atfork
Musl 1.2.3 and before call malloc() in pthread_atfork(),
which may result in a deadlock:

    PartitionRoot::EnableThreadCacheIfSupported()
      ::partition_alloc::internal::ScopedGuard guard{lock_};
      ThreadCache::Create(this);
        ThreadCache::ThreadCache()
          PlatformThread::CurrentId()
            InitAtFork::InitAtFork()
              pthread_atfork()
                malloc()
                  ShimMalloc()
                    PartitionAllocFunctionsInternal::Malloc()
                      PartitionRoot::AllocInternal()
                        PartitionRoot::AllocInternalNoHooks()
                          PartitionRoot::RawAlloc()
                            ::partition_alloc::internal::ScopedGuard guard{internal::PartitionRootLock(this)};
2026-07-02 22:58:43 +08:00
klzgrad baaacd7d67 musl: allocator: Fix __THROW and mallinfo 2026-07-02 22:58:43 +08:00
klzgrad aeb0911118 musl: base: Fix stack trace printing 2026-07-02 22:58:43 +08:00
klzgrad 4ab3f20512 musl: base: Remove use of mallinfo 2026-07-02 22:58:43 +08:00
klzgrad 33824aa8d7 musl: libc++: Allow setting musl 2026-07-02 22:58:43 +08:00
klzgrad 542ff11fe5 openwrt, windows: Use PartitionAlloc even in Cronet build to remove dependency on glibc 2026-07-02 22:58:43 +08:00
klzgrad 377ce8c76e openwrt: Disable C++ modules support 2026-07-02 22:58:43 +08:00
klzgrad 2129d10bb3 openwrt: third_party: Disable lock-free assert on ARMv5 2026-07-02 22:58:43 +08:00
klzgrad 732f0fd118 openwrt: base: Disable lock-free assert on ARMv6 2026-07-02 22:58:43 +08:00
klzgrad 275362f428 openwrt: third_party/lss: Avoid naming conflict in fstatat64
Supports OpenWrt builds.
2026-07-02 22:58:43 +08:00
klzgrad 222166cc7e openwrt: allocator: Fix recommitted pages not being zeroed when madvise is not available.
Support kernels built without CONFIG_ADVISE_SYSCALLS on small
embedded devices.
2026-07-02 22:58:43 +08:00
klzgrad e04b97bdf5 openwrt: base: Fix broken overloading of libc close in static build 2026-07-02 22:58:42 +08:00
klzgrad b86bdcc14e openwrt: build: Add OpenWrt toolchains 2026-07-02 22:58:42 +08:00
klzgrad 3e4d609c73 loong64: boringssl: Enable support for loong64 2026-07-02 22:58:42 +08:00
klzgrad 468801e7b8 mipsel: base: Disable lockfree assert 2026-07-02 22:58:42 +08:00
klzgrad dc3182d630 mipsel: allocator: Disable musttail compile error 2026-07-02 22:58:42 +08:00
klzgrad 544188ce08 mipsel: allocator: Fix mipsel build config 2026-07-02 22:58:42 +08:00
klzgrad 2df4857228 mipsel: build: Fix -z execstack link error 2026-07-02 22:58:42 +08:00
klzgrad 9b4473b5de mipsel: build: Disable ELF CREL 2026-07-02 22:58:42 +08:00
klzgrad 1d398cd065 mipsel: build: Work around MIPS floating point ABI passing in LTO
Clang reports:

floating point ABI '-mdouble-float' is incompatible with target floating point ABI '-msoft-float'

when -msoft-float is enabled for the architecture.
2026-07-02 22:58:42 +08:00
klzgrad 88badad819 arm: build: Support ARM build without FPU 2026-07-02 22:58:42 +08:00
klzgrad 7059deda3f arm: build: Support -mcpu= on ARM and ARM64 2026-07-02 22:58:42 +08:00
klzgrad 6a5aa9cf68 macos: allocator: Disable double registration check 2026-07-02 22:58:42 +08:00
klzgrad 936f114c70 third_party/perfetto: Add libperfetto when build_with_chromium=false 2026-07-02 22:58:42 +08:00
klzgrad f3be403d7b third_party/brotli: Fix missing import in BUILD.gn
is_ubsan is not declared when imported from net/BUILD.gn
2026-07-02 22:58:42 +08:00
klzgrad b362927248 net: Support preamble headers in ProxyDelegate 2026-07-02 22:58:42 +08:00
klzgrad 0cd612bf78 net/dns: Fix iwyu on win 2026-07-02 22:58:42 +08:00
klzgrad 602d0ba072 net/quic: Support tunnel preamble requests 2026-07-02 22:58:42 +08:00
klzgrad 2a940eb1cb net/quic: Add support for HTTP/3 CONNECT Fast Open
SpdyProxyClientSocket uses read_callback_ for both Connect() and
Read(), and its OnIOComplete() calls read_callback_, thus its fast
connect code checks read_callback_. The code was ported to
QuicProxyClientSocket without much change.

But QuicProxyClientSocket uses a separate connect_callback_ apart from
read_callback_, and its OnIOComplete() calls connect_callback_, thus
when headers are received after Connect() it doesn't need to check
read_callback_ and should always avoid calling connect_callback_.
2026-07-02 22:58:42 +08:00
klzgrad 88db709f1b net/spdy: Pad RST_STREAM frames
Clients sending too many RST_STREAM is an irregular behavior.

Hack in a preceding END_STREAM DATA frame padded towards [48, 72]
before RST_STREAM so that the TLS record looks like a HEADERS frame.

The server often replies to this with a WINDOW_UPDATE because padding
is accounted in flow control. Whether this constitudes a new irregular
behavior is still unclear.
2026-07-02 22:58:42 +08:00
klzgrad 75d65d8efb net/spdy: Support tunnel preamble requests 2026-07-02 22:58:42 +08:00
klzgrad b638911a87 net/spdy: Add support for HTTP/2 CONNECT Fast Open
SpdyProxyClientSocket waits for 200 OK before returning OK for Connect.

Change that behavior to returning OK immediately after CONNECT header.

This feature is enabled by a "fastopen" header via the proxy delegate.

Design notes:

The current approach is better than the obvious TCP Fast Open style fake
Connect().

Fast Open should not be used for preconnects as preconnects need actual
connections set up. The Naive client does not use preconnects per se
(using "...RawConnect") but the user agent will use preconnects and the
Naive client has to infer that. Hence there is a need to check the
incoming socket for available bytes right before Connect() and configure
whether a socket should be connected with Fast Open. But fake Connect()
make it difficult to check the incoming socket because it immediately
returns and there is not enough time for the first read of the incoming
socket to arrive.

To check for preconnects it is best to push the first read of the
incoming socket to as late as possible. The other (wrong) way of doing
that is to pass in an early read callback and call it immediately after
sending HEADERS and then send the available bytes right there. This way
is wrong because it does not work with late binding, which assumes
Connect() is idempotent and causes sockets opened in this way to be
potentially bound to the wrong socket requests.

The current approach is to return OK in Connect() right after sending
HEADERS before getting the reply, which is to be received later. If the
reply is received during a subsequent Read() and the reply indicates an
error, the error is returned to the callback of the Read(); otherwise
the error is ignored with the connection disconnected and subsequent
Read() and Write() should discover the disconnection.
2026-07-02 22:58:42 +08:00
klzgrad 019f9c47d9 net/spdy: Reduce warnings about RST on invalid streams
Per RFC 7540#6.4:

  However, after sending the RST_STREAM, the sending endpoint MUST be
  prepared to receive and process additional frames sent on the stream
  that might have been sent by the peer prior to the arrival of the
  RST_STREAM.
2026-07-02 22:58:42 +08:00
klzgrad 57158a2bc4 net: Allow http proxies in proxy chains 2026-07-02 22:58:42 +08:00
klzgrad 2bf0103592 net/socket: Use SO_REUSEPORT for server sockets 2026-07-02 22:58:42 +08:00