🐛 QUIC Hijack() skips the status-written check that HTTP/2 enforces
Los mantenedores suelen responder en 4 días
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 78/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- go
- Área
- backend, networking
Línea de trabajo
Comienza comparando http2RespWriter.Hijack en connection/http2.go con httpResponseAdapter.Hijack en connection/quic_connection.go, centrándote en statusWritten y connectResponseSent. Reproduce la diferencia con los protocolos HTTP/2 y QUIC y un backend que devuelva 101. Se considera terminado cuando ambos transportes rechacen Hijack antes de que se haya enviado su respuesta y mantengan un comportamiento coherente.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the bug
Hijack() has different preconditions on the two transports.
HTTP/2, http2RespWriter.Hijack in connection/http2.go, refuses when no status was written yet:
if !rp.statusWritten {
return nil, nil, fmt.Errorf("status not yet written before attempting to hijack connection")
}
QUIC, httpResponseAdapter.Hijack in connection/quic_connection.go, has no such check. It always returns a localProxyConnection, even when connectResponseSent is still false, so the caller can write raw bytes to the stream before any connect response went out.
Same caller, different outcome depending on the transport: on HTTP/2 it gets an error, on QUIC it gets a conn.
To Reproduce
Stock cloudflared writes the status before it hijacks, so the built-in ingress path does not hit this. I hit it in a fork that replaces the OriginProxy, with code that hijacks first. net/http/httputil.ReverseProxy does exactly that on a 101: handleUpgradeResponse calls Hijack() and then writes the status line onto the conn itself.
ProxyHTTPserves the request throughhttputil.ReverseProxyto a backend that answers 101.- With
--protocol http2,Hijackfails and the client gets a 502. - With
--protocol quic,Hijacksucceeds and the caller can write to the stream before any connect response was sent.
Expected behavior
Both transports enforce the same precondition. The HTTP/2 check looks like the right one, so QUIC could refuse the same way while connectResponseSent is false.
Environment and versions
- OS: Linux
- Architecture: AMD64
- Version: 2026.9.1, and the
Hijackbodies are unchanged on master as of 2026.9.3
Logs and errors
HTTP/2: status not yet written before attempting to hijack connection. QUIC: no error.
Additional context
I worked around it on my side, so it does not block me. Filing it because the two transports disagree on the ResponseWriter contract, and that is easy to miss.
- Lenguaje dominante
- Go
- Estrellas
- 15.8k
- Forks
- 1.4k
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de cloudflare/cloudflared
-
Priority: Normal Type: Bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
cloudflare/cloudflared#1747 ·
Los mantenedores suelen responder en 4 días
-
bug(ingress): host matching is case-sensitive, mixed-case Host/hostname misroutes (RFC 4343)Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
cloudflare/cloudflared#1715 ·
Los mantenedores suelen responder en 4 días
-
Priority: Normal Type: Feature Request
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
cloudflare/cloudflared#1645 · 3 reacciones ·
Los mantenedores suelen responder en 4 días
-
Priority: Normal Type: Bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 68/100
cloudflare/cloudflared#1609 · 1 reacción ·
Los mantenedores suelen responder en 4 días
-
Priority: Normal Type: Bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 68/100
cloudflare/cloudflared#1348 · 6 reacciones ·
Los mantenedores suelen responder en 4 días
Todos los issues de cloudflare/cloudflared
Issues similares
-
bug needs-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
DataDog/dd-trace-go#5469 ·
Los mantenedores suelen responder en 1 día
-
bug tests
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
l3montree-dev/devguard#3101 ·
Los mantenedores suelen responder en 1 día
-
area:*of bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
oapi-codegen/oapi-codegen#2593 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
DaoCloud/DaoCloud-docs#7432 ·
Los mantenedores suelen responder en 1 día