Skip to content

fix(network): honor HTTP response connection closure - #3581

Merged
drew merged 3 commits into
mainfrom
codex/fix-http-response-eof
Sep 23, 2026
Merged

drew merged 3 commits into
mainfrom
codex/fix-http-response-eof

Conversation

@drew

@drew drew commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Fix HTTP clients hanging after receiving a complete response when the upstream uses HTTP/1.0 default-close semantics or Connection: close. Finish response delivery and shut down downstream writes, including TLS close notification, instead of waiting for another request.

Related Issue

No issue required: localized HTTP response-lifecycle bug; the failure, fix, and regression coverage can be reviewed together. This change is independent of PR #3580.

Changes

  • Honor response persistence independently of Content-Length and chunked framing, including bodiless HTTP/1.0 responses.
  • Apply the same close decision to headers-only and body-transforming response middleware, and signal EOF before returning a consumed middleware response.
  • Add response/middleware regression coverage, persistent-then-closing exchanges over plaintext and TLS with a 64 KiB body, and a Docker regression for HTTP/1.0, explicit-close fixed-length, and explicit-close chunked responses.
  • Document HTTP response lifetime behavior. Reviewed related skills; no command, policy-option, or workflow changes are needed.

Testing

  • Supervisor-network library suite: 1,349 passed, 2 ignored, including response and TLS regressions (before final test-only lint cleanup).
  • mise run pre-commit passed on the final test change; formatting and git diff --check passed.
  • Docker host_gateway_alias E2E binary: all 3 tests passed, including HTTP/1.0, explicit-close fixed-length, and explicit-close chunked EOF checks. Fixed the fixture's unavailable crate reference by using the standard socket API.
  • Docker credential_gating E2E binary: 1 test passed, covering synthetic credential gating, transformations, and live policy binding.
  • Supplemental backend, task-memory, filter, and environment component checks: 63 passed.
  • Bounded Docker qualification rerun at 1dffe24e7: Q20 passed before/after restart. Overall matrix remains incomplete (3 PASS, 7 BLOCKED, 11 NOT RUN); this is not full security qualification.
  • Full CI at current head: pending. Added test:e2e so the E2E lane is requested; its workflow has started. Rust and Go SDK checks passed on the preceding runtime-fix head.
  • Full local mise run test: earlier broad run stopped at plaintext_mcp_forwarding_preserves_initialization_and_selected_revision (expected HTTP 200). It passed in the initial complete network-library run; that local failure was not isolated.
  • Full local mise run ci: earlier run failed in existing Go gateway-discovery tests because this host has /etc/openshell/gateways/default, while those tests expect an empty system gateway directory.

The four Docker E2E tests used pinned supervisor/sandbox images from runtime revision 1dffe24e7, with the E2E Python workload image and their own policies. Current commit 05bcbe822 changes only the test socket setup. All three local E2E attempts, including the initial compile failure, have verified cleanup of namespace-labeled resources, temporary gateway state and gateway listeners. Full local suites were not repeated, following the request to use CI for the remaining validation. No live gh client regression was run; the TLS regression exercises production TLS termination and relay paths.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture and published docs updated

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@github-actions

Copy link
Copy Markdown

@drew drew added the test:e2e Requires end-to-end coverage label Sep 23, 2026
@github-actions

Copy link
Copy Markdown

Label test:e2e applied for 1dffe24. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
pimlock
pimlock previously approved these changes Sep 23, 2026
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew
drew merged commit 52aac37 into main Sep 23, 2026
161 of 163 checks passed
@drew
drew deleted the codex/fix-http-response-eof branch September 23, 2026 19:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants