Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 14 additions & 4 deletions .github/workflows/chaos.yml
Original file line number Diff line number Diff line change
Expand Up @@ -117,9 +117,11 @@ jobs:
fi
score_line=$(grep -iE 'Score:' "$txt" | tail -1)
echo "=== $score_line ==="
# Baseline 2026-05-29: Score 143/161 (18 failed). Gate against
# regressions — the passed count must not drop below baseline.
BASELINE=143
# Baseline 2026-05-29: Score 155/161 (6 failed) after the #47
# RFC fixes (Host validation, Date, HEAD, CONNECT, empty TE,
# asterisk-form). Gate against regressions — the passed count
# must not drop below baseline.
BASELINE=155
passed=$(sed -nE 's/.*Score:[[:space:]]*([0-9]+)\/[0-9]+.*/\1/p' <<<"$score_line")
echo "passed=$passed baseline=$BASELINE"
if [ -z "$passed" ]; then
Expand Down Expand Up @@ -163,7 +165,15 @@ jobs:
git config user.email '41898282+github-actions[bot]@users.noreply.github.com'
git add docs/http11probe-report.md docs/http11probe-results.json
git commit -m "ci: refresh Http11Probe conformance report [skip ci]"
git push origin HEAD:main
# main may have advanced while this long job ran — rebase the
# report commit onto the latest tip and retry rather than fail
# on a non-fast-forward push.
for attempt in 1 2 3; do
if git pull --rebase origin main && git push origin HEAD:main; then
break
fi
echo "push attempt $attempt failed — retrying"; sleep 5
done

# --------------------------------------------------------------------
# Scheduler chaos: run the whole phpt suite under a randomised
Expand Down
21 changes: 4 additions & 17 deletions docs/http11probe-report.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,42 +2,30 @@

HTTP/1.1 RFC 9110/9112 compliance + request-smuggling + malformed-input + header-normalization + caching/cookie probe ([MDA2AV/Http11Probe](https://github.com/MDA2AV/Http11Probe)).

_Generated: 2026-05-29 14:39 UTC — refreshed weekly by `.github/workflows/chaos.yml`._
_Generated: 2026-05-29 16:41 UTC — refreshed weekly by `.github/workflows/chaos.yml`._

## Summary

| Total | Scored | Passed | Warnings | Failed | Errors |
|------:|-------:|-------:|---------:|-------:|-------:|
| 215 | 161 | 125 | 18 | 18 | 0 |
| 215 | 161 | 137 | 18 | 6 | 0 |

## Failures (22)
## Failures (10)

| Category | Check | RFC level | Expected | Got |
|----------|-------|-----------|----------|-----|
| Compliance | `COMP-ASTERISK-WITH-GET` | Must | 400, close, or timeout = warn | status=200 conn=Open |
| Compliance | `COMP-CHUNKED-BODY` | Must | 2xx + echo | status=200 conn=Open |
| Compliance | `COMP-CHUNKED-EXTENSION` | Must | 2xx preferred; 400 warns | status=200 conn=Open |
| Compliance | `COMP-CHUNKED-HEX-UPPERCASE` | Must | 2xx + echo | status=200 conn=Open |
| Compliance | `COMP-CHUNKED-MULTI` | Must | 2xx + echo | status=200 conn=Open |
| Compliance | `COMP-CHUNKED-TRAILER-VALID` | Must | 2xx + echo | status=200 conn=Open |
| Compliance | `COMP-DATE-HEADER` | Must | 2xx with Date header | status=200 conn=Open |
| Compliance | `COMP-DUPLICATE-HOST-SAME` | Must | 400 | status=200 conn=Open |
| Compliance | `COMP-HEAD-NO-BODY` | Must | 2xx with no body | status=200 conn=Open |
| Compliance | `COMP-HOST-EMPTY-VALUE` | Must | 400 or close | status=200 conn=Open |
| Compliance | `COMP-HOST-WITH-PATH` | Must | 400 or close | status=200 conn=Open |
| Compliance | `COMP-HOST-WITH-USERINFO` | Must | 400 or close | status=200 conn=Open |
| Compliance | `COMP-HTTP12-VERSION` | May | 200 or 505 | status=400 conn=ClosedByServer |
| Compliance | `COMP-METHOD-CONNECT` | Should | 400/405/501 or close | status=200 conn=Open |
| Compliance | `COMP-POST-CL-BODY` | Must | 2xx + echo | status=200 conn=Open |
| Compliance | `RFC9110-5.4-DUPLICATE-HOST` | Must | 400 | status=200 conn=Open |
| Compliance | `RFC9112-7.1-MISSING-HOST` | Must | 400 | status=200 conn=Open |
| Cookies | `COOK-ECHO` | NotApplicable | 2xx with Cookie in body | status=200 conn=Open |
| Cookies | `COOK-PARSED-BASIC` | NotApplicable | 2xx with foo=bar in body | status=200 conn=Open |
| Cookies | `COOK-PARSED-MULTI` | NotApplicable | 2xx with a=1, b=2, c=3 in body | status=200 conn=Open |
| Smuggling | `SMUG-MULTIPLE-HOST-COMMA` | Must | 400 or close | status=200 conn=Open |
| Smuggling | `SMUG-TE-EMPTY-VALUE` | Must | 400 or close | status=200 conn=Open |

## Warnings (40)
## Warnings (39)

| Category | Check | RFC level | Expected | Got |
|----------|-------|-----------|----------|-----|
Expand All @@ -49,7 +37,6 @@ _Generated: 2026-05-29 14:39 UTC — refreshed weekly by `.github/workflows/chao
| Capabilities | `CAP-LAST-MODIFIED-304` | Should | 304 | status=200 conn=Open |
| Compliance | `COMP-405-ALLOW` | Must | 405 + Allow header | status=200 conn=Open |
| Compliance | `COMP-ACCEPT-NONSENSE` | Should | 406 or 2xx | status=200 conn=Open |
| Compliance | `COMP-DATE-FORMAT` | Should | IMF-fixdate format | status=200 conn=Open |
| Compliance | `COMP-DUPLICATE-CT` | Should | 400 or 2xx | status=200 conn=Open |
| Compliance | `COMP-EXPECT-UNKNOWN` | May | 417 or 2xx | status=200 conn=Open |
| Compliance | `COMP-GET-WITH-CL-BODY` | May | 400 or 2xx | status=200 conn=Open |
Expand Down
Loading
Loading