🐛 QUIC Hijack() skips the status-written check that HTTP/2 enforces
Maintainer thường phản hồi trong vòng 4 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- go
- Lĩnh vực
- backend, networking
Hướng nghiên cứu
Compare http2RespWriter.Hijack in connection/http2.go with httpResponseAdapter.Hijack in connection/quic_connection.go, focusing on statusWritten and connectResponseSent. Reproduce the differing behavior with the described HTTP/2 and QUIC protocols, then verify that QUIC enforces the same precondition and no longer permits raw writes before a connect response is sent.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Describe the bug
Hijack() has different preconditions on the two transports.
HTTP/2, http2RespWriter.Hijack in connection/http2.go, refuses when no status was written yet:
if !rp.statusWritten {
return nil, nil, fmt.Errorf("status not yet written before attempting to hijack connection")
}
QUIC, httpResponseAdapter.Hijack in connection/quic_connection.go, has no such check. It always returns a localProxyConnection, even when connectResponseSent is still false, so the caller can write raw bytes to the stream before any connect response went out.
Same caller, different outcome depending on the transport: on HTTP/2 it gets an error, on QUIC it gets a conn.
To Reproduce
Stock cloudflared writes the status before it hijacks, so the built-in ingress path does not hit this. I hit it in a fork that replaces the OriginProxy, with code that hijacks first. net/http/httputil.ReverseProxy does exactly that on a 101: handleUpgradeResponse calls Hijack() and then writes the status line onto the conn itself.
ProxyHTTPserves the request throughhttputil.ReverseProxyto a backend that answers 101.- With
--protocol http2,Hijackfails and the client gets a 502. - With
--protocol quic,Hijacksucceeds and the caller can write to the stream before any connect response was sent.
Expected behavior
Both transports enforce the same precondition. The HTTP/2 check looks like the right one, so QUIC could refuse the same way while connectResponseSent is false.
Environment and versions
- OS: Linux
- Architecture: AMD64
- Version: 2026.9.1, and the
Hijackbodies are unchanged on master as of 2026.9.3
Logs and errors
HTTP/2: status not yet written before attempting to hijack connection. QUIC: no error.
Additional context
I worked around it on my side, so it does not block me. Filing it because the two transports disagree on the ResponseWriter contract, and that is easy to miss.
- Ngôn ngữ chính
- Go
- Star
- 15.8k
- Fork
- 1.4k
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của cloudflare/cloudflared
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
cloudflare/cloudflared#1748 ·
Maintainer thường phản hồi trong vòng 4 ngày
-
bug(ingress): host matching is case-sensitive, mixed-case Host/hostname misroutes (RFC 4343)Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
cloudflare/cloudflared#1715 ·
Maintainer thường phản hồi trong vòng 4 ngày
-
Priority: Normal Type: Feature Request
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
cloudflare/cloudflared#1645 · 3 reaction ·
Maintainer thường phản hồi trong vòng 4 ngày
-
Priority: Normal Type: Bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 68/100
cloudflare/cloudflared#1609 · 1 reaction ·
Maintainer thường phản hồi trong vòng 4 ngày
-
Priority: Normal Type: Bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 68/100
cloudflare/cloudflared#1348 · 6 reaction ·
Maintainer thường phản hồi trong vòng 4 ngày
Tất cả issue của cloudflare/cloudflared
Issue tương tự
-
priority: low 🌱 type: enhancement 💅🏼
Độ khó 2/5 Nửa ngày Mức phù hợp với người mới 84/100
nebari-dev/llm-serving-pack#199 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
area/helm kind/bug priority/backlog triage/accepted
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
lexfrei/cloudflare-tunnel-gateway-controller#889 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug difficulty: beginner documentation good first issue help wanted localization
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
wavefnd/wave-platform#140 ·
-
compiler/runtime
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
golang/go#81797 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày