Skip to content

fix(http): rewrite all User-Agent headers and preserve active sessions - #221

Merged
Zxilly merged 3 commits into
masterfrom
fix/session-rewrite-and-idle-ttl
Sep 30, 2026
Merged

Zxilly merged 3 commits into
masterfrom
fix/session-rewrite-and-idle-ttl

Conversation

@Zxilly

@Zxilly Zxilly commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Record every User-Agent header in a payload, including large batches of pipelined requests and duplicate headers.
  • Keep eight inline entries and use an embedded UT_array for overflow. Vendor unmodified upstream utarray.h v2.3.0 at e493aa90a2833b4655927598f169c31cfcdf7861, retaining its BSD notice. No new linked dependency.
  • Use a thin accessor for the inline/overflow regions. Inline memory is never passed to utarray's realloc or free. Overflow capacity is reused across parser feeds and freed when the session is destroyed.
  • Adapt utarray's default fatal OOM handling locally: restore capacity after failed reserve, reject unsafe size/count growth, and fail closed. NFQUEUE retains a failed-session marker across retransmitted fragments; proxy connections close.
  • Refresh last_active on nonempty parser input, including incomplete headers, content-length/chunked bodies, and retries on failed sessions. Truly idle sessions still expire.

Allocation scope

Allocation-count tests verify zero UA-entry heap allocations for 0–8 entries per parser feed, one overflow allocation at entry 9, and no new parser allocations while reusing enough reserved overflow capacity. This does not claim zero allocations for session objects, network buffers, or the entire daemon. NFQUEUE still allocates a separate copy-out buffer for payloads with more than eight entries.

Validation

  • Built the production binary and all five test executables with GCC 14.2, GoogleTest 1.14.0, and real libmnl/netfilter/pcap libraries.
  • ctest --test-dir build --output-on-failure -j 4: 144/144 passed.
  • Same 144 tests passed with AddressSanitizer and UndefinedBehaviorSanitizer. LeakSanitizer is disabled because this container runs under ptrace.
  • Counter/failure-injection tests cover init/destroy, inline capacity, first spill, reuse, first-allocation failure, growth failure with preserved old buffer/capacity, and overflow rejection before allocation. Test allocator instrumentation uses GNU-compatible linker --wrap; production allocators are unchanged.
  • A separate ASan/UBSan harness exercised the actual proxy payload path with 250 pipelined requests and 1,000 duplicate UA headers; no original values remained.
  • Seven parser/session regression cases were confirmed failing against the unmodified base commit; the empty-feed/idle control passed there.
  • Local builds used UCI and libbacktrace disabled. Privileged NFQUEUE, network-namespace/TPROXY integration, musl, and OpenWrt/QEMU checks were not run locally. CI passed on 771671af96210a83aa3bb87ea7cfa6eb4a7d368d: all 27 checks are green, including the 18-variant package build matrix, both QEMU versions, UCI/standalone/musl unit tests, cache/no-cache integration tests, and CodeQL.

CI workflows: build and tests, OpenWrt QEMU, CodeQL.

Build dependencies were extracted into the temporary workspace; no system packages or firewall settings were changed.

@Zxilly
Zxilly marked this pull request as ready for review September 30, 2026 02:25
@Zxilly
Zxilly merged commit 4ff67c3 into master Sep 30, 2026
27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant