Skip to content

0.2.3

Latest

Choose a tag to compare

@samooth samooth released this 28 Sep 23:15
· 21 commits to main since this release
0.2.3

Four defects that made 0.2.2 unusable from a real client, all found by
driving the server with curl and openssl s_client instead of with httpx.
None of them were visible to the test suite, which talks to httpx with
httpx and therefore agreed with the bugs.

TLS server unusable from real clients. The ServerHello carried a
server_name acknowledgement that OpenSSL rejects in a TLS 1.3
ServerHello, aborting with illegal_parameter before any key exchange.
Every real client sends SNI, so curl, browsers and openssl were all cut
off. The acknowledgement is now omitted.

TLS server broken for every modern client. The server advertised h2
through ALPN while there is no HTTP/2 framing behind it, so it negotiated
a protocol it could not speak. curl https://host/ failed; the same
request with --http1.1 worked. The ALPN preference is now derived from
what the server can actually serve.

Template arena never freed. Renderer.render declared
ctx: *const Context and mutated the arena through it. LLVM emits
readonly from the parameter type, so Engine.render could prove the
arena's node list was still null and fold defer ctx.deinit() away.
Every node pushed during a render leaked. A comptime guard now makes the
invariant a compile error.

Double free in getOrCompile. An errdefer stayed armed after the
source buffer's ownership passed to the cache, so an error path freed a
buffer the cache still held.

Also in this release

  • Interop tests that drive a live server with curl and openssl s_client,
    plus a CI job on Linux and macOS. They are opt-in via HTTPX_INTEROP so
    the main matrix stays hermetic.
  • A build step that isolates the template engine tests, which makes a leak
    in that module reproducible in seconds rather than a minute.
  • Docs now record what real clients do and where the gaps are.

Known limitation. X25519MLKEM768 is implemented for outgoing
handshakes only. A server answers with x25519, so a client offering only
the hybrid group is rejected. That is the default posture of OpenSSL 3.5
and later. See docs/reference/interop-status.md.