Skip to content

[HTTP/2] Complete remaining verification evidence #15

Description

@gsmlg

Context

The HTTP/2 wire-profile, connection pooling, multi-stream, HPACK, flow-control, h2c, OTP :ssl, ex_ssl, fingerprint observation, capture-manifest tooling, and independent hyper-h2 smoke path are implemented on main (HEAD 3bf5ec6). Current local evidence includes the full umbrella test suites, Dialyzer, Credo on Elixir 1.19.5/OTP 28, formatting, docs generation, and bounded bridge-budget measurements.

This issue tracks the evidence that is intentionally still outstanding; synthetic fixtures must not be promoted to browser evidence.

Remaining work

  • Capture a real browser HTTP/2 wire sample for a named product/version/platform and reproducible scenario, including cold and reused connection context, independent capture-tool provenance, redacted request/peer settings, raw fixture SHA-256, license/source metadata, matched fields, and known differences. Import it through HTTP.HTTP2.ProfileCapture, compare it with HTTP.HTTP2.Fingerprint.diff/2, and keep the matching scope explicit.
  • Run the exact CI toolchain (Elixir 1.18 / OTP 28) or an equivalent pinned environment for compile, tests, Credo, Dialyzer, and docs. Record commands and results separately from the local Elixir 1.19.5/OTP 28 evidence.
  • Add a long-duration real-socket churn/streaming benchmark with varying payload sizes that records owner/bridge process memory, mailbox length, retained binaries, queue peaks, connection reuse, and cleanup after drain/GOAWAY. Do not report throughput alone.
  • Expand independent interoperability beyond the pinned hyper-h2 single-peer smoke test to cover the relevant cold/warm HPACK, concurrent streams, flow-control, and malformed-input cases, with externally generated/decoded bytes.
  • Close the remaining report caveat around broader concurrent queue/drain evidence and map each completed result to the acceptance IDs in docs/HTTP2_IMPLEMENTATION_PLAN.md.

Acceptance criteria

  • browser_profile_verified is changed from false only with a traceable real-browser fixture and manifest; synthetic or simulator output is not accepted.
  • Exact CI-version gates have independently recorded results, or the environment limitation is explicitly retained as a blocker.
  • Long-duration resource measurements show bounded queue/bridge retention and clean lifecycle teardown under the documented workload.
  • Independent interoperability results identify implementation/version, fixture source, wire direction, and pass/fail scope.
  • docs/HTTP2_IMPLEMENTATION_REPORT.md, docs/HTTP2_FINGERPRINTS.md, and docs/HTTP2_PROFILE_CAPTURE.md reflect the evidence without overstating completion.

Current limitations

The connected Chrome DevTools session currently has pages for unrelated projects and no traceable http_fetch browser capture. Until such a sample is supplied or collected in a reproducible environment, browser_profile_verified must remain false.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions