🐛 QUIC Hijack() skips the status-written check that HTTP/2 enforces
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 78/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- go
- Área
- backend, networking
Línea de trabajo
Compare http2RespWriter.Hijack in connection/http2.go with httpResponseAdapter.Hijack in connection/quic_connection.go, focusing on statusWritten and connectResponseSent. Reproduce the differing behavior with the described HTTP/2 and QUIC protocols, then verify that QUIC enforces the same precondition and no longer permits raw writes before a connect response is sent.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the bug
Hijack() has different preconditions on the two transports.
HTTP/2, http2RespWriter.Hijack in connection/http2.go, refuses when no status was written yet:
if !rp.statusWritten {
return nil, nil, fmt.Errorf("status not yet written before attempting to hijack connection")
}
QUIC, httpResponseAdapter.Hijack in connection/quic_connection.go, has no such check. It always returns a localProxyConnection, even when connectResponseSent is still false, so the caller can write raw bytes to the stream before any connect response went out.
Same caller, different outcome depending on the transport: on HTTP/2 it gets an error, on QUIC it gets a conn.
To Reproduce
Stock cloudflared writes the status before it hijacks, so the built-in ingress path does not hit this. I hit it in a fork that replaces the OriginProxy, with code that hijacks first. net/http/httputil.ReverseProxy does exactly that on a 101: handleUpgradeResponse calls Hijack() and then writes the status line onto the conn itself.
ProxyHTTPserves the request throughhttputil.ReverseProxyto a backend that answers 101.- With
--protocol http2,Hijackfails and the client gets a 502. - With
--protocol quic,Hijacksucceeds and the caller can write to the stream before any connect response was sent.
Expected behavior
Both transports enforce the same precondition. The HTTP/2 check looks like the right one, so QUIC could refuse the same way while connectResponseSent is false.
Environment and versions
- OS: Linux
- Architecture: AMD64
- Version: 2026.9.1, and the
Hijackbodies are unchanged on master as of 2026.9.3
Logs and errors
HTTP/2: status not yet written before attempting to hijack connection. QUIC: no error.
Additional context
I worked around it on my side, so it does not block me. Filing it because the two transports disagree on the ResponseWriter contract, and that is easy to miss.
- Lenguaje dominante
- Go
- Estrellas
- 15.8k
- Forks
- 1.4k
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de cloudflare/cloudflared
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
cloudflare/cloudflared#1748 ·
-
bug(ingress): host matching is case-sensitive, mixed-case Host/hostname misroutes (RFC 4343)Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
cloudflare/cloudflared#1715 ·
-
Priority: Normal Type: Feature Request
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
cloudflare/cloudflared#1645 · 3 reacciones ·
-
Priority: Normal Type: Bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 68/100
cloudflare/cloudflared#1609 · 1 reacción ·
-
Priority: Normal Type: Bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 68/100
cloudflare/cloudflared#1348 · 6 reacciones ·
Todos los issues de cloudflare/cloudflared
Issues similares
-
bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
open-telemetry/opentelemetry-go-compile-instrumentation#1417 ·
Los mantenedores suelen responder en 2 días
-
agent-research-finding agent-research-recommend chore ready-for-agent
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
jordansmall/spindrift#4068 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Type/Task
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
OpenNSW/nsw-srilanka#537 ·
Los mantenedores suelen responder en 1 día
-
security
Dificultad 2/5 1-2 días Aptitud para principiantes 62/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
Los mantenedores suelen responder en 1 día