🐛 QUIC Hijack() skips the status-written check that HTTP/2 enforces
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- go
- Lĩnh vực
- backend, networking
Hướng nghiên cứu
Bắt đầu bằng cách so sánh http2RespWriter.Hijack trong connection/http2.go với httpResponseAdapter.Hijack trong connection/quic_connection.go, tập trung vào statusWritten và connectResponseSent. Tái hiện sự khác biệt với các giao thức HTTP/2 và QUIC cùng một backend trả về 101. Công việc được hoàn tất khi cả hai transport đều từ chối Hijack trước khi response của chúng được gửi và duy trì hành vi nhất quán.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Describe the bug
Hijack() has different preconditions on the two transports.
HTTP/2, http2RespWriter.Hijack in connection/http2.go, refuses when no status was written yet:
if !rp.statusWritten {
return nil, nil, fmt.Errorf("status not yet written before attempting to hijack connection")
}
QUIC, httpResponseAdapter.Hijack in connection/quic_connection.go, has no such check. It always returns a localProxyConnection, even when connectResponseSent is still false, so the caller can write raw bytes to the stream before any connect response went out.
Same caller, different outcome depending on the transport: on HTTP/2 it gets an error, on QUIC it gets a conn.
To Reproduce
Stock cloudflared writes the status before it hijacks, so the built-in ingress path does not hit this. I hit it in a fork that replaces the OriginProxy, with code that hijacks first. net/http/httputil.ReverseProxy does exactly that on a 101: handleUpgradeResponse calls Hijack() and then writes the status line onto the conn itself.
ProxyHTTPserves the request throughhttputil.ReverseProxyto a backend that answers 101.- With
--protocol http2,Hijackfails and the client gets a 502. - With
--protocol quic,Hijacksucceeds and the caller can write to the stream before any connect response was sent.
Expected behavior
Both transports enforce the same precondition. The HTTP/2 check looks like the right one, so QUIC could refuse the same way while connectResponseSent is false.
Environment and versions
- OS: Linux
- Architecture: AMD64
- Version: 2026.9.1, and the
Hijackbodies are unchanged on master as of 2026.9.3
Logs and errors
HTTP/2: status not yet written before attempting to hijack connection. QUIC: no error.
Additional context
I worked around it on my side, so it does not block me. Filing it because the two transports disagree on the ResponseWriter contract, and that is easy to miss.
- Ngôn ngữ chính
- Go
- Star
- 16k
- Fork
- 1.5k
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Có Dockerfile hoặc tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của cloudflare/cloudflared
-
Priority: Normal Type: Bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
cloudflare/cloudflared#1747 ·
-
bug(ingress): host matching is case-sensitive, mixed-case Host/hostname misroutes (RFC 4343)Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
cloudflare/cloudflared#1715 ·
-
Priority: Normal Type: Feature Request
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
cloudflare/cloudflared#1645 · 3 reaction ·
-
Priority: Normal Type: Bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 68/100
cloudflare/cloudflared#1609 · 1 reaction ·
-
Priority: Normal Type: Bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 68/100
cloudflare/cloudflared#1348 · 6 reaction ·
Tất cả issue của cloudflare/cloudflared
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 90/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
NVIDIA/k8s-device-plugin#2076 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
agentic-workflows
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
-
area/release kind/bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
kubernetes-sigs/kueue#16455 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày