gitoriaLog in with ident

tickets

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Main branchmainbb64d57cmission 012 (ticket #25 API part): every /api/projects/<x>/… route takes the project's id (12-char record id) as well as its slug, same answers byte for byte; tickets stay under their project, no global /api/tickets/<x>. gate 315/0 (old code: the 13 id checks fail), connect 60/0, live-data copy old vs new 1,484 identical, slug vs id 772 identicalmremain/plugins/http1/tests/tls-on-plain-port.mjs

3.4 KB

  1. // tls-on-plain-port.mjs — a TLS ClientHello sent to a plain hl:http1 port must be
  2. // closed at once, not held open until the client times out (routger, 2026-09-27:
  3. // Firefox's HTTPS-First tries https:// first on any non-localhost name, so the
  4. // page "loaded forever" instead of falling back to http). Drives the built
  5. // libhttp1.so through the interpreter (tls_on_plain_port.hl), then talks to it
  6. // with raw sockets — this is protocol-shape testing, below what an .hl fixture
  7. // can reach.
  8. import { spawn } from 'node:child_process';
  9. import { connect } from 'node:net';
  10. import { fileURLToPath } from 'node:url';
  11. import { dirname, resolve } from 'node:path';
  12. const HERE = dirname(fileURLToPath(import.meta.url));
  13. const ROOT = resolve(HERE, '../../..');
  14. const BIN = resolve(ROOT, 'native/zig-out/bin/hybriel');
  15. const FIXTURE = resolve(HERE, 'tls_on_plain_port.hl');
  16. const PORT = Number(process.env.HL_TEST_PORT || 14980);
  17. const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
  18. let failed = false;
  19. const fail = (msg) => { console.log('FAIL ' + msg); failed = true; };
  20. const server = spawn(BIN, [FIXTURE], {
  21. env: { ...process.env, HL_TEST_PORT: String(PORT) },
  22. stdio: ['ignore', 'pipe', 'pipe'],
  23. });
  24. let log = '';
  25. server.stdout.on('data', (d) => { log += d; });
  26. server.stderr.on('data', (d) => { log += d; });
  27. let up = false;
  28. for (let i = 0; i < 80; i++) {
  29. try {
  30. const r = await fetch(`http://127.0.0.1:${PORT}/`);
  31. if (r.status === 200) { up = true; break; }
  32. } catch {}
  33. await sleep(250);
  34. }
  35. if (!up) {
  36. console.log('FAIL server did not come up\n' + log.slice(0, 4000));
  37. server.kill('SIGKILL');
  38. process.exit(1);
  39. }
  40. // A TLS 1.2-shaped ClientHello record header: content type 0x16 (handshake),
  41. // version 0x03 0x03, followed by a plausible length and a few handshake bytes.
  42. // The fix only looks at the first two bytes, but this is what a real client
  43. // sends, so the fixture proves it against a realistic prefix.
  44. const clientHello = Buffer.from([
  45. 0x16, 0x03, 0x03, 0x00, 0x2f, // TLS record: handshake, TLS 1.2, length 0x2f
  46. 0x01, 0x00, 0x00, 0x2b, // handshake: ClientHello, length 0x2b
  47. 0x03, 0x03, // client_version 1.2
  48. ...Array(32).fill(0x42), // "random"
  49. ]);
  50. const closedInTime = await new Promise((resolvePromise) => {
  51. const sock = connect(PORT, '127.0.0.1');
  52. const start = Date.now();
  53. let settled = false;
  54. sock.on('connect', () => sock.write(clientHello));
  55. sock.on('close', () => {
  56. if (settled) return;
  57. settled = true;
  58. resolvePromise(Date.now() - start);
  59. });
  60. sock.on('error', () => {}); // ECONNRESET counts as closed
  61. setTimeout(() => {
  62. if (settled) return;
  63. settled = true;
  64. sock.destroy();
  65. resolvePromise(-1); // never closed within the budget
  66. }, 1000);
  67. });
  68. if (closedInTime < 0) {
  69. fail(`TLS ClientHello prefix was NOT closed within 1000ms`);
  70. } else {
  71. console.log(`ClientHello prefix closed in ${closedInTime}ms`);
  72. }
  73. // Plain HTTP on the same port must still answer — the fix must not have
  74. // turned the port TLS-only or broken ordinary requests.
  75. try {
  76. const r = await fetch(`http://127.0.0.1:${PORT}/`);
  77. const body = await r.text();
  78. if (r.status === 200 && body === 'ok') {
  79. console.log('plain HTTP still answers: 200 ok');
  80. } else {
  81. fail(`plain HTTP answered ${r.status} ${JSON.stringify(body)}`);
  82. }
  83. } catch (e) {
  84. fail(`plain HTTP request threw: ${e}`);
  85. }
  86. server.kill('SIGTERM');
  87. await sleep(300);
  88. if (!server.killed) server.kill('SIGKILL');
  89. console.log(failed ? 'FAIL' : 'PASS');
  90. process.exit(failed ? 1 : 0);

Branches

Latest commits

  • bb64d57cmission 012 (ticket #25 API part): every /api/projects/<x>/… route takes the project's id (12-char record id) as well as its slug, same answers byte for byte; tickets stay under their project, no global /api/tickets/<x>. gate 315/0 (old code: the 13 id checks fail), connect 60/0, live-data copy old vs new 1,484 identical, slug vs id 772 identicalmre
  • 7538b034mission 011 (ticket #25 web part): short page URLs /<slug> and /<slug>/<number>; /projects/<slug>, /projects/<slug>/<n>, /projects/<slug>/tickets/<n> and /tickets/<ref> answer 301 (current slug); slug pages moved behind hl:web's own routes after construction (they answered /__hl/* and /components/*.hl); reserved slugs refused; API paths unchanged. gate 293/0, connect 60/0, live-data copy 187/0, API old vs new: only page links differmre
  • 0369106emission 010 (code order) 4/4: README file map + import order + 'Same output' test, STATUS (entry, lessons, how to verify), LOG, report; tests/realdata-baseline.mjs + realdata-compare*.py (a cleanup answers the same on live data), tests/letcount.pymre
  • a75e0279mission 010 (code order) 3/4: let only where a variable is reassigned or re-bound in a loop body (456 lets → plain declarations; Hybriel refuses a plain declaration inside a loop on its 2nd pass). gate 249/0, connect 60/0, real-data reads identical, a 50-step write sequence (API + faces) identical to the old codemre
  • e9d5c618mission 010 (code order) 2/4: one lib/ file per topic — store.hl split into projects / tickets (+ relations) / events / tickets-helpers, util.hl shared helpers (env, storage dir, URLs, sorts, Vienna time), the function routes out of project.hl into lib/api.hl (thin; auth/filters/Accept in api-helpers.hl), invite + member-removal logic out of the faces/routes into invites.hl / tickets.hl; project.hl is the map. /login/callback gets req + the session store by reference. gate 249/0, connect 60/0, real-data reads identicalmre
  • 97e269b5mission 010 (code order) 1/4: .hl files out of the root — lib/ (store, users, connections, invites, migrate, markdown, mdview, import = ticketfile, util = localtime, jsoncheck, api-helpers = api), tools/import.hl, components/styles.hl; import paths only. gate 249/0, connect 60/0, real-data reads identicalmre
  • 38f9d10ftickets: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gate 249/0, connect 60/0mre
  • d3db6139tickets: Hybriel master 190aa11d (fc838894 GC correctness, #126 closure scopes, #127); gate 249/0, connect 60/0mre
  • bce182e3tickets: Hybriel master 7eea0d32 (#126 memory, #48 lambda copies its argument); migrate.hl lambdas take &logmre
  • 4137be0fantcolony#40: mission references point to the moved missionsmre
  • 9bfba36aantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • c7bd2645tickets: Hybriel master 73267707 (#122 fixed); compactNow workaround removed (#110 covered)mre
  • 2ab91ee9tickets: gate checks rows appear once (session sync); re-vendor to ff51cf46 stopped on hybriel#122, stays 837fe120mre
  • e01c2b1dtickets#24: installable app (manifest, service worker, offline list), own icon; gate waits for the hello's pongmre
  • 752fbb7fdeploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • 38bdd5e4deploy.sh: never send .git or .gitignore to Byrodinmre
  • f12fa1bcState of 2026-09-27, before the move to gitoriamre