Release 7.0.11-beta - #1044
Merged
Merged
Release 7.0.11-beta#1044
Conversation
Bumps [actions/deploy-pages](https://github.com/actions/deploy-pages) from 4 to 5. - [Release notes](https://github.com/actions/deploy-pages/releases) - [Commits](actions/deploy-pages@v4...v5) --- updated-dependencies: - dependency-name: actions/deploy-pages dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jehonathan Thomas <jehonathant@gmail.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v4...v7) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jehonathan Thomas <jehonathant@gmail.com>
Bumps [azure/login](https://github.com/azure/login) from 2 to 3. - [Release notes](https://github.com/azure/login/releases) - [Commits](Azure/login@v2...v3) --- updated-dependencies: - dependency-name: azure/login dependency-version: '3' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jehonathan Thomas <jehonathant@gmail.com>
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v8) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jehonathan Thomas <jehonathant@gmail.com>
Bumps [actions/cache](https://github.com/actions/cache) from 4 to 6. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v4...v6) --- updated-dependencies: - dependency-name: actions/cache dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jehonathan Thomas <jehonathant@gmail.com>
…ddress. A bad bind left Start stuck because parse ran outside the start-busy finally. Treat * as all IPv4 adapters to match the CLI.
…binds. Empty fields no longer raise conversion exceptions; * picks an OS port, and invalid input shows a short message.
…CK, GOAWAY safety, h3 atomics
ServerHello delay (original bug):
- Start leaf cert generation and Auto-mode h2 probe concurrently before CONNECT 200
so both overlap browser RTT instead of stacking on ServerHello
- Re-apply Http2ServerHelloProbeBudget AFTER cert is ready; budget now covers only
the network RTT portion of the probe, not the local BouncyCastle cert cost
- Speculation comments corrected: cold-start h2 offer is always safe because
ApplyDeferredHttp2Negotiation activates the h1.1 bridge after TLS completes
RFC 9113 §8.3.1 — HPACK CONNECT re-encode:
- Plain CONNECT (no ExtendedConnectProtocol) must omit :scheme and :path
- Only extended CONNECT and all other methods include :scheme/:path
- Fixes PROTOCOL_ERROR when proxying through an upstream H2 proxy
RFC 9113 §8.3.1 — HPACK :authority:
- Do not encode an empty :authority; omit it and let Host carry the value
GOAWAY CTS safety:
- Remove Cancellation.Dispose() inside GOAWAY stream loop while stream is
still in connectionState.Streams — fixes ObjectDisposedException on
concurrent DATA/HEADERS frames for recently-GOAWAY'd stream IDs
- Cancel without disposing; disposal deferred to RemoveAndFinalizeStream
IPv6 :authority host/port split:
- Use AuthorityParser instead of LastIndexOf(':') for RFC 2732 bracket support
in Http2Helper.Copy.Headers.cs interception predicate
RFC 9113 §6.9.1 — zero WINDOW_UPDATE:
- Http2OriginConnection: increment=0 on stream > 0 is a stream error
(RST_STREAM PROTOCOL_ERROR), not a connection error — connection keeps running
RFC 8441 advertisement guard:
- Stop injecting ENABLE_CONNECT_PROTOCOL=1 toward the client when the origin
never sent it; false advertisement always immediately RSTs extended CONNECT
H3 GOAWAY control stream lifecycle:
- Client GOAWAY on control stream: send server GOAWAY and continue draining
instead of returning (which would close the stream => H3_CLOSED_CRITICAL_STREAM)
H3 GOAWAY stream ID atomicity:
- Replace racy Interlocked.Exchange(Math.Max) with correct CompareExchange loop
- Fix stale comment claiming +4 offset (code never did that)
SslProtocol correctness:
- Transparent path: store sslStream.SslProtocol (negotiated) not SupportedSslProtocols (bitmask)
- Explicit path: update SslProtocol after AuthenticateAsServerAsync with negotiated value
Explicit proxy ClientHello drain:
- Replace single ReadAsync + hard throw with the same drain loop used by
the transparent handler (tolerates partial reads)
RFC 9110 §6.5.1 — forbidden trailer headers:
- Add 'te' to ForbiddenTrailerHeaders set
Comment/doc accuracy (no behavior change):
- Http2OriginCapabilityCache: key is full connection route, not just host:port
- Http2FlowController: update stale receive-credit strategy description
- Http2Helper.Copy.cs: fix HPACK decoder sizing comment (localSettings vs remoteSettings)
- Http2Helper.Send.cs: add GOAWAY Last-Stream-ID guidance comment (use highest processed)
- Http2Helper.Hpack.cs: add RFC 9113 annotation on plain CONNECT omission
- Http2NegotiationHandler: add comprehensive doc for speculation+bridge invariants
- Http3Connection: fix stale +4 comment, add CAS-loop explanation
- RFC 7540 → RFC 9113 citation updates
Tests:
- Http2_ProbeAlpnRejectedByH1OnlyOrigin_CachesFalseForTtl: align with deliberate
false-caching behavior for definitive ALPN rejection
- SonarGate coverage bump updated for new code paths
35-issue triage. 12 fixed in d11d03d. This document tracks: - Re-review checklist for the 12 fixes - 10 future-hardening items with reproduction steps and fix guidance - 5 items needing architectural decision before coding - 4 intentional design choices with rationale - 3 pre-existing test failures outside this scope - Prioritised fix order recommendation
…emented When EnableQpackDynamicTable=true a peer that fills its dynamic table sends requiredInsertCount > 0 and wire indexes relative to Base. QpackDecoder was silently looking up the raw wire index as an absolute table index, which either returns the wrong header value or throws a misleading not-found exception. Add a fail-fast guard so the decoder throws Http3ConnectionException (QpackDecompressionFailed) with a clear diagnostic instead of producing corrupt headers. Preserve the S-bit and DeltaBase locals with a TODO comment for the future RFC 9204 Base-relative decoding implementation. Update protocol-hardening-backlog.md: reclassify B3-a as future hardening (not just architectural decision), document the exact RFC 9204 fixes required (Base computation, relative/post-base index resolution, encoder preamble), and note the fail-fast guard added.
