Skip to content

Release 7.0.12-beta - #1052

Merged
justcoding121 merged 64 commits into
betafrom
develop
Sep 26, 2026
Merged

justcoding121 merged 64 commits into
betafrom
develop

Conversation

@justcoding121

Copy link
Copy Markdown
Owner

Summary

  • Promote develop to beta as 7.0.12-beta (patch bump from 7.0.11).
  • Ships Inspector session retention (disk spill / HAR 1.2 / responsive eviction), Excluded-hosts + Logging dialog UX, HTTP/2 MaxConcurrentStreams gated on client SETTINGS ACK, and Actions bumps (checkout v7 / setup-dotnet v6 / upload-artifact v7).
  • Keep Chocolatey/winget skipped (SKIP_CATALOG_PUBLISH=true; no CHOCOLATEY_API_KEY).

Test plan

  • PR checks: .NET / build, ui-portable (3 OS), cli-e2e (3 OS), RPS saturation / rps compare-spot (3 OS), path guard, Sonar OK
  • Merge only when green (resolve conflicts by keeping develop / 7.0.12)
  • After merge: rps-publish-gate + rps-peer-gate green → NuGet 7.0.12-beta, tag v7.0.12-beta, release.yml channel=beta; Chocolatey skipped
  • Download Beta = v7.0.12-beta; Stable remains v7.0.11

dependabot Bot and others added 30 commits September 15, 2026 16:22
Bumps [actions/deploy-pages](https://github.com/actions/deploy-pages) from 4 to 5.
- [Release notes](https://github.com/actions/deploy-pages/releases)
- [Commits](actions/deploy-pages@v4...v5)

---
updated-dependencies:
- dependency-name: actions/deploy-pages
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jehonathan Thomas <jehonathant@gmail.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jehonathan Thomas <jehonathant@gmail.com>
Bumps [azure/login](https://github.com/azure/login) from 2 to 3.
- [Release notes](https://github.com/azure/login/releases)
- [Commits](Azure/login@v2...v3)

---
updated-dependencies:
- dependency-name: azure/login
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jehonathan Thomas <jehonathant@gmail.com>
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v8)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jehonathan Thomas <jehonathant@gmail.com>
Bumps [actions/cache](https://github.com/actions/cache) from 4 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Jehonathan Thomas <jehonathant@gmail.com>
…ddress.

A bad bind left Start stuck because parse ran outside the start-busy finally. Treat * as all IPv4 adapters to match the CLI.
…binds.

Empty fields no longer raise conversion exceptions; * picks an OS port, and invalid input shows a short message.
…CK, GOAWAY safety, h3 atomics

ServerHello delay (original bug):
- Start leaf cert generation and Auto-mode h2 probe concurrently before CONNECT 200
  so both overlap browser RTT instead of stacking on ServerHello
- Re-apply Http2ServerHelloProbeBudget AFTER cert is ready; budget now covers only
  the network RTT portion of the probe, not the local BouncyCastle cert cost
- Speculation comments corrected: cold-start h2 offer is always safe because
  ApplyDeferredHttp2Negotiation activates the h1.1 bridge after TLS completes

RFC 9113 §8.3.1 — HPACK CONNECT re-encode:
- Plain CONNECT (no ExtendedConnectProtocol) must omit :scheme and :path
- Only extended CONNECT and all other methods include :scheme/:path
- Fixes PROTOCOL_ERROR when proxying through an upstream H2 proxy

RFC 9113 §8.3.1 — HPACK :authority:
- Do not encode an empty :authority; omit it and let Host carry the value

GOAWAY CTS safety:
- Remove Cancellation.Dispose() inside GOAWAY stream loop while stream is
  still in connectionState.Streams — fixes ObjectDisposedException on
  concurrent DATA/HEADERS frames for recently-GOAWAY'd stream IDs
- Cancel without disposing; disposal deferred to RemoveAndFinalizeStream

IPv6 :authority host/port split:
- Use AuthorityParser instead of LastIndexOf(':') for RFC 2732 bracket support
  in Http2Helper.Copy.Headers.cs interception predicate

RFC 9113 §6.9.1 — zero WINDOW_UPDATE:
- Http2OriginConnection: increment=0 on stream > 0 is a stream error
  (RST_STREAM PROTOCOL_ERROR), not a connection error — connection keeps running

RFC 8441 advertisement guard:
- Stop injecting ENABLE_CONNECT_PROTOCOL=1 toward the client when the origin
  never sent it; false advertisement always immediately RSTs extended CONNECT

H3 GOAWAY control stream lifecycle:
- Client GOAWAY on control stream: send server GOAWAY and continue draining
  instead of returning (which would close the stream => H3_CLOSED_CRITICAL_STREAM)

H3 GOAWAY stream ID atomicity:
- Replace racy Interlocked.Exchange(Math.Max) with correct CompareExchange loop
- Fix stale comment claiming +4 offset (code never did that)

SslProtocol correctness:
- Transparent path: store sslStream.SslProtocol (negotiated) not SupportedSslProtocols (bitmask)
- Explicit path: update SslProtocol after AuthenticateAsServerAsync with negotiated value

Explicit proxy ClientHello drain:
- Replace single ReadAsync + hard throw with the same drain loop used by
  the transparent handler (tolerates partial reads)

RFC 9110 §6.5.1 — forbidden trailer headers:
- Add 'te' to ForbiddenTrailerHeaders set

Comment/doc accuracy (no behavior change):
- Http2OriginCapabilityCache: key is full connection route, not just host:port
- Http2FlowController: update stale receive-credit strategy description
- Http2Helper.Copy.cs: fix HPACK decoder sizing comment (localSettings vs remoteSettings)
- Http2Helper.Send.cs: add GOAWAY Last-Stream-ID guidance comment (use highest processed)
- Http2Helper.Hpack.cs: add RFC 9113 annotation on plain CONNECT omission
- Http2NegotiationHandler: add comprehensive doc for speculation+bridge invariants
- Http3Connection: fix stale +4 comment, add CAS-loop explanation
- RFC 7540 → RFC 9113 citation updates

Tests:
- Http2_ProbeAlpnRejectedByH1OnlyOrigin_CachesFalseForTtl: align with deliberate
  false-caching behavior for definitive ALPN rejection
- SonarGate coverage bump updated for new code paths
35-issue triage. 12 fixed in d11d03d. This document tracks:
- Re-review checklist for the 12 fixes
- 10 future-hardening items with reproduction steps and fix guidance
- 5 items needing architectural decision before coding
- 4 intentional design choices with rationale
- 3 pre-existing test failures outside this scope
- Prioritised fix order recommendation
…emented

When EnableQpackDynamicTable=true a peer that fills its dynamic table
sends requiredInsertCount > 0 and wire indexes relative to Base.
QpackDecoder was silently looking up the raw wire index as an absolute
table index, which either returns the wrong header value or throws a
misleading not-found exception.

Add a fail-fast guard so the decoder throws Http3ConnectionException
(QpackDecompressionFailed) with a clear diagnostic instead of
producing corrupt headers. Preserve the S-bit and DeltaBase locals
with a TODO comment for the future RFC 9204 Base-relative decoding
implementation.

Update protocol-hardening-backlog.md: reclassify B3-a as future
hardening (not just architectural decision), document the exact RFC
9204 fixes required (Base computation, relative/post-base index
resolution, encoder preamble), and note the fail-fast guard added.
…ertions.

Invalid HTTP/2 padding/PRIORITY framing now throws; update unit coverage to match. Soften HKCU Firefox policy asserts under group-policy lockdown, and disable HTTP/2 in the upstream CONNECT auth test so abandoned ALPN probes do not duplicate NTLM captures.
Add Configuration PublicAPI for Http2RelayValidation (CI warnaserror). Reduce StartCapture cognitive complexity, merge nested preview-image ifs, tighten error enumerator types, and rephrase an UpdateService comment that Sonar treated as commented-out code.
justcoding121 and others added 24 commits September 17, 2026 06:30
…tus.

The assertion raced EndTrustCommand and saw the interim Trusting root CA busy text before the trusted outcome landed.
- ExceptionControlFlowTests: widen TcpConnectionFactory filter to also
  exclude SocketException (Windows WSAEINTR/WSAENOTSOCK from losing
  Happy Eyeballs connect attempt) in addition to OperationCanceledException.
- Add diagnostic capture bag so any future failure prints the exact
  exception type + message + stack trace in the assertion message.
- ConnectionPoolTests, StaleKeepAliveTests: add [DoNotParallelize] to
  prevent AppDomain.FirstChanceException cross-test interference when
  MSTest runs tests at method-level parallelism.
…TrustForDecryptAsync

VerifyOsUserSslTrust is a quick Root-store lookup that was passed
StatusCancelToken.  On macOS the status-revert timer fires on a
background thread and calls CancelStatusRevert(), which cancels the
CancellationTokenSource.  If the test (or a concurrent status change)
reads StatusCancelToken at that exact moment, Task.Run gets an already-
cancelled token and throws TaskCanceledException — manifesting as the
flaky Inspector-Trust-Decision CI failure on macos-latest.

The _decryptEnableGeneration counter in EnableDecryptHttpsAsync already
provides the correct abort signal for superseded enable requests, so the
status-revert cancellation is both redundant and racy here.  Switch to
CancellationToken.None so the trust check always runs to completion.
RotateCa_SecondImmediateYes raced EndTrustCommand: IsRootTrusted can
flip true while _trustCommandBusy is still held, so the second Execute
was rejected and timed out — blocking release.yml publish-release and
the Download Beta refresh after 7.0.11-beta NuGet already published.

Also replace fixed Delay(20) in Decrypt_WhileTrustBusy and require
TrustGateIdle on other chained trust commands.
…), and rename the learned-host button to Promote to not decrypted hosts.
…ry limit, and clearer missing-body UX.

Keep headers in memory under MaxSessions; always spill finished bodies; batch grid updates; prune disk by size; explain pruned bodies in Inspect; and drop the retention dialog intro.
… and fix Size vs Inspect honesty.

Archive finished sessions as HAR-like JSON under an independent disk budget, wait for a status before spill, show CONNECT wire Size without pretending it is an HTTP body, and use max(request, response) for the Size column.
…aks.

Unload upstream/gRPC/protobuf after spill, re-clear late body reattach, drop Inspect UI copies when changing selection, always remove CONNECT from the live map, and add soak/memory-probe coverage.
Reuse the same format for Import/Export HAR (including multi-select), so disk-cache files open as standard HARs without losing Inspector-only fields.
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3 to 4.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v3...v4)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact) from 3 to 5.
- [Release notes](https://github.com/actions/upload-pages-artifact/releases)
- [Commits](actions/upload-pages-artifact@v3...v5)

---
updated-dependencies:
- dependency-name: actions/upload-pages-artifact
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 5 to 6.
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-dotnet
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Avoids session-id collisions across Inspector restarts while keeping prior runs importable and pruning oldest HARs across all runs under the disk budget.
* chore(deps): bump actions/checkout from 4 to 7

Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* Wait for the decrypted HTTPS URL before asserting the happy-path session.

CONNECT is published as host:port first, so a count check races the request row.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: justcoding121 <justcoding121@users.noreply.github.com>
…st MaxSessionsInMemory.

Eviction now only enqueues a spill when bodies are still in RAM, and load/flush waits cover large spill backlogs instead of falsely marking bodies missing.
Stops refusing streams before the browser has applied SETTINGS (RFC 9113), demotes expected capacity refuses to Debug, and documents the retry-vs-admission error model.
@sonarqubecloud

Copy link
Copy Markdown

This branch was successfully deployed

1 active deployment
github-pages — 2c076303 Deployed Sep 26, 2026 by github-actions[bot] via deploy #495
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant