fix(nvhttp): wrap TLS socket to ensure graceful closure - #3077

Merged
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset
Aug 25, 2024
Merged

fix(nvhttp): wrap TLS socket to ensure graceful closure#3077
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset

Conversation

@cgutman

@cgutmancgutman commented Aug 24, 2024

Copy link
Copy Markdown
Collaborator

Description

The upstream SimpleWeb::Server<SimpleWeb::HTTPS> implementation doesn't ensure the TLS session is torn down gracefully which leads to unexpected TCP RST packets from Sunshine to the client when using TLS v1.3 and setting close_connection_after_response (which NvHTTP does). Depending on the client, this spurious TCP RST can lead to the HTTPS request failing even though all the required data did end up on the wire. The QSslSocket implementation in Qt seems to be particularly susceptible to the issue, causing computers to constantly bounce between online and offline.

Ideally this would be fixed upstream, but the way that the classes are structured with SimpleWeb::ServerBase doesn't provide a straightforward place to insert this code (ServerBase has no clue about any TLS stuff). Fixing it on our side using a little wrapper class is fairly simple with most of the diff just being renames of the old class to the new one. We already had a class derived from SimpleWeb::Server<SimpleWeb::HTTPS>, so changing it to derive from SimpleWeb::ServerBase just required a few more lines from the upstream constructor of SimpleWeb::Server<SimpleWeb::HTTPS>.

Screenshot

Issues Fixed or Closed

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

@cgutmancgutman added this to the stable release milestone Aug 24, 2024
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
5.1% Duplication on New Code (required ≤ 3%)

See analysis details on SonarCloud

Comment threadsrc/nvhttp.cpp
@codecov

codecovBot commented Aug 24, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 4.76190% with 20 lines in your changes missing coverage. Please review.

Project coverage is 9.41%. Comparing base (c9f853d) to head (81c012b).
Report is 121 commits behind head on master.

Files with missing linesPatch %Lines
src/nvhttp.cpp4.76%7 Missing and 13 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #3077 +/- ##
=========================================
- Coverage 9.61% 9.41% -0.20% 
=========================================
Files 101 77 -24 Lines 17914 14013 -3901 Branches 8371 6431 -1940 =========================================
- Hits 1722 1319 -403 + Misses 13321 10080 -3241 + Partials 2871 2614 -257 
FlagCoverage Δ
Linux?
Windows4.95% <0.00%> (-0.01%)⬇️
macOS-1210.36% <4.76%> (-0.05%)⬇️
macOS-1310.27% <4.76%> (-0.05%)⬇️
macOS-1410.55% <4.76%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/nvhttp.cpp0.89% <4.76%> (-0.32%)⬇️

... and 54 files with indirect coverage changes

---- 🚨 Try these New Features:

@Hazer

Copy link
Copy Markdown
Contributor

@cgutman Any migration steps for current users running this behind some reverse proxy or it's mostly transparent?

@cgutman

Copy link
Copy Markdown
CollaboratorAuthor

It's transparent to any reverse proxies.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@cgutman@Hazer@ns6089@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(nvhttp): wrap TLS socket to ensure graceful closure - #3077

Merged
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset
Aug 25, 2024
Merged

fix(nvhttp): wrap TLS socket to ensure graceful closure#3077
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset

Conversation

@cgutman

@cgutmancgutman commented Aug 24, 2024

Copy link
Copy Markdown
Collaborator

Description

The upstream SimpleWeb::Server<SimpleWeb::HTTPS> implementation doesn't ensure the TLS session is torn down gracefully which leads to unexpected TCP RST packets from Sunshine to the client when using TLS v1.3 and setting close_connection_after_response (which NvHTTP does). Depending on the client, this spurious TCP RST can lead to the HTTPS request failing even though all the required data did end up on the wire. The QSslSocket implementation in Qt seems to be particularly susceptible to the issue, causing computers to constantly bounce between online and offline.

Ideally this would be fixed upstream, but the way that the classes are structured with SimpleWeb::ServerBase doesn't provide a straightforward place to insert this code (ServerBase has no clue about any TLS stuff). Fixing it on our side using a little wrapper class is fairly simple with most of the diff just being renames of the old class to the new one. We already had a class derived from SimpleWeb::Server<SimpleWeb::HTTPS>, so changing it to derive from SimpleWeb::ServerBase just required a few more lines from the upstream constructor of SimpleWeb::Server<SimpleWeb::HTTPS>.

Screenshot

Issues Fixed or Closed

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

@cgutmancgutman added this to the stable release milestone Aug 24, 2024
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
5.1% Duplication on New Code (required ≤ 3%)

See analysis details on SonarCloud

Comment threadsrc/nvhttp.cpp
@codecov

codecovBot commented Aug 24, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 4.76190% with 20 lines in your changes missing coverage. Please review.

Project coverage is 9.41%. Comparing base (c9f853d) to head (81c012b).
Report is 121 commits behind head on master.

Files with missing linesPatch %Lines
src/nvhttp.cpp4.76%7 Missing and 13 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #3077 +/- ##
=========================================
- Coverage 9.61% 9.41% -0.20% 
=========================================
Files 101 77 -24 Lines 17914 14013 -3901 Branches 8371 6431 -1940 =========================================
- Hits 1722 1319 -403 + Misses 13321 10080 -3241 + Partials 2871 2614 -257 
FlagCoverage Δ
Linux?
Windows4.95% <0.00%> (-0.01%)⬇️
macOS-1210.36% <4.76%> (-0.05%)⬇️
macOS-1310.27% <4.76%> (-0.05%)⬇️
macOS-1410.55% <4.76%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/nvhttp.cpp0.89% <4.76%> (-0.32%)⬇️

... and 54 files with indirect coverage changes

---- 🚨 Try these New Features:

@Hazer

Copy link
Copy Markdown
Contributor

@cgutman Any migration steps for current users running this behind some reverse proxy or it's mostly transparent?

@cgutman

Copy link
Copy Markdown
CollaboratorAuthor

It's transparent to any reverse proxies.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@cgutman@Hazer@ns6089@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(nvhttp): wrap TLS socket to ensure graceful closure - #3077

Merged
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset
Aug 25, 2024
Merged

fix(nvhttp): wrap TLS socket to ensure graceful closure#3077
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset

Conversation

@cgutman

@cgutmancgutman commented Aug 24, 2024

Copy link
Copy Markdown
Collaborator

Description

The upstream SimpleWeb::Server<SimpleWeb::HTTPS> implementation doesn't ensure the TLS session is torn down gracefully which leads to unexpected TCP RST packets from Sunshine to the client when using TLS v1.3 and setting close_connection_after_response (which NvHTTP does). Depending on the client, this spurious TCP RST can lead to the HTTPS request failing even though all the required data did end up on the wire. The QSslSocket implementation in Qt seems to be particularly susceptible to the issue, causing computers to constantly bounce between online and offline.

Ideally this would be fixed upstream, but the way that the classes are structured with SimpleWeb::ServerBase doesn't provide a straightforward place to insert this code (ServerBase has no clue about any TLS stuff). Fixing it on our side using a little wrapper class is fairly simple with most of the diff just being renames of the old class to the new one. We already had a class derived from SimpleWeb::Server<SimpleWeb::HTTPS>, so changing it to derive from SimpleWeb::ServerBase just required a few more lines from the upstream constructor of SimpleWeb::Server<SimpleWeb::HTTPS>.

Screenshot

Issues Fixed or Closed

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

@cgutmancgutman added this to the stable release milestone Aug 24, 2024
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
5.1% Duplication on New Code (required ≤ 3%)

See analysis details on SonarCloud

Comment threadsrc/nvhttp.cpp
@codecov

codecovBot commented Aug 24, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 4.76190% with 20 lines in your changes missing coverage. Please review.

Project coverage is 9.41%. Comparing base (c9f853d) to head (81c012b).
Report is 121 commits behind head on master.

Files with missing linesPatch %Lines
src/nvhttp.cpp4.76%7 Missing and 13 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #3077 +/- ##
=========================================
- Coverage 9.61% 9.41% -0.20% 
=========================================
Files 101 77 -24 Lines 17914 14013 -3901 Branches 8371 6431 -1940 =========================================
- Hits 1722 1319 -403 + Misses 13321 10080 -3241 + Partials 2871 2614 -257 
FlagCoverage Δ
Linux?
Windows4.95% <0.00%> (-0.01%)⬇️
macOS-1210.36% <4.76%> (-0.05%)⬇️
macOS-1310.27% <4.76%> (-0.05%)⬇️
macOS-1410.55% <4.76%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/nvhttp.cpp0.89% <4.76%> (-0.32%)⬇️

... and 54 files with indirect coverage changes

---- 🚨 Try these New Features:

@Hazer

Copy link
Copy Markdown
Contributor

@cgutman Any migration steps for current users running this behind some reverse proxy or it's mostly transparent?

@cgutman

Copy link
Copy Markdown
CollaboratorAuthor

It's transparent to any reverse proxies.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@cgutman@Hazer@ns6089@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(nvhttp): wrap TLS socket to ensure graceful closure - #3077

Merged
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset
Aug 25, 2024
Merged

fix(nvhttp): wrap TLS socket to ensure graceful closure#3077
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset

Conversation

@cgutman

@cgutmancgutman commented Aug 24, 2024

Copy link
Copy Markdown
Collaborator

Description

The upstream SimpleWeb::Server<SimpleWeb::HTTPS> implementation doesn't ensure the TLS session is torn down gracefully which leads to unexpected TCP RST packets from Sunshine to the client when using TLS v1.3 and setting close_connection_after_response (which NvHTTP does). Depending on the client, this spurious TCP RST can lead to the HTTPS request failing even though all the required data did end up on the wire. The QSslSocket implementation in Qt seems to be particularly susceptible to the issue, causing computers to constantly bounce between online and offline.

Ideally this would be fixed upstream, but the way that the classes are structured with SimpleWeb::ServerBase doesn't provide a straightforward place to insert this code (ServerBase has no clue about any TLS stuff). Fixing it on our side using a little wrapper class is fairly simple with most of the diff just being renames of the old class to the new one. We already had a class derived from SimpleWeb::Server<SimpleWeb::HTTPS>, so changing it to derive from SimpleWeb::ServerBase just required a few more lines from the upstream constructor of SimpleWeb::Server<SimpleWeb::HTTPS>.

Screenshot

Issues Fixed or Closed

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

@cgutmancgutman added this to the stable release milestone Aug 24, 2024
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
5.1% Duplication on New Code (required ≤ 3%)

See analysis details on SonarCloud

Comment threadsrc/nvhttp.cpp
@codecov

codecovBot commented Aug 24, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 4.76190% with 20 lines in your changes missing coverage. Please review.

Project coverage is 9.41%. Comparing base (c9f853d) to head (81c012b).
Report is 121 commits behind head on master.

Files with missing linesPatch %Lines
src/nvhttp.cpp4.76%7 Missing and 13 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #3077 +/- ##
=========================================
- Coverage 9.61% 9.41% -0.20% 
=========================================
Files 101 77 -24 Lines 17914 14013 -3901 Branches 8371 6431 -1940 =========================================
- Hits 1722 1319 -403 + Misses 13321 10080 -3241 + Partials 2871 2614 -257 
FlagCoverage Δ
Linux?
Windows4.95% <0.00%> (-0.01%)⬇️
macOS-1210.36% <4.76%> (-0.05%)⬇️
macOS-1310.27% <4.76%> (-0.05%)⬇️
macOS-1410.55% <4.76%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/nvhttp.cpp0.89% <4.76%> (-0.32%)⬇️

... and 54 files with indirect coverage changes

---- 🚨 Try these New Features:

@Hazer

Copy link
Copy Markdown
Contributor

@cgutman Any migration steps for current users running this behind some reverse proxy or it's mostly transparent?

@cgutman

Copy link
Copy Markdown
CollaboratorAuthor

It's transparent to any reverse proxies.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@cgutman@Hazer@ns6089@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(nvhttp): wrap TLS socket to ensure graceful closure - #3077

Merged
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset
Aug 25, 2024
Merged

fix(nvhttp): wrap TLS socket to ensure graceful closure#3077
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset

Conversation

@cgutman

@cgutmancgutman commented Aug 24, 2024

Copy link
Copy Markdown
Collaborator

Description

The upstream SimpleWeb::Server<SimpleWeb::HTTPS> implementation doesn't ensure the TLS session is torn down gracefully which leads to unexpected TCP RST packets from Sunshine to the client when using TLS v1.3 and setting close_connection_after_response (which NvHTTP does). Depending on the client, this spurious TCP RST can lead to the HTTPS request failing even though all the required data did end up on the wire. The QSslSocket implementation in Qt seems to be particularly susceptible to the issue, causing computers to constantly bounce between online and offline.

Ideally this would be fixed upstream, but the way that the classes are structured with SimpleWeb::ServerBase doesn't provide a straightforward place to insert this code (ServerBase has no clue about any TLS stuff). Fixing it on our side using a little wrapper class is fairly simple with most of the diff just being renames of the old class to the new one. We already had a class derived from SimpleWeb::Server<SimpleWeb::HTTPS>, so changing it to derive from SimpleWeb::ServerBase just required a few more lines from the upstream constructor of SimpleWeb::Server<SimpleWeb::HTTPS>.

Screenshot

Issues Fixed or Closed

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

@cgutmancgutman added this to the stable release milestone Aug 24, 2024
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
5.1% Duplication on New Code (required ≤ 3%)

See analysis details on SonarCloud

Comment threadsrc/nvhttp.cpp
@codecov

codecovBot commented Aug 24, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 4.76190% with 20 lines in your changes missing coverage. Please review.

Project coverage is 9.41%. Comparing base (c9f853d) to head (81c012b).
Report is 121 commits behind head on master.

Files with missing linesPatch %Lines
src/nvhttp.cpp4.76%7 Missing and 13 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #3077 +/- ##
=========================================
- Coverage 9.61% 9.41% -0.20% 
=========================================
Files 101 77 -24 Lines 17914 14013 -3901 Branches 8371 6431 -1940 =========================================
- Hits 1722 1319 -403 + Misses 13321 10080 -3241 + Partials 2871 2614 -257 
FlagCoverage Δ
Linux?
Windows4.95% <0.00%> (-0.01%)⬇️
macOS-1210.36% <4.76%> (-0.05%)⬇️
macOS-1310.27% <4.76%> (-0.05%)⬇️
macOS-1410.55% <4.76%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/nvhttp.cpp0.89% <4.76%> (-0.32%)⬇️

... and 54 files with indirect coverage changes

---- 🚨 Try these New Features:

@Hazer

Copy link
Copy Markdown
Contributor

@cgutman Any migration steps for current users running this behind some reverse proxy or it's mostly transparent?

@cgutman

Copy link
Copy Markdown
CollaboratorAuthor

It's transparent to any reverse proxies.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@cgutman@Hazer@ns6089@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(nvhttp): wrap TLS socket to ensure graceful closure - #3077

Merged
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset
Aug 25, 2024
Merged

fix(nvhttp): wrap TLS socket to ensure graceful closure#3077
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset

Conversation

@cgutman

@cgutmancgutman commented Aug 24, 2024

Copy link
Copy Markdown
Collaborator

Description

The upstream SimpleWeb::Server<SimpleWeb::HTTPS> implementation doesn't ensure the TLS session is torn down gracefully which leads to unexpected TCP RST packets from Sunshine to the client when using TLS v1.3 and setting close_connection_after_response (which NvHTTP does). Depending on the client, this spurious TCP RST can lead to the HTTPS request failing even though all the required data did end up on the wire. The QSslSocket implementation in Qt seems to be particularly susceptible to the issue, causing computers to constantly bounce between online and offline.

Ideally this would be fixed upstream, but the way that the classes are structured with SimpleWeb::ServerBase doesn't provide a straightforward place to insert this code (ServerBase has no clue about any TLS stuff). Fixing it on our side using a little wrapper class is fairly simple with most of the diff just being renames of the old class to the new one. We already had a class derived from SimpleWeb::Server<SimpleWeb::HTTPS>, so changing it to derive from SimpleWeb::ServerBase just required a few more lines from the upstream constructor of SimpleWeb::Server<SimpleWeb::HTTPS>.

Screenshot

Issues Fixed or Closed

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

@cgutmancgutman added this to the stable release milestone Aug 24, 2024
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
5.1% Duplication on New Code (required ≤ 3%)

See analysis details on SonarCloud

Comment threadsrc/nvhttp.cpp
@codecov

codecovBot commented Aug 24, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 4.76190% with 20 lines in your changes missing coverage. Please review.

Project coverage is 9.41%. Comparing base (c9f853d) to head (81c012b).
Report is 121 commits behind head on master.

Files with missing linesPatch %Lines
src/nvhttp.cpp4.76%7 Missing and 13 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #3077 +/- ##
=========================================
- Coverage 9.61% 9.41% -0.20% 
=========================================
Files 101 77 -24 Lines 17914 14013 -3901 Branches 8371 6431 -1940 =========================================
- Hits 1722 1319 -403 + Misses 13321 10080 -3241 + Partials 2871 2614 -257 
FlagCoverage Δ
Linux?
Windows4.95% <0.00%> (-0.01%)⬇️
macOS-1210.36% <4.76%> (-0.05%)⬇️
macOS-1310.27% <4.76%> (-0.05%)⬇️
macOS-1410.55% <4.76%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/nvhttp.cpp0.89% <4.76%> (-0.32%)⬇️

... and 54 files with indirect coverage changes

---- 🚨 Try these New Features:

@Hazer

Copy link
Copy Markdown
Contributor

@cgutman Any migration steps for current users running this behind some reverse proxy or it's mostly transparent?

@cgutman

Copy link
Copy Markdown
CollaboratorAuthor

It's transparent to any reverse proxies.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@cgutman@Hazer@ns6089@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(nvhttp): wrap TLS socket to ensure graceful closure - #3077

Merged
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset
Aug 25, 2024
Merged

fix(nvhttp): wrap TLS socket to ensure graceful closure#3077
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset

Conversation

@cgutman

@cgutmancgutman commented Aug 24, 2024

Copy link
Copy Markdown
Collaborator

Description

The upstream SimpleWeb::Server<SimpleWeb::HTTPS> implementation doesn't ensure the TLS session is torn down gracefully which leads to unexpected TCP RST packets from Sunshine to the client when using TLS v1.3 and setting close_connection_after_response (which NvHTTP does). Depending on the client, this spurious TCP RST can lead to the HTTPS request failing even though all the required data did end up on the wire. The QSslSocket implementation in Qt seems to be particularly susceptible to the issue, causing computers to constantly bounce between online and offline.

Ideally this would be fixed upstream, but the way that the classes are structured with SimpleWeb::ServerBase doesn't provide a straightforward place to insert this code (ServerBase has no clue about any TLS stuff). Fixing it on our side using a little wrapper class is fairly simple with most of the diff just being renames of the old class to the new one. We already had a class derived from SimpleWeb::Server<SimpleWeb::HTTPS>, so changing it to derive from SimpleWeb::ServerBase just required a few more lines from the upstream constructor of SimpleWeb::Server<SimpleWeb::HTTPS>.

Screenshot

Issues Fixed or Closed

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

@cgutmancgutman added this to the stable release milestone Aug 24, 2024
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
5.1% Duplication on New Code (required ≤ 3%)

See analysis details on SonarCloud

Comment threadsrc/nvhttp.cpp
@codecov

codecovBot commented Aug 24, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 4.76190% with 20 lines in your changes missing coverage. Please review.

Project coverage is 9.41%. Comparing base (c9f853d) to head (81c012b).
Report is 121 commits behind head on master.

Files with missing linesPatch %Lines
src/nvhttp.cpp4.76%7 Missing and 13 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #3077 +/- ##
=========================================
- Coverage 9.61% 9.41% -0.20% 
=========================================
Files 101 77 -24 Lines 17914 14013 -3901 Branches 8371 6431 -1940 =========================================
- Hits 1722 1319 -403 + Misses 13321 10080 -3241 + Partials 2871 2614 -257 
FlagCoverage Δ
Linux?
Windows4.95% <0.00%> (-0.01%)⬇️
macOS-1210.36% <4.76%> (-0.05%)⬇️
macOS-1310.27% <4.76%> (-0.05%)⬇️
macOS-1410.55% <4.76%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/nvhttp.cpp0.89% <4.76%> (-0.32%)⬇️

... and 54 files with indirect coverage changes

---- 🚨 Try these New Features:

@Hazer

Copy link
Copy Markdown
Contributor

@cgutman Any migration steps for current users running this behind some reverse proxy or it's mostly transparent?

@cgutman

Copy link
Copy Markdown
CollaboratorAuthor

It's transparent to any reverse proxies.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@cgutman@Hazer@ns6089@ReenigneArcher
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(nvhttp): wrap TLS socket to ensure graceful closure - #3077

Merged
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset
Aug 25, 2024
Merged

fix(nvhttp): wrap TLS socket to ensure graceful closure#3077
ReenigneArcher merged 1 commit into
LizardByte:masterfrom
cgutman:tls_reset

Conversation

@cgutman

@cgutmancgutman commented Aug 24, 2024

Copy link
Copy Markdown
Collaborator

Description

The upstream SimpleWeb::Server<SimpleWeb::HTTPS> implementation doesn't ensure the TLS session is torn down gracefully which leads to unexpected TCP RST packets from Sunshine to the client when using TLS v1.3 and setting close_connection_after_response (which NvHTTP does). Depending on the client, this spurious TCP RST can lead to the HTTPS request failing even though all the required data did end up on the wire. The QSslSocket implementation in Qt seems to be particularly susceptible to the issue, causing computers to constantly bounce between online and offline.

Ideally this would be fixed upstream, but the way that the classes are structured with SimpleWeb::ServerBase doesn't provide a straightforward place to insert this code (ServerBase has no clue about any TLS stuff). Fixing it on our side using a little wrapper class is fairly simple with most of the diff just being renames of the old class to the new one. We already had a class derived from SimpleWeb::Server<SimpleWeb::HTTPS>, so changing it to derive from SimpleWeb::ServerBase just required a few more lines from the upstream constructor of SimpleWeb::Server<SimpleWeb::HTTPS>.

Screenshot

Issues Fixed or Closed

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Dependency update (updates to dependencies)
  • Documentation update (changes to documentation)
  • Repository update (changes to repository files, e.g. .github/...)

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated the in code docstring/documentation-blocks for new or existing methods/components

@cgutmancgutman added this to the stable release milestone Aug 24, 2024
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
5.1% Duplication on New Code (required ≤ 3%)

See analysis details on SonarCloud

Comment threadsrc/nvhttp.cpp
@codecov

codecovBot commented Aug 24, 2024

Copy link
Copy Markdown

Codecov Report

Attention: Patch coverage is 4.76190% with 20 lines in your changes missing coverage. Please review.

Project coverage is 9.41%. Comparing base (c9f853d) to head (81c012b).
Report is 121 commits behind head on master.

Files with missing linesPatch %Lines
src/nvhttp.cpp4.76%7 Missing and 13 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## master #3077 +/- ##
=========================================
- Coverage 9.61% 9.41% -0.20% 
=========================================
Files 101 77 -24 Lines 17914 14013 -3901 Branches 8371 6431 -1940 =========================================
- Hits 1722 1319 -403 + Misses 13321 10080 -3241 + Partials 2871 2614 -257 
FlagCoverage Δ
Linux?
Windows4.95% <0.00%> (-0.01%)⬇️
macOS-1210.36% <4.76%> (-0.05%)⬇️
macOS-1310.27% <4.76%> (-0.05%)⬇️
macOS-1410.55% <4.76%> (-0.05%)⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing linesCoverage Δ
src/nvhttp.cpp0.89% <4.76%> (-0.32%)⬇️

... and 54 files with indirect coverage changes

---- 🚨 Try these New Features:

@Hazer

Copy link
Copy Markdown
Contributor

@cgutman Any migration steps for current users running this behind some reverse proxy or it's mostly transparent?

@cgutman

Copy link
Copy Markdown
CollaboratorAuthor

It's transparent to any reverse proxies.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@cgutman@Hazer@ns6089@ReenigneArcher