Repository navigation
Conversation
Bun.serve passed the JS string through as raw bytes. OpenSSL reads the first byte as a length, so "http/1.1" failed with "Failed to configure TLS ALPN protocols". A string is one protocol name. A Buffer stays the wire format the caller already built. Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
steipete
left a comment
There was a problem hiding this comment.
Requesting changes: a bare string is not a single protocol name in Node's ALPN API, and this change also breaks Bun's existing wire-formatted string input.
Node v24.21.0, checked with loopback TLS handshakes in isolation:
ALPNProtocols |
Result |
|---|---|
"http/1.1" or "\x08http/1.1" |
tls.createServer does not advertise ALPN; tls.connect throws TypeError: Must give a Buffer as first argument |
["http/1.1"] |
Encodes as 08 68 74 74 70 2f 31 2e 31; negotiates http/1.1 |
Buffer.from("\x08http/1.1") or equivalent Uint8Array |
Preserves the encoded list; negotiates http/1.1 |
Buffer.from("http/1.1") |
Throws ERR_INVALID_ARG_VALUE for a truncated wire list |
See Node's ALPN converter and socket application. HTTP/2 is not evidence for the proposed string interpretation: it replaces the list with h2, optionally adding http/1.1. Equivalent HTTP/2 checks negotiated h2 for all three supplied forms.
Separately, Bun previously forwarded a string such as "\x02h2" as the valid wire list 02 68 32. This patch emits 03 02 68 32, advertising a different protocol whose name includes the old length byte. Please preserve existing wire-string behavior; treating plain strings as names would need a separate API decision. Add a client/server handshake assertion for the negotiated protocol: server.port > 0 cannot catch this regression or detect silently omitted ALPN.
Length-prefixing every JS string turned a wire list such as "\x02h2" into a different protocol name. Bun already accepts that string as the OpenSSL list. A plain name is not rewritten. The test handshakes the negotiated protocol instead of checking that the server port is set. Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
A string |
What does this PR do?
Bun.servekeeps a stringALPNProtocolsas the OpenSSL wire list. A string such as"\x02h2"still negotiatesh2. A plain"http/1.1"is not rewritten into a single protocol name.Length-prefixing every string advertised a different protocol (
03 02 68 32for"\x02h2"). Checkingserver.port > 0did not catch that.How did you verify your code works?
Release build of this tree,
test/js/bun/http/serve-alpn-string.test.ts.Before restoring the wire-list path:
After restoring it:
The command was
./build/release/bun test ./test/js/bun/http/serve-alpn-string.test.ts.