Repository navigation
Update llhttp from 9.3.0 to 9.4.3 - #8552
Open
Amaury Chamayou (achamayou) wants to merge 2 commits into
Open
Amaury Chamayou (achamayou) wants to merge 2 commits into
Amaury Chamayou (achamayou) wants to merge 2 commits into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Amaury Chamayou (achamayou)
October 10, 2026 15:11
View session
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
🔵 Needs a closer look
The security-sensitive parser update is sound, but the required long-term compatibility test remains blocked.
0 open findings
What changed in this PR
Updates CCF’s vendored HTTP/1.x parser from llhttp 9.3.0 to 9.4.3, incorporating stricter framing validation and parser fixes.
Changes:
- Updates the manifest and vendored generated llhttp artifacts.
- Adds unit and end-to-end regression coverage for parsing changes.
- Documents the changed HTTP behavior and release impact.
Custom instructions used
.github/copilot-instructions.md.github/instructions/reviewing.instructions.md.github/instructions/changelog.instructions.md.github/skills/testing/SKILL.md.github/skills/formatting-and-linting/SKILL.md
| File | Description |
|---|---|
CHANGELOG.md |
Records the parser upgrade and behavior changes. |
cgmanifest.json |
Pins llhttp 9.4.3 and its release commit. |
3rdparty/exported/llhttp/api.c |
Adds the relaxed-header API implementation. |
3rdparty/exported/llhttp/llhttp.c |
Imports the updated generated parser. |
3rdparty/exported/llhttp/llhttp.h |
Updates version metadata and public declarations. |
doc/operations/network.rst |
Documents malformed-framing rejection. |
src/http/test/http_test.cpp |
Adds focused parser regressions. |
tests/e2e_logging.py |
Tests empty Transfer-Encoding rejection end to end. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Update CCF's HTTP/1.x parser to the latest non-prerelease llhttp release, incorporating the cumulative parsing fixes since 9.3.0.
Refs #8551.
Implementation summary
Follow the previous vendoring pattern: import the generated C/header artifacts from
release/v9.4.3, pinned to0e815792b167a9bd8ace259b95b7da953776c288, into the existing flattened directory and updatecgmanifest.json.http.cis unchanged. There are no local modifications to the upstream artifacts.0x7f) from quoted strings (nodejs/llhttp#682); refresh llparse to 7.3.1, including generated ARM NEON fixes for feature detection, vector operand types and zero-mask handling; reorganize method/constants generation and upstream build options.llhttp_set_lenient_header_value_relaxed()API andLENIENT_HEADER_VALUE_RELAXEDflag; accept tabs aroundContent-Length; update CMake exports and shared/static builds, benchmarks, documentation and license text.Content-Lengthis accepted. Upstream packaging/tooling changes need no CCF build adaptation.Connection: closefollowed by a tab.Connection: close.Transfer-Encodingvalues.HPE_INVALID_TRANSFER_ENCODING, rather than being accepted alongsideContent-Length. Malformed client requests follow CCF's existing HTTP 400/session-close/error-metric path.Full upstream comparison: v9.3.0...v9.4.3.
Add focused HTTP unit regressions and extend the existing illegal-traffic e2e test. Document the framing changes in the networking guide and changelog.
Safety and compatibility
No lenient parsing flags are enabled. The new public API is additive; existing parser/callback layouts and enum numeric values are unchanged. No CCF ledger, KV or consensus serialization changes are made. Clients that send an empty
Transfer-Encodingshould omit that header when no transfer coding is used. The stricter malformed-input rejection above is intentional.Validation completed on x86_64: vendored-dependency verification (all 4 artifacts), affected C++ builds, the HTTP/public-header/OpenAPI unit tests, all 5 new regression cases (68 assertions; all 5 cases fail against 9.3.0), HTTP/1 and HTTP/2
cpp_illegal/js_illegale2e coverage,scripts/ci-checks.sh, and the Sphinx build with--fail-on-warning. The rolling-upgrade phase from CCF 7.0.18 also completes successfully.Required CI must pass before merge.