Skip to content

Update llhttp from 9.3.0 to 9.4.3 - #8552

Open
Amaury Chamayou (achamayou) wants to merge 2 commits into
mainfrom
achamayou-redesigned-barnacle
Open

Amaury Chamayou (achamayou) wants to merge 2 commits into
mainfrom
achamayou-redesigned-barnacle

Conversation

@achamayou

@achamayou Amaury Chamayou (achamayou) commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Motivation

Update CCF's HTTP/1.x parser to the latest non-prerelease llhttp release, incorporating the cumulative parsing fixes since 9.3.0.

Refs #8551.

Implementation summary

Follow the previous vendoring pattern: import the generated C/header artifacts from release/v9.4.3, pinned to 0e815792b167a9bd8ace259b95b7da953776c288, into the existing flattened directory and update cgmanifest.json. http.c is unchanged. There are no local modifications to the upstream artifacts.

Upstream release Relevant changes Implications for CCF
9.3.1 Fix the QDTEXT lookup table, excluding DEL (0x7f) from quoted strings (nodejs/llhttp#682); refresh llparse to 7.3.1, including generated ARM NEON fixes for feature detection, vector operand types and zero-mask handling; reorganize method/constants generation and upstream build options. Quoted chunk extensions containing DEL are rejected. The vendored code includes the ARM fixes, but local validation is x86_64 only. Existing method/status/error numeric values remain unchanged. CCF does not consume upstream build scripts.
9.4.0 Add the opt-in llhttp_set_lenient_header_value_relaxed() API and LENIENT_HEADER_VALUE_RELAXED flag; accept tabs around Content-Length; update CMake exports and shared/static builds, benchmarks, documentation and license text. CCF leaves the new relaxed-header flag disabled, preserving default header-value validation. Valid optional whitespace around Content-Length is accepted. Upstream packaging/tooling changes need no CCF build adaptation.
9.4.1 Repair release generation and include a required CMake file. No CCF integration change: generated sources are vendored directly, without the upstream CMake package.
9.4.2 Require LF after CR in response status lines; correctly recognize Connection: close followed by a tab. Malformed CR/CRCR response-line endings are rejected. Trailing optional whitespace no longer prevents the parser from rejecting further requests after Connection: close.
9.4.3 Reject empty Transfer-Encoding values. Empty and whitespace-only values in requests/responses now produce HPE_INVALID_TRANSFER_ENCODING, rather than being accepted alongside Content-Length. Malformed client requests follow CCF's existing HTTP 400/session-close/error-metric path.

Full upstream comparison: v9.3.0...v9.4.3.

Add focused HTTP unit regressions and extend the existing illegal-traffic e2e test. Document the framing changes in the networking guide and changelog.

Safety and compatibility

No lenient parsing flags are enabled. The new public API is additive; existing parser/callback layouts and enum numeric values are unchanged. No CCF ledger, KV or consensus serialization changes are made. Clients that send an empty Transfer-Encoding should omit that header when no transfer coding is used. The stricter malformed-input rejection above is intentional.

Validation completed on x86_64: vendored-dependency verification (all 4 artifacts), affected C++ builds, the HTTP/public-header/OpenAPI unit tests, all 5 new regression cases (68 assertions; all 5 cases fail against 9.3.0), HTTP/1 and HTTP/2 cpp_illegal/js_illegal e2e coverage, scripts/ci-checks.sh, and the Sphinx build with --fail-on-warning. The rolling-upgrade phase from CCF 7.0.18 also completes successfully.

Required CI must pass before merge.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@achamayou
Amaury Chamayou (achamayou) requested a review from a team as a code owner October 10, 2026 15:11
Copilot AI balanced review requested due to automatic review settings October 10, 2026 15:11
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The security-sensitive parser update is sound, but the required long-term compatibility test remains blocked.

0 open findings

What changed in this PR

Updates CCF’s vendored HTTP/1.x parser from llhttp 9.3.0 to 9.4.3, incorporating stricter framing validation and parser fixes.

Changes:

  • Updates the manifest and vendored generated llhttp artifacts.
  • Adds unit and end-to-end regression coverage for parsing changes.
  • Documents the changed HTTP behavior and release impact.

Custom instructions used

  • .github/copilot-instructions.md
  • .github/instructions/reviewing.instructions.md
  • .github/instructions/changelog.instructions.md
  • .github/skills/testing/SKILL.md
  • .github/skills/formatting-and-linting/SKILL.md
File Description
CHANGELOG.md Records the parser upgrade and behavior changes.
cgmanifest.json Pins llhttp 9.4.3 and its release commit.
3rdparty/​exported/​llhttp/​api.c Adds the relaxed-header API implementation.
3rdparty/​exported/​llhttp/​llhttp.c Imports the updated generated parser.
3rdparty/​exported/​llhttp/​llhttp.h Updates version metadata and public declarations.
doc/​operations/​network.rst Documents malformed-framing rejection.
src/​http/​test/​http_test.cpp Adds focused parser regressions.
tests/​e2e_logging.py Tests empty Transfer-Encoding rejection end to end.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants