gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit139fafd8139fafd8tracker#16: short bio (4 lines, click = all), real-data check script, README + STATUSmre139fafd8/plugins/http1/tests/tls-on-plain-port.mjs

3.4 KB

  1. // tls-on-plain-port.mjs — a TLS ClientHello sent to a plain hl:http1 port must be
  2. // closed at once, not held open until the client times out (routger, 2026-09-27:
  3. // Firefox's HTTPS-First tries https:// first on any non-localhost name, so the
  4. // page "loaded forever" instead of falling back to http). Drives the built
  5. // libhttp1.so through the interpreter (tls_on_plain_port.hl), then talks to it
  6. // with raw sockets — this is protocol-shape testing, below what an .hl fixture
  7. // can reach.
  8. import { spawn } from 'node:child_process';
  9. import { connect } from 'node:net';
  10. import { fileURLToPath } from 'node:url';
  11. import { dirname, resolve } from 'node:path';
  12. const HERE = dirname(fileURLToPath(import.meta.url));
  13. const ROOT = resolve(HERE, '../../..');
  14. const BIN = resolve(ROOT, 'native/zig-out/bin/hybriel');
  15. const FIXTURE = resolve(HERE, 'tls_on_plain_port.hl');
  16. const PORT = Number(process.env.HL_TEST_PORT || 14980);
  17. const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
  18. let failed = false;
  19. const fail = (msg) => { console.log('FAIL ' + msg); failed = true; };
  20. const server = spawn(BIN, [FIXTURE], {
  21. env: { ...process.env, HL_TEST_PORT: String(PORT) },
  22. stdio: ['ignore', 'pipe', 'pipe'],
  23. });
  24. let log = '';
  25. server.stdout.on('data', (d) => { log += d; });
  26. server.stderr.on('data', (d) => { log += d; });
  27. let up = false;
  28. for (let i = 0; i < 80; i++) {
  29. try {
  30. const r = await fetch(`http://127.0.0.1:${PORT}/`);
  31. if (r.status === 200) { up = true; break; }
  32. } catch {}
  33. await sleep(250);
  34. }
  35. if (!up) {
  36. console.log('FAIL server did not come up\n' + log.slice(0, 4000));
  37. server.kill('SIGKILL');
  38. process.exit(1);
  39. }
  40. // A TLS 1.2-shaped ClientHello record header: content type 0x16 (handshake),
  41. // version 0x03 0x03, followed by a plausible length and a few handshake bytes.
  42. // The fix only looks at the first two bytes, but this is what a real client
  43. // sends, so the fixture proves it against a realistic prefix.
  44. const clientHello = Buffer.from([
  45. 0x16, 0x03, 0x03, 0x00, 0x2f, // TLS record: handshake, TLS 1.2, length 0x2f
  46. 0x01, 0x00, 0x00, 0x2b, // handshake: ClientHello, length 0x2b
  47. 0x03, 0x03, // client_version 1.2
  48. ...Array(32).fill(0x42), // "random"
  49. ]);
  50. const closedInTime = await new Promise((resolvePromise) => {
  51. const sock = connect(PORT, '127.0.0.1');
  52. const start = Date.now();
  53. let settled = false;
  54. sock.on('connect', () => sock.write(clientHello));
  55. sock.on('close', () => {
  56. if (settled) return;
  57. settled = true;
  58. resolvePromise(Date.now() - start);
  59. });
  60. sock.on('error', () => {}); // ECONNRESET counts as closed
  61. setTimeout(() => {
  62. if (settled) return;
  63. settled = true;
  64. sock.destroy();
  65. resolvePromise(-1); // never closed within the budget
  66. }, 1000);
  67. });
  68. if (closedInTime < 0) {
  69. fail(`TLS ClientHello prefix was NOT closed within 1000ms`);
  70. } else {
  71. console.log(`ClientHello prefix closed in ${closedInTime}ms`);
  72. }
  73. // Plain HTTP on the same port must still answer — the fix must not have
  74. // turned the port TLS-only or broken ordinary requests.
  75. try {
  76. const r = await fetch(`http://127.0.0.1:${PORT}/`);
  77. const body = await r.text();
  78. if (r.status === 200 && body === 'ok') {
  79. console.log('plain HTTP still answers: 200 ok');
  80. } else {
  81. fail(`plain HTTP answered ${r.status} ${JSON.stringify(body)}`);
  82. }
  83. } catch (e) {
  84. fail(`plain HTTP request threw: ${e}`);
  85. }
  86. server.kill('SIGTERM');
  87. await sleep(300);
  88. if (!server.killed) server.kill('SIGKILL');
  89. console.log(failed ? 'FAIL' : 'PASS');
  90. process.exit(failed ? 1 : 0);

Branches

Latest commits

  • 139fafd8tracker#16: short bio (4 lines, click = all), real-data check script, README + STATUSmre
  • 93be9476tracker#16: person pages /person/<slug> with the filmography fetched from TMDB on the first visit (step by step), gatemre
  • 47a3cae6STATUS: mission 053 merge commit idsmre
  • dcc5eecaMerge branch 't14-search'mre
  • 03edc783Merge branch 't15-tvmaze'mre
  • 71b46345tracker#15: numbering check by date or title, placeholder titles in other languages, docs + real-data proofmre
  • 6bb2daf1tracker#13: homepage (tiles, intro, latest movies/shows), /shows, /movies/page/N, /my/movies; lists cached in memorymre
  • b8bd1157tracker#14: README + STATUS (search, real-data numbers, gate, merge notes)mre
  • 65c694a8tracker#14: search — header magnifier, /search/<text> (in-memory word-prefix index over titles + people), Fetch from web (TMDB search/multi, ours left out), Add = import via syncShow; gate +25 checks, real-data scriptmre
  • 34f2c15btracker#15: TVmaze merge in the sync (gaps only: new episodes/seasons, empty titles/air dates; numbering check), fake TVmaze episodes + gatemre
  • cbdc4ea7tracker#12: link icons TMDB/IMDb/TVDB/TVmaze; sync fills missing ids (TVmaze lookup); movies fetched via /movie/mre
  • b105bcd8tracker#11: Hybriel master ff51cf46 (checks no longer vanish), mobile-first styles, carets, follow button, sign-in modal, inverted check, orange castmre
  • 31b758aatracker#10: installable app (manifest, service worker, offline shell), own icon + faviconmre
  • 2fa9d997tracker#9: TMDB sync (followed shows: seasons, episodes, posters), tools/sync-tmdb.hl + daily run 04:00 UTC, fake TMDB in gatemre
  • 49e1f61edeploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • 54070a4etracker#8: /my/unwatched + /my/schedule (301 from old), S01E01, title (year), 1 episode, watched-set lookup (unwatched 15s -> 1s)mre
  • 3251488atracker#7: /my/shows (followed shows, newest follow first, poster, title, last watched SxxEyy); gate can take screenshots (TRACKER_GATE_SHOTS)mre
  • 44b7d9f9tracker#6: /schedule — upcoming episodes of followed shows, soonest firstmre
  • 91c9fc8ctracker#5: /unwatched — unwatched released episodes of followed shows, newest firstmre
  • a97c0295tracker#4: show page /shows/:slug (header, seasons, episodes, watch checks) + tools/relink-episode-seasons.hlmre