gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commiteb3b9205eb3b9205tracker: report 031mreeb3b9205/plugins/http1/tests/tls-on-plain-port.mjs

3.4 KB

  1. // tls-on-plain-port.mjs — a TLS ClientHello sent to a plain hl:http1 port must be
  2. // closed at once, not held open until the client times out (routger, 2026-09-27:
  3. // Firefox's HTTPS-First tries https:// first on any non-localhost name, so the
  4. // page "loaded forever" instead of falling back to http). Drives the built
  5. // libhttp1.so through the interpreter (tls_on_plain_port.hl), then talks to it
  6. // with raw sockets — this is protocol-shape testing, below what an .hl fixture
  7. // can reach.
  8. import { spawn } from 'node:child_process';
  9. import { connect } from 'node:net';
  10. import { fileURLToPath } from 'node:url';
  11. import { dirname, resolve } from 'node:path';
  12. const HERE = dirname(fileURLToPath(import.meta.url));
  13. const ROOT = resolve(HERE, '../../..');
  14. const BIN = resolve(ROOT, 'native/zig-out/bin/hybriel');
  15. const FIXTURE = resolve(HERE, 'tls_on_plain_port.hl');
  16. const PORT = Number(process.env.HL_TEST_PORT || 14980);
  17. const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
  18. let failed = false;
  19. const fail = (msg) => { console.log('FAIL ' + msg); failed = true; };
  20. const server = spawn(BIN, [FIXTURE], {
  21. env: { ...process.env, HL_TEST_PORT: String(PORT) },
  22. stdio: ['ignore', 'pipe', 'pipe'],
  23. });
  24. let log = '';
  25. server.stdout.on('data', (d) => { log += d; });
  26. server.stderr.on('data', (d) => { log += d; });
  27. let up = false;
  28. for (let i = 0; i < 80; i++) {
  29. try {
  30. const r = await fetch(`http://127.0.0.1:${PORT}/`);
  31. if (r.status === 200) { up = true; break; }
  32. } catch {}
  33. await sleep(250);
  34. }
  35. if (!up) {
  36. console.log('FAIL server did not come up\n' + log.slice(0, 4000));
  37. server.kill('SIGKILL');
  38. process.exit(1);
  39. }
  40. // A TLS 1.2-shaped ClientHello record header: content type 0x16 (handshake),
  41. // version 0x03 0x03, followed by a plausible length and a few handshake bytes.
  42. // The fix only looks at the first two bytes, but this is what a real client
  43. // sends, so the fixture proves it against a realistic prefix.
  44. const clientHello = Buffer.from([
  45. 0x16, 0x03, 0x03, 0x00, 0x2f, // TLS record: handshake, TLS 1.2, length 0x2f
  46. 0x01, 0x00, 0x00, 0x2b, // handshake: ClientHello, length 0x2b
  47. 0x03, 0x03, // client_version 1.2
  48. ...Array(32).fill(0x42), // "random"
  49. ]);
  50. const closedInTime = await new Promise((resolvePromise) => {
  51. const sock = connect(PORT, '127.0.0.1');
  52. const start = Date.now();
  53. let settled = false;
  54. sock.on('connect', () => sock.write(clientHello));
  55. sock.on('close', () => {
  56. if (settled) return;
  57. settled = true;
  58. resolvePromise(Date.now() - start);
  59. });
  60. sock.on('error', () => {}); // ECONNRESET counts as closed
  61. setTimeout(() => {
  62. if (settled) return;
  63. settled = true;
  64. sock.destroy();
  65. resolvePromise(-1); // never closed within the budget
  66. }, 1000);
  67. });
  68. if (closedInTime < 0) {
  69. fail(`TLS ClientHello prefix was NOT closed within 1000ms`);
  70. } else {
  71. console.log(`ClientHello prefix closed in ${closedInTime}ms`);
  72. }
  73. // Plain HTTP on the same port must still answer — the fix must not have
  74. // turned the port TLS-only or broken ordinary requests.
  75. try {
  76. const r = await fetch(`http://127.0.0.1:${PORT}/`);
  77. const body = await r.text();
  78. if (r.status === 200 && body === 'ok') {
  79. console.log('plain HTTP still answers: 200 ok');
  80. } else {
  81. fail(`plain HTTP answered ${r.status} ${JSON.stringify(body)}`);
  82. }
  83. } catch (e) {
  84. fail(`plain HTTP request threw: ${e}`);
  85. }
  86. server.kill('SIGTERM');
  87. await sleep(300);
  88. if (!server.killed) server.kill('SIGKILL');
  89. console.log(failed ? 'FAIL' : 'PASS');
  90. process.exit(failed ? 1 : 0);

Branches

Latest commits

  • eb3b9205tracker: report 031mre
  • 9b5d2e89tracker mission 031: README (What it does, Test: four gates + the #32 checks, Files: theme/, new pages), STATUS (real copy, A/B load, how to repeat, open points), LOGmre
  • 39950e4ctracker#32 (mission 031): the WorldAPI theme (theme/ vendored verbatim from layouts.worldapi.org 85b5654; styles.hl inherits it: accent green-dark, type colours 1-6; own base/header rules, row lines, genre-pill and inverted-button frames removed, the season foldable keeps its line; check-theme 21 -> 0, 4th deploy gate; main actions class primary) and the #32 header (theme AppHeader/MainMenu/UserMenu/Sidebar/ContentFirst: desktop brand, search, Series|Shows|Movies|Genres|People, user icon with Unwatched..Settings, Logout; signed out the ident selector, phone the iD icon dropdown; phone menu in the sidebar overlay; marked entry by :has); /find -> /search/<q>, /genres, /people(/<letter>), /settings; main { ContentFirst { slot } } works around the hl:web one-line slot bug; gates 365/0, 32/0, 52/0, check-theme 0mre
  • a386dc92tracker: reports 029 + 030mre
  • 71e0fd7dtracker missions 029 + 030: README (What it does, Files, gate count), STATUS (real-copy numbers, how to repeat, open points), LOGmre
  • d36ea6eatracker#34 + #35 (mission 030): Follow directly under the poster, as wide as the poster (show.hl, styles.hl); the status pill next to a series' title — TVmaze's status (new tvmazeStatus, stored by the sync's TVmaze merge) else TMDB's, TVmaze Ended + TMDB Canceled = Canceled, inverted (filled, dark text, no border), green running / yellow pending / red canceled / muted ended (shows.hl statusOf); the daily delta asks TVmaze's status of an unfollowed series TVmaze's change list names (dailysync.hl syncRunStep, sync.hl syncTvmazeStatus); the status backfill after the details repair (backfill.hl, jobs.hl statusTick; resumable, 550 ms per TVmaze request); gates 354/0, 32/0, 52/0mre
  • 7d7d4487tracker#33 (mission 029): reduced titles — every title TMDB's details never went through this app (no detailsAt, no tmdbSync) is incomplete (shows.hl isIncomplete; the old tracker's migrated rows passed #26's test: 5,697 non-adult on the live copy, 691 series without seasons); the repair job does the visibly reduced first (shows.hl missingParts), the page completes one on open; a title TMDB has no poster for (The Remaining) shows the placeholder; tools/count-incomplete.hl; gate fixtures stand for synced titles (tmdbSync), tests/seed-reduced.hl + #33 checks; gates 347/0, 32/0, 52/0mre
  • 661c2592tracker: report 028mre
  • 27c916fatracker mission 028: README ("Code order", the new file map), STATUS (counts before/after, tests, how to repeat, open), LOGmre
  • d924f398tracker mission 028: comments name the new files (sync.hl, dailysync.hl, backfill.hl, credits.hl, jobs.hl, images.hl …); tools/ref-params.py + tools/lambda-audit.py also scan lib/ (they globbed the root only), lambda-audit counts a plain `x = p` alias like `let x = p`mre
  • 2e89b968tracker mission 028 (code order) 5/5 let: `let` only where a variable is reassigned — 667 never-reassigned lets became plain declarations (project.hl, lib/, components/, tools/, tests/); kept: 264 in loop bodies (a plain declaration there is 'Cannot reassign' on the 2nd pass), 234 reassigned, 27 whose name is also a member/outer/free name (a plain write would rebind it); tools/let-audit.py decides and fixes (README 'Code order'); tests/realdata-m028.{sh,mjs} = the page-output diff on a real copy; gates 342/0, 32/0, 52/0, real-copy pages identicalmre
