Conversation
The "multiple before a single HEADERS" test picked each interim status from 100..199 and expected Mint to accept it. Mint rejects 101 in HTTP/2 since RFC 9113 section 8.6 doesn't support the Switching Protocols status, so the test failed for seeds that drew 101 (for example --seed 338383). The statuses are now drawn from 100..199 without 101.
The fuzz property required zero body bytes for every 204 response. A 2xx response to CONNECT establishes a tunnel and the DATA frames after it are tunnel data (RFC 9110 section 9.3.6, RFC 9113 section 8.5), so the model now follows the RFC and exempts CONNECT 2xx responses from both the bodiless and the content-length checks. Mint answers a CONNECT 204 followed by DATA with a stream error, which the property still accepts.
Client operations are {index, :body, ref_index, chunk} or
{index, :request, {method, body}}, but the comprehension that picks the
operations for the current chunk only matched four-element tuples, so
request operations were dropped and no request was ever issued in the
middle of a scenario. Operations are now matched on their index whatever
their size.
TestServer.listen_and_accept/0 opened a TLS listen socket that nothing closed, so every HTTP/2 fuzz scenario left a listener behind: 200 scenarios grew the tcp_inet ports from 1 to 201 and the processes from 125 to 527. The accepting task now closes the listen socket once it has accepted the single connection it serves, and the same 200 scenarios end with 1 port and 127 processes.
The model seeded the server's view of the connection window from Mint's own receive_window_remaining, so a client that kept a 16,777,216-byte window internally without sending the WINDOW_UPDATE that announces it went unnoticed. The view now starts at the 65,535-byte initial window (RFC 9113 section 6.9.2) and only grows by the stream 0 WINDOW_UPDATE frames the test server decodes from what Mint writes, starting with the one that may follow the client preface. The preface is still required to be a SETTINGS frame followed by at most that WINDOW_UPDATE, and anything else fails the scenario before it runs.
Coverage Report for CI Build 5Coverage decreased (-0.1%) to 90.406%Details
Uncovered ChangesNo uncovered changes found. Coverage Regressions2 previously-covered lines in 1 file lost coverage.
Coverage Stats
馃挍 - Coveralls |
Responses with more than one transfer coding could come up, as a generated Transfer-Encoding: chunked plus a random Transfer-Encoding: gzip header, but no invariant compared the body size Mint delivered with what the framing gives, so treating the first coding as the framing one went unnoticed. Chunked bodies are now also sent with "gzip, chunked", which RFC 9112 section 6.3 frames as chunked, and with "chunked, gzip", whose body is read until the connection closes and includes the chunk framing. Each generated framing carries the body length it gives, and the model checks the body size of completed responses to the initial requests. That holds when the bytes are unmutated, every initial request was issued, and the response and the ones before it are 1.1 responses to GET or POST with a 200, 404 or 500 status, no 101, and no extra framing headers. Responses to requests issued mid-scenario aren't checked. A response read until close takes the rest of the bytes, so no response after it has a known size.
ericmj
force-pushed
the
test-followups
branch
from
September 28, 2026 15:04
a6c9e49 to
5c51742
Compare
ericmj
marked this pull request as ready for review
September 28, 2026 16:23
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes to the fuzz properties from #520 and a flaky HTTP/2 test, one commit each, meant to be rebase-merged rather than squashed. No library changes.
--seed 338383).FUZZ_RUNS=200the property was left with 201 open ports.gzip, chunkedandchunked, gzip, and checks the body size of completed responses to the initial requests against the length their framing gives. Reverting to the first transfer coding now fails the property.The default
mix testtime is unchanged within run-to-run noise.