add basic support for SNI different than URI in H3 - #71428

Merged
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni
Jul 1, 2022
Merged

add basic support for SNI different than URI in H3#71428
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni

Conversation

@wfurt

Copy link
Copy Markdown
Member

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes#57169

@wfurtwfurt added this to the 7.0.0 milestone Jun 29, 2022
@wfurt
wfurt requested a review from a teamJune 29, 2022 12:58
@wfurtwfurt self-assigned this Jun 29, 2022
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

Issue Details

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes #57169

Author:wfurt
Assignees:wfurt
Labels:

area-System.Net.Quic

Milestone:7.0.0

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason to swap the IsNullOrEmpty check with the equality comparison?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not really. I think _state.TargetHost is unlikely to be null. (or maybe never would)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're in an async method, you can await or you can just use the sync version of the method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While the name is ConnectAsync it does not have async keyword. I was thinking about sync method but that does not have cancellation overload.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think that using sync-over-async on an async method within an async method (albeit only task returning atm) is the best option here.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can switch to Dns.GetHostAddresses and give up on cancellation completely. cc: @stephentoub for any additional suggestions.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

QuicException?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is what we get in HTTP/Sockets and in case GetHostAddressesAsync fail to resolve. I'm not 100% we would ever get empty list without failure but if we would I did not want to cause index errors. I'm open to QuicException but fail to resolve may not be IOException.

@ManickaPManickaPJun 29, 2022

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fail to resolve may not be IOException

Why?

We should then reconsider inheriting QuicException from IOException, but we shouldn't throw SocketException from S.N.Quic.

cc @rzikm

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as I mentioned we may do it anyway if Dns.GetHostAddressesAsync fails. Unless you want to catch it and throw something else in both cases. We can certainly do it as well.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

@ManickaPManickaP left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

@wfurt
wfurt merged commit 7b89c86 into dotnet:mainJul 1, 2022
@wfurt
wfurt deleted the quicSni branch July 1, 2022 17:37
@ManickaPManickaP mentioned this pull request Jul 8, 2022
@ghostghost locked as resolved and limited conversation to collaborators Jul 31, 2022
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[HTTP/3] SNI does not use the Host header value

2 participants

@wfurt@ManickaP
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

add basic support for SNI different than URI in H3 - #71428

Merged
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni
Jul 1, 2022
Merged

add basic support for SNI different than URI in H3#71428
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni

Conversation

@wfurt

Copy link
Copy Markdown
Member

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes#57169

@wfurtwfurt added this to the 7.0.0 milestone Jun 29, 2022
@wfurt
wfurt requested a review from a teamJune 29, 2022 12:58
@wfurtwfurt self-assigned this Jun 29, 2022
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

Issue Details

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes #57169

Author:wfurt
Assignees:wfurt
Labels:

area-System.Net.Quic

Milestone:7.0.0

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason to swap the IsNullOrEmpty check with the equality comparison?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not really. I think _state.TargetHost is unlikely to be null. (or maybe never would)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're in an async method, you can await or you can just use the sync version of the method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While the name is ConnectAsync it does not have async keyword. I was thinking about sync method but that does not have cancellation overload.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think that using sync-over-async on an async method within an async method (albeit only task returning atm) is the best option here.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can switch to Dns.GetHostAddresses and give up on cancellation completely. cc: @stephentoub for any additional suggestions.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

QuicException?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is what we get in HTTP/Sockets and in case GetHostAddressesAsync fail to resolve. I'm not 100% we would ever get empty list without failure but if we would I did not want to cause index errors. I'm open to QuicException but fail to resolve may not be IOException.

@ManickaPManickaPJun 29, 2022

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fail to resolve may not be IOException

Why?

We should then reconsider inheriting QuicException from IOException, but we shouldn't throw SocketException from S.N.Quic.

cc @rzikm

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as I mentioned we may do it anyway if Dns.GetHostAddressesAsync fails. Unless you want to catch it and throw something else in both cases. We can certainly do it as well.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

@ManickaPManickaP left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

@wfurt
wfurt merged commit 7b89c86 into dotnet:mainJul 1, 2022
@wfurt
wfurt deleted the quicSni branch July 1, 2022 17:37
@ManickaPManickaP mentioned this pull request Jul 8, 2022
@ghostghost locked as resolved and limited conversation to collaborators Jul 31, 2022
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[HTTP/3] SNI does not use the Host header value

2 participants

@wfurt@ManickaP
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

add basic support for SNI different than URI in H3 - #71428

Merged
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni
Jul 1, 2022
Merged

add basic support for SNI different than URI in H3#71428
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni

Conversation

@wfurt

Copy link
Copy Markdown
Member

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes#57169

@wfurtwfurt added this to the 7.0.0 milestone Jun 29, 2022
@wfurt
wfurt requested a review from a teamJune 29, 2022 12:58
@wfurtwfurt self-assigned this Jun 29, 2022
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

Issue Details

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes #57169

Author:wfurt
Assignees:wfurt
Labels:

area-System.Net.Quic

Milestone:7.0.0

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason to swap the IsNullOrEmpty check with the equality comparison?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not really. I think _state.TargetHost is unlikely to be null. (or maybe never would)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're in an async method, you can await or you can just use the sync version of the method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While the name is ConnectAsync it does not have async keyword. I was thinking about sync method but that does not have cancellation overload.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think that using sync-over-async on an async method within an async method (albeit only task returning atm) is the best option here.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can switch to Dns.GetHostAddresses and give up on cancellation completely. cc: @stephentoub for any additional suggestions.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

QuicException?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is what we get in HTTP/Sockets and in case GetHostAddressesAsync fail to resolve. I'm not 100% we would ever get empty list without failure but if we would I did not want to cause index errors. I'm open to QuicException but fail to resolve may not be IOException.

@ManickaPManickaPJun 29, 2022

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fail to resolve may not be IOException

Why?

We should then reconsider inheriting QuicException from IOException, but we shouldn't throw SocketException from S.N.Quic.

cc @rzikm

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as I mentioned we may do it anyway if Dns.GetHostAddressesAsync fails. Unless you want to catch it and throw something else in both cases. We can certainly do it as well.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

@ManickaPManickaP left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

@wfurt
wfurt merged commit 7b89c86 into dotnet:mainJul 1, 2022
@wfurt
wfurt deleted the quicSni branch July 1, 2022 17:37
@ManickaPManickaP mentioned this pull request Jul 8, 2022
@ghostghost locked as resolved and limited conversation to collaborators Jul 31, 2022
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[HTTP/3] SNI does not use the Host header value

2 participants

@wfurt@ManickaP
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

add basic support for SNI different than URI in H3 - #71428

Merged
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni
Jul 1, 2022
Merged

add basic support for SNI different than URI in H3#71428
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni

Conversation

@wfurt

Copy link
Copy Markdown
Member

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes#57169

@wfurtwfurt added this to the 7.0.0 milestone Jun 29, 2022
@wfurt
wfurt requested a review from a teamJune 29, 2022 12:58
@wfurtwfurt self-assigned this Jun 29, 2022
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

Issue Details

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes #57169

Author:wfurt
Assignees:wfurt
Labels:

area-System.Net.Quic

Milestone:7.0.0

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason to swap the IsNullOrEmpty check with the equality comparison?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not really. I think _state.TargetHost is unlikely to be null. (or maybe never would)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're in an async method, you can await or you can just use the sync version of the method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While the name is ConnectAsync it does not have async keyword. I was thinking about sync method but that does not have cancellation overload.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think that using sync-over-async on an async method within an async method (albeit only task returning atm) is the best option here.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can switch to Dns.GetHostAddresses and give up on cancellation completely. cc: @stephentoub for any additional suggestions.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

QuicException?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is what we get in HTTP/Sockets and in case GetHostAddressesAsync fail to resolve. I'm not 100% we would ever get empty list without failure but if we would I did not want to cause index errors. I'm open to QuicException but fail to resolve may not be IOException.

@ManickaPManickaPJun 29, 2022

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fail to resolve may not be IOException

Why?

We should then reconsider inheriting QuicException from IOException, but we shouldn't throw SocketException from S.N.Quic.

cc @rzikm

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as I mentioned we may do it anyway if Dns.GetHostAddressesAsync fails. Unless you want to catch it and throw something else in both cases. We can certainly do it as well.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

@ManickaPManickaP left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

@wfurt
wfurt merged commit 7b89c86 into dotnet:mainJul 1, 2022
@wfurt
wfurt deleted the quicSni branch July 1, 2022 17:37
@ManickaPManickaP mentioned this pull request Jul 8, 2022
@ghostghost locked as resolved and limited conversation to collaborators Jul 31, 2022
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[HTTP/3] SNI does not use the Host header value

2 participants

@wfurt@ManickaP
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

add basic support for SNI different than URI in H3 - #71428

Merged
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni
Jul 1, 2022
Merged

add basic support for SNI different than URI in H3#71428
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni

Conversation

@wfurt

Copy link
Copy Markdown
Member

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes#57169

@wfurtwfurt added this to the 7.0.0 milestone Jun 29, 2022
@wfurt
wfurt requested a review from a teamJune 29, 2022 12:58
@wfurtwfurt self-assigned this Jun 29, 2022
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

Issue Details

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes #57169

Author:wfurt
Assignees:wfurt
Labels:

area-System.Net.Quic

Milestone:7.0.0

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason to swap the IsNullOrEmpty check with the equality comparison?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not really. I think _state.TargetHost is unlikely to be null. (or maybe never would)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're in an async method, you can await or you can just use the sync version of the method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While the name is ConnectAsync it does not have async keyword. I was thinking about sync method but that does not have cancellation overload.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think that using sync-over-async on an async method within an async method (albeit only task returning atm) is the best option here.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can switch to Dns.GetHostAddresses and give up on cancellation completely. cc: @stephentoub for any additional suggestions.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

QuicException?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is what we get in HTTP/Sockets and in case GetHostAddressesAsync fail to resolve. I'm not 100% we would ever get empty list without failure but if we would I did not want to cause index errors. I'm open to QuicException but fail to resolve may not be IOException.

@ManickaPManickaPJun 29, 2022

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fail to resolve may not be IOException

Why?

We should then reconsider inheriting QuicException from IOException, but we shouldn't throw SocketException from S.N.Quic.

cc @rzikm

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as I mentioned we may do it anyway if Dns.GetHostAddressesAsync fails. Unless you want to catch it and throw something else in both cases. We can certainly do it as well.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

@ManickaPManickaP left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

@wfurt
wfurt merged commit 7b89c86 into dotnet:mainJul 1, 2022
@wfurt
wfurt deleted the quicSni branch July 1, 2022 17:37
@ManickaPManickaP mentioned this pull request Jul 8, 2022
@ghostghost locked as resolved and limited conversation to collaborators Jul 31, 2022
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[HTTP/3] SNI does not use the Host header value

2 participants

@wfurt@ManickaP
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

add basic support for SNI different than URI in H3 - #71428

Merged
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni
Jul 1, 2022
Merged

add basic support for SNI different than URI in H3#71428
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni

Conversation

@wfurt

Copy link
Copy Markdown
Member

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes#57169

@wfurtwfurt added this to the 7.0.0 milestone Jun 29, 2022
@wfurt
wfurt requested a review from a teamJune 29, 2022 12:58
@wfurtwfurt self-assigned this Jun 29, 2022
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

Issue Details

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes #57169

Author:wfurt
Assignees:wfurt
Labels:

area-System.Net.Quic

Milestone:7.0.0

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason to swap the IsNullOrEmpty check with the equality comparison?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not really. I think _state.TargetHost is unlikely to be null. (or maybe never would)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're in an async method, you can await or you can just use the sync version of the method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While the name is ConnectAsync it does not have async keyword. I was thinking about sync method but that does not have cancellation overload.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think that using sync-over-async on an async method within an async method (albeit only task returning atm) is the best option here.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can switch to Dns.GetHostAddresses and give up on cancellation completely. cc: @stephentoub for any additional suggestions.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

QuicException?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is what we get in HTTP/Sockets and in case GetHostAddressesAsync fail to resolve. I'm not 100% we would ever get empty list without failure but if we would I did not want to cause index errors. I'm open to QuicException but fail to resolve may not be IOException.

@ManickaPManickaPJun 29, 2022

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fail to resolve may not be IOException

Why?

We should then reconsider inheriting QuicException from IOException, but we shouldn't throw SocketException from S.N.Quic.

cc @rzikm

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as I mentioned we may do it anyway if Dns.GetHostAddressesAsync fails. Unless you want to catch it and throw something else in both cases. We can certainly do it as well.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

@ManickaPManickaP left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

@wfurt
wfurt merged commit 7b89c86 into dotnet:mainJul 1, 2022
@wfurt
wfurt deleted the quicSni branch July 1, 2022 17:37
@ManickaPManickaP mentioned this pull request Jul 8, 2022
@ghostghost locked as resolved and limited conversation to collaborators Jul 31, 2022
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[HTTP/3] SNI does not use the Host header value

2 participants

@wfurt@ManickaP
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

add basic support for SNI different than URI in H3 - #71428

Merged
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni
Jul 1, 2022
Merged

add basic support for SNI different than URI in H3#71428
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni

Conversation

@wfurt

Copy link
Copy Markdown
Member

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes#57169

@wfurtwfurt added this to the 7.0.0 milestone Jun 29, 2022
@wfurt
wfurt requested a review from a teamJune 29, 2022 12:58
@wfurtwfurt self-assigned this Jun 29, 2022
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

Issue Details

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes #57169

Author:wfurt
Assignees:wfurt
Labels:

area-System.Net.Quic

Milestone:7.0.0

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason to swap the IsNullOrEmpty check with the equality comparison?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not really. I think _state.TargetHost is unlikely to be null. (or maybe never would)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're in an async method, you can await or you can just use the sync version of the method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While the name is ConnectAsync it does not have async keyword. I was thinking about sync method but that does not have cancellation overload.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think that using sync-over-async on an async method within an async method (albeit only task returning atm) is the best option here.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can switch to Dns.GetHostAddresses and give up on cancellation completely. cc: @stephentoub for any additional suggestions.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

QuicException?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is what we get in HTTP/Sockets and in case GetHostAddressesAsync fail to resolve. I'm not 100% we would ever get empty list without failure but if we would I did not want to cause index errors. I'm open to QuicException but fail to resolve may not be IOException.

@ManickaPManickaPJun 29, 2022

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fail to resolve may not be IOException

Why?

We should then reconsider inheriting QuicException from IOException, but we shouldn't throw SocketException from S.N.Quic.

cc @rzikm

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as I mentioned we may do it anyway if Dns.GetHostAddressesAsync fails. Unless you want to catch it and throw something else in both cases. We can certainly do it as well.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

@ManickaPManickaP left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

@wfurt
wfurt merged commit 7b89c86 into dotnet:mainJul 1, 2022
@wfurt
wfurt deleted the quicSni branch July 1, 2022 17:37
@ManickaPManickaP mentioned this pull request Jul 8, 2022
@ghostghost locked as resolved and limited conversation to collaborators Jul 31, 2022
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[HTTP/3] SNI does not use the Host header value

2 participants

@wfurt@ManickaP
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

add basic support for SNI different than URI in H3 - #71428

Merged
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni
Jul 1, 2022
Merged

add basic support for SNI different than URI in H3#71428
wfurt merged 2 commits into
dotnet:mainfrom
wfurt:quicSni

Conversation

@wfurt

Copy link
Copy Markdown
Member

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes#57169

@wfurtwfurt added this to the 7.0.0 milestone Jun 29, 2022
@wfurt
wfurt requested a review from a teamJune 29, 2022 12:58
@wfurtwfurt self-assigned this Jun 29, 2022
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

Issue Details

We had minimal support for cases with IP address. This extends that with simple DNS lookup. While we can get more than one address and in Sockets we would try to try them all, this PR simply mimics MsQuic and only use first IP.
That may be sufficient as this scenario mostly involve testing. Also in the future we can enhance whole connect (or MsQuic) to do something better.

fixes #57169

Author:wfurt
Assignees:wfurt
Labels:

area-System.Net.Quic

Milestone:7.0.0

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason to swap the IsNullOrEmpty check with the equality comparison?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not really. I think _state.TargetHost is unlikely to be null. (or maybe never would)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You're in an async method, you can await or you can just use the sync version of the method.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

While the name is ConnectAsync it does not have async keyword. I was thinking about sync method but that does not have cancellation overload.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think that using sync-over-async on an async method within an async method (albeit only task returning atm) is the best option here.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I can switch to Dns.GetHostAddresses and give up on cancellation completely. cc: @stephentoub for any additional suggestions.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

QuicException?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is what we get in HTTP/Sockets and in case GetHostAddressesAsync fail to resolve. I'm not 100% we would ever get empty list without failure but if we would I did not want to cause index errors. I'm open to QuicException but fail to resolve may not be IOException.

@ManickaPManickaPJun 29, 2022

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fail to resolve may not be IOException

Why?

We should then reconsider inheriting QuicException from IOException, but we shouldn't throw SocketException from S.N.Quic.

cc @rzikm

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as I mentioned we may do it anyway if Dns.GetHostAddressesAsync fails. Unless you want to catch it and throw something else in both cases. We can certainly do it as well.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

@ManickaPManickaP left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!

cancellationToken.ThrowIfCancellationRequested();
if (addresses.Length == 0)
{
throw new SocketException((int)SocketError.HostNotFound);

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Baaah, I'm not sure, let's keep the SocketException for now to be consistent with NameResolution class. We can revisit this in the future if it'll cause confusion.

// If the name is actually IP address we can use it to make at least some cases work for people
// who want to bypass DNS but connect to specific virtual host.
if (!string.IsNullOrEmpty(_state.TargetHost) && !dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && IPAddress.TryParse(dnsHost, out IPAddress? address))
if (!dnsHost.Equals(_state.TargetHost, StringComparison.InvariantCultureIgnoreCase) && !string.IsNullOrEmpty(_state.TargetHost))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was just asking because you swapped them, I don't mind either way.

}
else
{
IPAddress[] addresses = Dns.GetHostAddressesAsync(dnsHost, cancellationToken).GetAwaiter().GetResult();

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Once I merge this with the static ConnectAsync, I can take the full advantage of the async and call await. So I guess it doesn't matter much here atm.

@wfurt
wfurt merged commit 7b89c86 into dotnet:mainJul 1, 2022
@wfurt
wfurt deleted the quicSni branch July 1, 2022 17:37
@ManickaPManickaP mentioned this pull request Jul 8, 2022
@ghostghost locked as resolved and limited conversation to collaborators Jul 31, 2022
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[HTTP/3] SNI does not use the Host header value

2 participants

@wfurt@ManickaP