HTTP CONNECT proxy tunnel has lax response parsing and loses early data
Los mantenedores suelen responder en 2 días
@heitzlki ya está trabajando en esto.
Desde el 11/9/2026.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 48/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- rust
- Área
- networking
Línea de trabajo
Comienza en src/client/legacy/connect/proxy/tunnel.rs, en el procesamiento de la respuesta CONNECT, y después lee la estructura privada Rewind en src/common/rewind.rs para entender el contexto del almacenamiento en búfer. Revisa la handshake API y determina cómo deberían representarse el análisis estricto de las respuestas y los datos iniciales retenidos; la tarea estará terminada cuando se rechacen las respuestas malformadas y los datos del servidor de destino se conserven después de establecer el túnel.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Version
hyper-util 0.1.20
Platform
Linux 6.18.14
Summary
While evaluating hyper-util's client::legacy::connect::proxy::tunnel for use with gRPC routing over HTTP CONNECT proxies, I identified two limitations in the current handshake implementation.
1. Lax Response Parsing
It heuristically matches the start and end of the expected response, potentially accepting malformed responses.
This can be fixed by using httparse to properly parse the response.
2. No Buffering for Early Data
It assumes the read buffer contains no data from the target server immediately after the proxy's response. This assumption holds for protocols where the client always speaks first (e.g., TLS) after the tunnel is established. However, since gRPC implementations must work with any security protocol, they must handle cases where the server sends data immediately.
Fixing this would require an API change, as the returned I/O stream would need to incorporate a buffer for the peeked data, similar to the private Rewind struct.
Although the handshaking code is simple enough to be re-implemented in gRPC, I wanted to check if these fixes can be upstreamed to allow us to use hyper-util.
Code Sample
Expected Behavior
- The proxy response must be correctly parsed.
- The data from the target server must be retained.
Actual Behavior
- A malformed proxy response may be accepted
- The data from the target server may be lost.
Additional Context
No response
- Lenguaje dominante
- Rust
- Estrellas
- 16.3k
- Forks
- 1.8k
- Merge medio
- 4 d 13 h
- PR fusionados (30 d)
- 21
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de hyperium/hyper
-
Publicly reexport the http crateAbiertoC-feature
Dificultad 1/5 Menos de una hora Aptitud para principiantes 65/100
hyperium/hyper#2652 · 4 reacciones ·
Los mantenedores suelen responder en 2 días
-
Write a HIP for `Body::poll_progress()`Posiblemente ocupada @cratelyn la tomó hace 2 días. AbiertoA-body B-rfc C-feature
hyperium/hyper#4228 · 1 asignado ·
Los mantenedores suelen responder en 2 días
-
Dificultad 3/5 1-2 días Aptitud para principiantes 74/100
hyperium/hyper#4211 · 1 comentario ·
Los mantenedores suelen responder en 2 días
-
Upgraded HTTP/2 CONNECT streams cannot be reset, so a failed tunnel looks like a clean closePosiblemente ocupada @jeremyjpj0916 la tomó hace 12 días. Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 55/100
Los mantenedores suelen responder en 2 días
-
Allow connection pools to stop reusing an HTTP/2 connection before its keep-alive timeoutPosiblemente ocupada @jiahaoliang la tomó hace 30 días. AbiertoC-feature
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
hyperium/hyper#4186 · 2 comentarios ·
Los mantenedores suelen responder en 2 días
Todos los issues de hyperium/hyper
Issues similares
-
bug user-priority/P2
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
t8y2/dbx#11718 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
rescript-lang/rescript#8765 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
nautechsystems/nautilus_trader#5287 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
farion1231/cc-switch#8072 ·
Los mantenedores suelen responder en 1 día
-
Python 3.15 supportPosiblemente ocupada @amnesiaof la tomó hoy. AbiertoL: python L: python:uv
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
dependabot/dependabot-core#16524 · 1 comentario ·
Los mantenedores suelen responder en 1 día