  • 54796ff2tracker mission 028 (code order) 4/5 thin faces + last copies: the show page's check/follow faces call lib/watches.hl toggleWatched / toggleSeasonWatched (seasonAllWatched moved there) and lib/follows.hl toggleFollowed; both logins (header selector face, /login/callback) share lib/users.hl userOfCode; todayStr/listOf copies in components and the export readers copied into tools/migrate.hl + tools/old-short-ids.hl now once (lib/util.hl, lib/export.hl); gates 342/0, 32/0, 52/0; old-short-ids output byte-identical, migrate output identicalmre
  • 06b078e3tracker mission 028 (code order) 3/5 project.hl is the map: config, routes, wiring and a feature → file index (914 → 258 lines); the background jobs (daily sync run, backfills, details repair, credits job, merge, short ids, collection seed) moved unchanged into lib/jobs.hl (a class: their state is reassigned every step, a static cannot be; one instance made after the server), the login callback into lib/users.hl, poster/photo serving into lib/images.hl, the /shows/<slug> rule into lib/shows.hl showsMovedPath; route handlers are thin wrappers; gates 342/0, 32/0, 52/0, real-copy pages identicalmre
  • 94716fd2tracker mission 028 (code order) 2/5 util + topics: lib/util.hl holds envOr, storageDir, postersDir, profilesDir, newId, hexDigits, todayStr, dateOr, textOr, hasId, listOr, firstOf, sortDesc once (were copied into up to 5 files); tmdbsync.hl split into tmdb.hl (TMDB/TVmaze requests), sync.hl (one title's sync), sync-helpers.hl, backfill.hl; details.hl split into details.hl, credits.hl, credits-helpers.hl (isIncomplete to shows.hl); search-helpers.hl (words, query, ranking, slugs); collections.hl (the TMDB collection seed, out of franchises.hl); deltasync.hl renamed dailysync.hl; no behaviour change: gates 342/0, 32/0, 52/0, real-copy pages identicalmre
  • 186079b0tracker mission 028 (code order) 1/5 move: every root .hl except project.hl into lib/ (styles.hl into components/), import paths only; gates 342/0, 32/0, 52/0; real-copy pages identicalmre
  • 4f47f181tracker: report 027mre
  • dc1d4be4tracker mission 027: Hybriel master 06617221 vendored (plugin allocator fixes 3a781359 + 413f60e4); real copy RSS through first-start jobs + 400 loads flat ~2.55 GB (190aa11d 2.3 -> 5.6 GB), page times <= 1.1x; gates 342/0, 32/0, 52/0mre
  • 84e1b3e1tracker: reports 025 + 026mre
  • dc40d859tracker#31 (mission 026): duplicate titles merged — the 68 type+tmdbId pairs held by 157 records were the old tracker's (all migrated); merge.hl repair job (own clock, before the TMDB jobs) keeps one keeper per title (follows/watches > old short id > oldest), moves follows, watches, seasons, cast, credits, timelines, tombstones the rest (mergedInto, never deleted), slugs + short ids 301 to the keeper; stray seasons merged into their listed twin (Reacher S3 watches) or linked when watched; search import re-checks before its put; deploy.sh waits up to 90 s for 200; real copy 68 -> 0 dup ids, az5b2 follows/watches equal; gates 342/0, 32/0, 52/0mre
  • 2667da05tracker#30 (mission 025): /my/ pages from slim cached title cards, episode rows and watch sets (after the jobs /my/series 1.8 s -> 0.06 s, /my/unwatched 4.1 -> 0.18 s); timeline page shows its name once; franchise widget under the poster/title; movies with TV leftovers (First Contact) go through the details repair; tools/count-tmdb-ids.hl; gates 327/0, 52/0, 32/0mre