fix(network): honor HTTP response connection closure - #3581
Merged
Merged
Conversation
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
drew
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
September 23, 2026 05:30
|
🌿 Preview your docs: https://nvidia-preview-pr-3581.docs.buildwithfern.com/openshell |
|
Label |
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
pimlock
previously approved these changes
Sep 23, 2026
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix HTTP clients hanging after receiving a complete response when the upstream uses HTTP/1.0 default-close semantics or
Connection: close. Finish response delivery and shut down downstream writes, including TLS close notification, instead of waiting for another request.Related Issue
No issue required: localized HTTP response-lifecycle bug; the failure, fix, and regression coverage can be reviewed together. This change is independent of PR #3580.
Changes
Testing
mise run pre-commitpassed on the final test change; formatting andgit diff --checkpassed.host_gateway_aliasE2E binary: all 3 tests passed, including HTTP/1.0, explicit-close fixed-length, and explicit-close chunked EOF checks. Fixed the fixture's unavailable crate reference by using the standard socket API.credential_gatingE2E binary: 1 test passed, covering synthetic credential gating, transformations, and live policy binding.1dffe24e7: Q20 passed before/after restart. Overall matrix remains incomplete (3 PASS, 7 BLOCKED, 11 NOT RUN); this is not full security qualification.test:e2eso the E2E lane is requested; its workflow has started. Rust and Go SDK checks passed on the preceding runtime-fix head.mise run test: earlier broad run stopped atplaintext_mcp_forwarding_preserves_initialization_and_selected_revision(expected HTTP 200). It passed in the initial complete network-library run; that local failure was not isolated.mise run ci: earlier run failed in existing Go gateway-discovery tests because this host has/etc/openshell/gateways/default, while those tests expect an empty system gateway directory.The four Docker E2E tests used pinned supervisor/sandbox images from runtime revision
1dffe24e7, with the E2E Python workload image and their own policies. Current commit05bcbe822changes only the test socket setup. All three local E2E attempts, including the initial compile failure, have verified cleanup of namespace-labeled resources, temporary gateway state and gateway listeners. Full local suites were not repeated, following the request to use CI for the remaining validation. No liveghclient regression was run; the TLS regression exercises production TLS termination and relay paths.Checklist