…ll 35 findings resolved
…dation on the relay path
… add Observe and Enforce handling
…nc-context deadlocks
…he wrong frame type
…ertions. Invalid HTTP/2 padding/PRIORITY framing now throws; update unit coverage to match. Soften HKCU Firefox policy asserts under group-policy lockdown, and disable HTTP/2 in the upstream CONNECT auth test so abandoned ALPN probes do not duplicate NTLM captures.
Add Configuration PublicAPI for Http2RelayValidation (CI warnaserror). Reduce StartCapture cognitive complexity, merge nested preview-image ifs, tighten error enumerator types, and rephrase an UpdateService comment that Sonar treated as commented-out code.
Pass session cancellation into the cert-validation Task.Run, share the DATA padding PROTOCOL_ERROR string, and split streamed H3 response writes so SendResponseAsync stays under the complexity cap.
Passing sessionArgs.CancellationToken into Task.Run satisfied S8949 but raised first-chance OperationCanceledException on keep-alive Happy Path integration. Use CancellationToken.None with an explicit opt-out rationale instead.
Paste product, heavier, gRPC, and WebSocket tables from the completed sharded GHA runs (including mac-retries), regenerate practical charts, and surface the macOS 64 KB chart on the website.
Raise y-axis headroom when tall right-side bars sit under the product legend, and restore natural H1→H2→H3 heavier cluster order.
Update behind-YARP / heavier / lossy / arch / TLS summary lines that still cited the prior band, fix duplicated Windows peer-omission notes, and make the heavier paste strip stale notes on re-run.
Align AssemblyInfo, CLI E2E asserts, and packaging stubs with VersionPrefix so the beta and stable identity match.
…verage. PR new-code coverage was blocked by ProcessCompleteHeaderBlock / Quic trailer paths that need a full protocol harness; align exclusions with existing bridge seams and unit-test EnforceHttp2RelayHeaderSemantics.
…tus. The assertion raced EndTrustCommand and saw the interim Trusting root CA busy text before the trusted outcome landed.
- ExceptionControlFlowTests: widen TcpConnectionFactory filter to also exclude SocketException (Windows WSAEINTR/WSAENOTSOCK from losing Happy Eyeballs connect attempt) in addition to OperationCanceledException. - Add diagnostic capture bag so any future failure prints the exact exception type + message + stack trace in the assertion message. - ConnectionPoolTests, StaleKeepAliveTests: add [DoNotParallelize] to prevent AppDomain.FirstChanceException cross-test interference when MSTest runs tests at method-level parallelism.
…TrustForDecryptAsync VerifyOsUserSslTrust is a quick Root-store lookup that was passed StatusCancelToken. On macOS the status-revert timer fires on a background thread and calls CancelStatusRevert(), which cancels the CancellationTokenSource. If the test (or a concurrent status change) reads StatusCancelToken at that exact moment, Task.Run gets an already- cancelled token and throws TaskCanceledException — manifesting as the flaky Inspector-Trust-Decision CI failure on macos-latest. The _decryptEnableGeneration counter in EnableDecryptHttpsAsync already provides the correct abort signal for superseded enable requests, so the status-revert cancellation is both redundant and racy here. Switch to CancellationToken.None so the trust check always runs to completion.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
developtip tobetafor v7.0.11-beta.CHOCOLATEY_API_KEYunset / catalog hold).Test plan
.NETbuild + ui-portable + cli-e2e (3 OS) greenrps-publish-gate+rps-peer-gategreen → NuGet7.0.11-beta+v7.0.11-beta