gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commitb638e99db638e99dMerge t38 (tracker#38 pagination, #35 Returning/Airing label) into main: LOG/STATUS keep both sides; pager gate follows #37's /people (everyone, last updated first: seed updatedAt); gates pager 229/0, browser 374/0mreb638e99d/plugins/http1/tests/tls-on-plain-port.mjs

3.4 KB

  1. // tls-on-plain-port.mjs — a TLS ClientHello sent to a plain hl:http1 port must be
  2. // closed at once, not held open until the client times out (routger, 2026-09-27:
  3. // Firefox's HTTPS-First tries https:// first on any non-localhost name, so the
  4. // page "loaded forever" instead of falling back to http). Drives the built
  5. // libhttp1.so through the interpreter (tls_on_plain_port.hl), then talks to it
  6. // with raw sockets — this is protocol-shape testing, below what an .hl fixture
  7. // can reach.
  8. import { spawn } from 'node:child_process';
  9. import { connect } from 'node:net';
  10. import { fileURLToPath } from 'node:url';
  11. import { dirname, resolve } from 'node:path';
  12. const HERE = dirname(fileURLToPath(import.meta.url));
  13. const ROOT = resolve(HERE, '../../..');
  14. const BIN = resolve(ROOT, 'native/zig-out/bin/hybriel');
  15. const FIXTURE = resolve(HERE, 'tls_on_plain_port.hl');
  16. const PORT = Number(process.env.HL_TEST_PORT || 14980);
  17. const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
  18. let failed = false;
  19. const fail = (msg) => { console.log('FAIL ' + msg); failed = true; };
  20. const server = spawn(BIN, [FIXTURE], {
  21. env: { ...process.env, HL_TEST_PORT: String(PORT) },
  22. stdio: ['ignore', 'pipe', 'pipe'],
  23. });
  24. let log = '';
  25. server.stdout.on('data', (d) => { log += d; });
  26. server.stderr.on('data', (d) => { log += d; });
  27. let up = false;
  28. for (let i = 0; i < 80; i++) {
  29. try {
  30. const r = await fetch(`http://127.0.0.1:${PORT}/`);
  31. if (r.status === 200) { up = true; break; }
  32. } catch {}
  33. await sleep(250);
  34. }
  35. if (!up) {
  36. console.log('FAIL server did not come up\n' + log.slice(0, 4000));
  37. server.kill('SIGKILL');
  38. process.exit(1);
  39. }
  40. // A TLS 1.2-shaped ClientHello record header: content type 0x16 (handshake),
  41. // version 0x03 0x03, followed by a plausible length and a few handshake bytes.
  42. // The fix only looks at the first two bytes, but this is what a real client
  43. // sends, so the fixture proves it against a realistic prefix.
  44. const clientHello = Buffer.from([
  45. 0x16, 0x03, 0x03, 0x00, 0x2f, // TLS record: handshake, TLS 1.2, length 0x2f
  46. 0x01, 0x00, 0x00, 0x2b, // handshake: ClientHello, length 0x2b
  47. 0x03, 0x03, // client_version 1.2
  48. ...Array(32).fill(0x42), // "random"
  49. ]);
  50. const closedInTime = await new Promise((resolvePromise) => {
  51. const sock = connect(PORT, '127.0.0.1');
  52. const start = Date.now();
  53. let settled = false;
  54. sock.on('connect', () => sock.write(clientHello));
  55. sock.on('close', () => {
  56. if (settled) return;
  57. settled = true;
  58. resolvePromise(Date.now() - start);
  59. });
  60. sock.on('error', () => {}); // ECONNRESET counts as closed
  61. setTimeout(() => {
  62. if (settled) return;
  63. settled = true;
  64. sock.destroy();
  65. resolvePromise(-1); // never closed within the budget
  66. }, 1000);
  67. });
  68. if (closedInTime < 0) {
  69. fail(`TLS ClientHello prefix was NOT closed within 1000ms`);
  70. } else {
  71. console.log(`ClientHello prefix closed in ${closedInTime}ms`);
  72. }
  73. // Plain HTTP on the same port must still answer — the fix must not have
  74. // turned the port TLS-only or broken ordinary requests.
  75. try {
  76. const r = await fetch(`http://127.0.0.1:${PORT}/`);
  77. const body = await r.text();
  78. if (r.status === 200 && body === 'ok') {
  79. console.log('plain HTTP still answers: 200 ok');
  80. } else {
  81. fail(`plain HTTP answered ${r.status} ${JSON.stringify(body)}`);
  82. }
  83. } catch (e) {
  84. fail(`plain HTTP request threw: ${e}`);
  85. }
  86. server.kill('SIGTERM');
  87. await sleep(300);
  88. if (!server.killed) server.kill('SIGKILL');
  89. console.log(failed ? 'FAIL' : 'PASS');
  90. process.exit(failed ? 1 : 0);

Branches

Latest commits

  • b638e99dMerge t38 (tracker#38 pagination, #35 Returning/Airing label) into main: LOG/STATUS keep both sides; pager gate follows #37's /people (everyone, last updated first: seed updatedAt); gates pager 229/0, browser 374/0mre
  • f8ffa4dbtracker: report 032 + The Remaining + #39mre
  • 7565a863tracker: LOG timemre
  • b10f00c8tracker#39: double episodes — migrated episodes whose TMDB id TMDB replaced are adopted by their number in the sync (old id -> migratedTmdbId); merge.hl step 3 merges each season's doubles at start (keeper: most watches > synced > first; watches moved/parked; tombstones into mergedEpisodes, nothing deleted); tools/count-duplicate-episodes.hl; gate fixture + paths-m039; live copy 850 -> 0 in 64 s; gates 373/0, 32/0, 52/0mre
  • 9448d643tracker#35 follow-up (mission 033): TVmaze 'Running' is labelled 'Returning', or 'Airing' while a non-special episode of the two newest seasons is released within today +-7 days (data unchanged); gate fixtures Running/Airing/Aired + a special; browser 366/0, kinds 32/0, franchises 52/0, pager 229/0, check-theme 0mre
  • 8751adb8tracker: report 032mre
  • 9bce1f65tracker mission 032: STATUS gate files + the hour-boundary flakemre
  • 718bfb89tracker#37 (mission 032): /people = everyone, last updated first (updatedAt stamped by the person fill; view built at boot, touched people first at once), photo + name tiles (person colour) with the /movies pagination, /people/<letter> removed; photo = our file, tmdbProfile, a cast/crew entry's profile (in-memory map at boot), else the new 'no photo' placeholder; new cast/crew/created_by people keep tmdbProfile; search people rows with the photo; /settings = the heading only; util.hl sortDesc starts from sorted runs (same result, 105k: 1.6 s -> 0.15 s); gates 369/0, 32/0, 52/0, check-theme 0; README/STATUS/LOGmre
  • 03ec792ftracker#38 (mission 033): pagination goes exactly to the clicked page — tilelist read the clicked button's text after pagination.hl's own handler had rebuilt the buttons (real clicks only); now li.current, else the button's own text; new gate tests/pager.mjs (5 lists x 11 pages, 390/1280, real + script clicks, Back/Forward) 229/0; browser 365/0, kinds 32/0, franchises 52/0, check-theme 0mre
  • 96ba683adeploy.sh: a gate without a 'passed,' line (check-theme) no longer ends the scriptmre
  • eb3b9205tracker: report 031mre
  • 9b5d2e89tracker mission 031: README (What it does, Test: four gates + the #32 checks, Files: theme/, new pages), STATUS (real copy, A/B load, how to repeat, open points), LOGmre
  • 39950e4ctracker#32 (mission 031): the WorldAPI theme (theme/ vendored verbatim from layouts.worldapi.org 85b5654; styles.hl inherits it: accent green-dark, type colours 1-6; own base/header rules, row lines, genre-pill and inverted-button frames removed, the season foldable keeps its line; check-theme 21 -> 0, 4th deploy gate; main actions class primary) and the #32 header (theme AppHeader/MainMenu/UserMenu/Sidebar/ContentFirst: desktop brand, search, Series|Shows|Movies|Genres|People, user icon with Unwatched..Settings, Logout; signed out the ident selector, phone the iD icon dropdown; phone menu in the sidebar overlay; marked entry by :has); /find -> /search/<q>, /genres, /people(/<letter>), /settings; main { ContentFirst { slot } } works around the hl:web one-line slot bug; gates 365/0, 32/0, 52/0, check-theme 0mre
  • a386dc92tracker: reports 029 + 030mre
  • 71e0fd7dtracker missions 029 + 030: README (What it does, Files, gate count), STATUS (real-copy numbers, how to repeat, open points), LOGmre
  • d36ea6eatracker#34 + #35 (mission 030): Follow directly under the poster, as wide as the poster (show.hl, styles.hl); the status pill next to a series' title — TVmaze's status (new tvmazeStatus, stored by the sync's TVmaze merge) else TMDB's, TVmaze Ended + TMDB Canceled = Canceled, inverted (filled, dark text, no border), green running / yellow pending / red canceled / muted ended (shows.hl statusOf); the daily delta asks TVmaze's status of an unfollowed series TVmaze's change list names (dailysync.hl syncRunStep, sync.hl syncTvmazeStatus); the status backfill after the details repair (backfill.hl, jobs.hl statusTick; resumable, 550 ms per TVmaze request); gates 354/0, 32/0, 52/0mre
  • 7d7d4487tracker#33 (mission 029): reduced titles — every title TMDB's details never went through this app (no detailsAt, no tmdbSync) is incomplete (shows.hl isIncomplete; the old tracker's migrated rows passed #26's test: 5,697 non-adult on the live copy, 691 series without seasons); the repair job does the visibly reduced first (shows.hl missingParts), the page completes one on open; a title TMDB has no poster for (The Remaining) shows the placeholder; tools/count-incomplete.hl; gate fixtures stand for synced titles (tmdbSync), tests/seed-reduced.hl + #33 checks; gates 347/0, 32/0, 52/0mre
  • 661c2592tracker: report 028mre
  • 27c916fatracker mission 028: README ("Code order", the new file map), STATUS (counts before/after, tests, how to repeat, open), LOGmre
  • d924f398tracker mission 028: comments name the new files (sync.hl, dailysync.hl, backfill.hl, credits.hl, jobs.hl, images.hl …); tools/ref-params.py + tools/lambda-audit.py also scan lib/ (they globbed the root only), lambda-audit counts a plain `x = p` alias like `let x = p`mre