Skip to content

feat: add ClientHello record fragmentation - #419

Open
thesinakamali wants to merge 1 commit into
refraction-networking:masterfrom
thesinakamali:feat/clienthello-fragmentation
Open

thesinakamali wants to merge 1 commit into
refraction-networking:masterfrom
thesinakamali:feat/clienthello-fragmentation

Conversation

@thesinakamali

Copy link
Copy Markdown
Contributor

Add a Config.FragmentClientHello callback that, when set, splits the ClientHello across two TLS handshake records instead of sending it in one. The callback receives the marshaled ClientHello and returns the offset to split at; returning an offset outside 0 < n < len sends a single record, so callers can decide per connection. This mainly addresses middleboxes that pattern match on the ClientHello without reassembling the record layer. If the field is nil, behavior is unchanged.

Fragmentation is applied only to client side non-QUIC, non-ECH ClientHellos in the initial handshake, which includes HelloRetryRequest retries but not renegotiation. Splitting a handshake message across records is permitted by RFC 8446, Section 5.1.

Changes:

  • Add ClientHelloFragFunc type and FragmentClientHello field to Config in common.go
  • Include FragmentClientHello in Config.Clone()
  • Add ClientHelloFragmented field to ConnectionMetrics in common.go
  • Add shouldFragmentClientHello and writeFragmentedClientHello to Conn in u_client_hello_fragmentation.go
  • Add tests in u_client_hello_fragmentation_test.go covering split offsets, invalid-offset fallback, HRR, ECH, QUIC, and renegotiation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant