🐛 QUIC Hijack() skips the status-written check that HTTP/2 enforces
维护者通常 4 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 78/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- go
- 领域
- backend, networking
调研方向
首先比较 connection/http2.go 中的 http2RespWriter.Hijack 与 connection/quic_connection.go 中的 httpResponseAdapter.Hijack,重点关注 statusWritten 和 connectResponseSent。使用 HTTP/2 和 QUIC 协议以及返回 101 的后端重现这一差异。当两个传输都在其响应发送之前拒绝 Hijack,并保持一致的行为时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
Describe the bug
Hijack() has different preconditions on the two transports.
HTTP/2, http2RespWriter.Hijack in connection/http2.go, refuses when no status was written yet:
if !rp.statusWritten {
return nil, nil, fmt.Errorf("status not yet written before attempting to hijack connection")
}
QUIC, httpResponseAdapter.Hijack in connection/quic_connection.go, has no such check. It always returns a localProxyConnection, even when connectResponseSent is still false, so the caller can write raw bytes to the stream before any connect response went out.
Same caller, different outcome depending on the transport: on HTTP/2 it gets an error, on QUIC it gets a conn.
To Reproduce
Stock cloudflared writes the status before it hijacks, so the built-in ingress path does not hit this. I hit it in a fork that replaces the OriginProxy, with code that hijacks first. net/http/httputil.ReverseProxy does exactly that on a 101: handleUpgradeResponse calls Hijack() and then writes the status line onto the conn itself.
ProxyHTTPserves the request throughhttputil.ReverseProxyto a backend that answers 101.- With
--protocol http2,Hijackfails and the client gets a 502. - With
--protocol quic,Hijacksucceeds and the caller can write to the stream before any connect response was sent.
Expected behavior
Both transports enforce the same precondition. The HTTP/2 check looks like the right one, so QUIC could refuse the same way while connectResponseSent is false.
Environment and versions
- OS: Linux
- Architecture: AMD64
- Version: 2026.9.1, and the
Hijackbodies are unchanged on master as of 2026.9.3
Logs and errors
HTTP/2: status not yet written before attempting to hijack connection. QUIC: no error.
Additional context
I worked around it on my side, so it does not block me. Filing it because the two transports disagree on the ResponseWriter contract, and that is easy to miss.
- 主要语言
- Go
- 星标
- 15.8k
- 派生
- 1.4k
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
cloudflare/cloudflared 的其他 Issue
-
Priority: Normal Type: Bug
难度 2/5 1-3 小时 新手友好度 78/100
cloudflare/cloudflared#1747 ·
维护者通常 4 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
cloudflare/cloudflared#1715 ·
维护者通常 4 天内回复
-
Priority: Normal Type: Feature Request
难度 2/5 1-3 小时 新手友好度 68/100
cloudflare/cloudflared#1645 · 3 个 reaction ·
维护者通常 4 天内回复
-
Priority: Normal Type: Bug
难度 1/5 1 小时以内 新手友好度 68/100
cloudflare/cloudflared#1609 · 1 个 reaction ·
维护者通常 4 天内回复
-
Priority: Normal Type: Bug
难度 1/5 1 小时以内 新手友好度 68/100
cloudflare/cloudflared#1348 · 6 个 reaction ·
维护者通常 4 天内回复
查看 cloudflare/cloudflared 的全部 Issue
相似的 Issue
-
priority: low 🌱 type: enhancement 💅🏼
难度 2/5 半天 新手友好度 84/100
nebari-dev/llm-serving-pack#199 ·
维护者通常 3 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 78/100
-
area/helm kind/bug priority/backlog triage/accepted
难度 2/5 1-3 小时 新手友好度 84/100
lexfrei/cloudflare-tunnel-gateway-controller#889 ·
维护者通常 1 天内回复
-
bug difficulty: beginner documentation good first issue help wanted localization
难度 1/5 1 小时以内 新手友好度 90/100
wavefnd/wave-platform#140 ·
-
compiler/runtime
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复