Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

🐛 QUIC Hijack() skips the status-written check that HTTP/2 enforces

Đang mở Phù hợp với người mới
#1,747 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 4 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
78/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
go
Lĩnh vực
backend, networking

Hướng nghiên cứu

Compare http2RespWriter.Hijack in connection/http2.go with httpResponseAdapter.Hijack in connection/quic_connection.go, focusing on statusWritten and connectResponseSent. Reproduce the differing behavior with the described HTTP/2 and QUIC protocols, then verify that QUIC enforces the same precondition and no longer permits raw writes before a connect response is sent.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Priority: Normal Type: Bug

Describe the bug

Hijack() has different preconditions on the two transports.

HTTP/2, http2RespWriter.Hijack in connection/http2.go, refuses when no status was written yet:

if !rp.statusWritten {
	return nil, nil, fmt.Errorf("status not yet written before attempting to hijack connection")
}

QUIC, httpResponseAdapter.Hijack in connection/quic_connection.go, has no such check. It always returns a localProxyConnection, even when connectResponseSent is still false, so the caller can write raw bytes to the stream before any connect response went out.

Same caller, different outcome depending on the transport: on HTTP/2 it gets an error, on QUIC it gets a conn.

To Reproduce

Stock cloudflared writes the status before it hijacks, so the built-in ingress path does not hit this. I hit it in a fork that replaces the OriginProxy, with code that hijacks first. net/http/httputil.ReverseProxy does exactly that on a 101: handleUpgradeResponse calls Hijack() and then writes the status line onto the conn itself.

  1. ProxyHTTP serves the request through httputil.ReverseProxy to a backend that answers 101.
  2. With --protocol http2, Hijack fails and the client gets a 502.
  3. With --protocol quic, Hijack succeeds and the caller can write to the stream before any connect response was sent.

Expected behavior

Both transports enforce the same precondition. The HTTP/2 check looks like the right one, so QUIC could refuse the same way while connectResponseSent is false.

Environment and versions

  • OS: Linux
  • Architecture: AMD64
  • Version: 2026.9.1, and the Hijack bodies are unchanged on master as of 2026.9.3

Logs and errors

HTTP/2: status not yet written before attempting to hijack connection. QUIC: no error.

Additional context

I worked around it on my side, so it does not block me. Filing it because the two transports disagree on the ResponseWriter contract, and that is easy to miss.

Ngôn ngữ chính
Go
Star
15.8k
Fork
1.4k
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của cloudflare/cloudflared

Tất cả issue của cloudflare/cloudflared

Issue tương tự

Thêm issue về Go

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.