Skip to content

Vendor Quiver: fix WebTransport session/stream lifecycle, bound buffers, and make the vendor tree reproducible - #63

Open
anderson-oki wants to merge 6 commits into
mainfrom
fix/vendor-quiver-webtransport-lifecycle
Open

anderson-oki wants to merge 6 commits into
mainfrom
fix/vendor-quiver-webtransport-lifecycle

Conversation

@anderson-oki

Copy link
Copy Markdown
Collaborator

Delivers all six work packages from NEC-29 on one branch, one commit per package.

What changed

  • WP4 — reproducible vendor tree (commit 1). Vendor/Quiver is now generated from the pinned upstream commit (d3b0cdc5) plus a committed patch series in Vendor/Quiver/Patches/. scripts/vendor-quiver.sh rebuilds it and fails on any unexpected diff; CI runs it and fails when the tree is edited without a patch. VENDORING.md now documents all nine deltas (including the two undocumented security fixes from ff4fc44c) and states the correct rationale: the only hard blocker is the missing QUICCrypto library product, not package access. The corrupted SystemTrustStore diagnostic ("ca-certificates public") is restored, and the blind s/\bpackage /public /g is replaced by patch 0002.
  • WP1 — lifecycle (commit 2). transitionToClosed unregisters the session and resets its child streams; streams are removed on FIN/reset via a one-shot terminal notification; a per-session stream bound (default 64, configurable through WebTransportOptions/WebTransportConfiguration) rejects churn; handleIncomingBidiStream no longer routes a 0x00 (DATA) first varint into session 0.
  • WP3 — framing (commit 3). The bidi framing loop reads across STREAM frames until both varints are complete; a signal with no session ID, and a signal with an unknown session ID, reset the stream instead of silently rerouting; the no-signal path stays accepted for peers that predate the signal.
  • WP2 — bounds (commit 4). The four session event streams use a bounded policy with a droppedEvents counter; capsule payload length is capped at the 16 MB frame bound; CRYPTO reassembly is capped by segment count; the app's request handler drains the body it never reads (app-side, no vendor delta).
  • WP5 — hardening batch (commit 5). 0-RTT fails closed without replay protection; isRetryPacket indexes slices from their own startIndex; dead duplicate ProtocolLimits constants removed and ConnectionID.maxLength unified; empty ALPN fails closed; a truncatedLength >= 0 guard precedes prefix.
  • WP6 — harness (commit 6). scripts/vendor-quiver-tests.sh runs upstream's own suite against our patched sources; CI invokes it on any Vendor/Quiver change.

Verification

  • swift build --scratch-path .build/shared --target OpenNOW — Build complete.
  • swift test --scratch-path .build/shared --filter RemoteCoOp — 283 tests, 30 suites, passed.
  • scripts/vendor-quiver-tests.sh — upstream suite, exit 0 (222 tests; the machine-dependent QUICBenchmarks throughput suites are skipped).
  • scripts/vendor-quiver.sh — "Vendor/Quiver matches the pinned commit plus the committed patch series."
  • Strict swiftlint over App GFN Model OPN View ViewModel Tests — 0 violations; no baseline entries added; Vendor/ stays outside the lint path.

Open items

  • Spikes not re-run. spikes/browseregress needs a real Chrome and spikes/webtransport needs agency loopback; neither is available in this environment, and both directories are gitignored. They must be re-run before this goes further than review.
  • No new app-seam tests. The WP1/WP2/WP3 behaviour is vendor-internal and is covered by the WP6 upstream-suite harness, as the issue allows; there is no app-seam seam to drive a real QUIC WebTransport session from Tests/RemoteCoOp today.
  • Legacy no-signal peers and session 0/4. Rejecting a 0x00/0x04 first varint (WP1 item 5) means a peer that both omits the 0x41 signal and uses session ID 0 or 4 no longer interoperates. Chrome and our own client always send the signal; this matches the issue's stated conformance requirement but is a real edge of the "optional on receive" property.
  • The CI vendor job could not be pushed with the workspace HTTPS token (no workflow scope); the branch was pushed via SSH.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 6b300361-1cd8-4e8d-9b02-431ae9d3a083


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant