Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

🐛 QUIC Hijack() skips the status-written check that HTTP/2 enforces

未关闭 适合新手
#1,747 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 4 天内回复

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
78/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
go

调研方向

Compare http2RespWriter.Hijack in connection/http2.go with httpResponseAdapter.Hijack in connection/quic_connection.go, focusing on statusWritten and connectResponseSent. Reproduce the differing behavior with the described HTTP/2 and QUIC protocols, then verify that QUIC enforces the same precondition and no longer permits raw writes before a connect response is sent.

由索引模型根据 Issue 内容生成。

描述

Priority: Normal Type: Bug

Describe the bug

Hijack() has different preconditions on the two transports.

HTTP/2, http2RespWriter.Hijack in connection/http2.go, refuses when no status was written yet:

if !rp.statusWritten {
	return nil, nil, fmt.Errorf("status not yet written before attempting to hijack connection")
}

QUIC, httpResponseAdapter.Hijack in connection/quic_connection.go, has no such check. It always returns a localProxyConnection, even when connectResponseSent is still false, so the caller can write raw bytes to the stream before any connect response went out.

Same caller, different outcome depending on the transport: on HTTP/2 it gets an error, on QUIC it gets a conn.

To Reproduce

Stock cloudflared writes the status before it hijacks, so the built-in ingress path does not hit this. I hit it in a fork that replaces the OriginProxy, with code that hijacks first. net/http/httputil.ReverseProxy does exactly that on a 101: handleUpgradeResponse calls Hijack() and then writes the status line onto the conn itself.

  1. ProxyHTTP serves the request through httputil.ReverseProxy to a backend that answers 101.
  2. With --protocol http2, Hijack fails and the client gets a 502.
  3. With --protocol quic, Hijack succeeds and the caller can write to the stream before any connect response was sent.

Expected behavior

Both transports enforce the same precondition. The HTTP/2 check looks like the right one, so QUIC could refuse the same way while connectResponseSent is false.

Environment and versions

  • OS: Linux
  • Architecture: AMD64
  • Version: 2026.9.1, and the Hijack bodies are unchanged on master as of 2026.9.3

Logs and errors

HTTP/2: status not yet written before attempting to hijack connection. QUIC: no error.

Additional context

I worked around it on my side, so it does not block me. Filing it because the two transports disagree on the ResponseWriter contract, and that is easy to miss.

主要语言
Go
星标
15.8k
派生
1.4k
PR 合并指标
30 天内没有已合并 PR

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

cloudflare/cloudflared 的其他 Issue

查看 cloudflare/cloudflared 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。