Skip to content

[T3 Connect] Negotiate HTTP/2 for procedure HTTPS requests - #6012

Draft
bradleyshep wants to merge 1 commit into
masterfrom
bradley/procedure-http2
Draft

bradleyshep wants to merge 1 commit into
masterfrom
bradley/procedure-http2

Conversation

@bradleyshep

@bradleyshep bradleyshep commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Part of the work to move T3 Code's T3 Connect relay onto SpacetimeDB.

Description of Changes

This enables reqwest's native-tls-alpn feature, so the native-tls connector offers ALPN h2. Without it, every outbound ctx.http.fetch over HTTPS was pinned to HTTP/1.1, and HTTP/2-only APIs could not be reached from modules. One example is Apple's APNs, which modules need for iOS push notifications.

Split out of #6005 / #6006.

API and ABI breaking changes

None.

Rollback safety impact

n/a

Expected complexity level and risk

  1. It's a one-line feature flag. Servers that only speak HTTP/1.1 keep negotiating HTTP/1.1.

Worth a reviewer's eye: the flag is on the workspace reqwest, and release builds compile the CLI, updater and standalone server together, so the CLI and updater also start offering HTTP/2 over TLS. Scoping it to spacetimedb-core wouldn't change that, because Cargo unifies features across one build. Maincloud and GitHub select HTTP/2 when offered; the S3 bucket for client binaries stays on HTTP/1.1. spacetime server ping maincloud works with a build of this branch; publish, logs and spacetime version upgrade over HTTP/2 weren't tested.

Testing

  • New test http_request_offers_h2_over_tls (behind allow_loopback_http_for_tests, like the decompression tests beside it): a procedure HTTPS request made through InstanceEnv::http_request offers h2 via ALPN in its TLS ClientHello. Without this change it offers no ALPN protocols, so an HTTP/2-only server such as APNs has nothing to select.
  • The test fails with native-tls-alpn removed
  • Not covered: a full HTTP/2 round trip. The procedure client only trusts the OS certificate store, so a loopback server can't complete the handshake without a production seam (e.g. a shared client builder a test could add a root certificate to).
  • Note: CI's cargo test --all doesn't enable allow_loopback_http_for_tests, so this test doesn't run in CI on its own; [T3 Connect] Reuse one HTTP client per replica for procedure requests #6023 adds a focused CI step that runs the loopback HTTP tests, including this one once both land.
  • CI build

@alexscomm

Copy link
Copy Markdown

I need this fix for iOS push notifications.

@bradleyshep
bradleyshep force-pushed the bradley/procedure-http2 branch from dab05ee to 9624673 Compare September 30, 2026 15:57
@bradleyshep
bradleyshep force-pushed the bradley/procedure-http2 branch from 9624673 to 03e80c8 Compare September 30, 2026 17:45
@bradleyshep bradleyshep changed the title Negotiate HTTP/2 for procedure HTTPS requests [T3 Connect] Negotiate HTTP/2 for procedure HTTPS requests Sep 30, 2026
Enable reqwest's `native-tls-alpn` feature so the native-tls connector
offers ALPN `h2`. Without it every outbound `ctx.http.fetch` over HTTPS
was pinned to HTTP/1.1, and HTTP/2-only APIs such as Apple's APNs
(iOS push notifications) could not be reached from modules.
@bradleyshep
bradleyshep force-pushed the bradley/procedure-http2 branch from 03e80c8 to adce315 Compare October 1, 2026 17:26

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants