Skip to content

feat(proxy): add an operator HTTP/2 opt-out - #15318

Open
Kizuno18 wants to merge 2 commits into
diegosouzapw:release/v3.8.52from
Kizuno18:kz/http1-optout
Open

Kizuno18 wants to merge 2 commits into
diegosouzapw:release/v3.8.52from
Kizuno18:kz/http1-optout

Conversation

@Kizuno18

@Kizuno18 Kizuno18 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Adds an operator opt-out for HTTP/2 without rewriting compiled bundles. Closes #15313.

OMNIROUTE_UPSTREAM_HTTP2_ENABLED keeps the current enabled default; explicit false, 0, no, or off forces HTTP/1.1 on the shared Undici direct/proxy dispatchers and both relay agents. The proxy construction threads it through both requestTls and proxyTls, merging the existing family pin. The SOCKS connector inherits the shared TLS options. Normal and fresh-socket retry paths are covered.

Connection limits, keep-alive, pipelining, authentication, and certificate validation stay intact. Changing the flag requires a restart because dispatchers are cached and relay agents are created at startup. It does not control wreq or provider-specific transports, and is not a quota fix or proof that HTTP/2 caused an OOM.

The new loopback tests failed before the change with protocol: '2.0' despite the opt-out and pass afterward with protocol: '1.1'. They use a trusted temporary certificate, an HTTP/2 origin with HTTP/1 fallback, authenticated HTTP/HTTPS CONNECT proxies, and a SOCKS5 proxy. Coverage includes a 4 MiB POST, concurrent POSTs, relay retries, the enabled default, and rejection of an untrusted certificate.

Validation on Node 24.19.0:

  • New tests plus dispatcher/family/concurrency/retry/relay/SOCKS regressions: 64/64 passed.
  • npm run test:vitest: 54 files, 493/493 passed.
  • Scoped ESLint and direct tsc --noEmit -p open-sse/tsconfig.json passed.
  • npm run check:docs-all passed with command-local Git Bash shell/npm launchers on Windows. Existing advisory version/count drift remains.
  • Normal commit hooks passed without disabling Husky or using a stash.

The broader tls-proxy-context.test.ts run has six baseline failures; I reproduced the same failures in the second worktree with unmodified transport sources and the same dependencies. Those files were not changed. Full native unit-suite coverage and a production build/deployment were not run for this PR.

@Kizuno18
Kizuno18 requested a review from diegosouzapw as a code owner October 2, 2026 01:29

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(backend): add an HTTP/1.1 opt-out across Undici dispatchers

1 participant