Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SSL is broken in Safari (because of IPv6) #10

Closed
ameshkov opened this issue Nov 9, 2015 · 23 comments
Closed

SSL is broken in Safari (because of IPv6) #10

ameshkov opened this issue Nov 9, 2015 · 23 comments

Comments

@ameshkov
Copy link
Member

ameshkov commented Nov 9, 2015

The issue I noticed with some HTTPS sites not working in Safari still happens. For example, it'll happen if I boot the Mac partition then start Safari and it'll attempt to load my homepage https://news.google.com/ and it'll end up giving off an error. It only happens the first time though when Safari is set to Google News as my homepage. Refreshing the page or opening Google News in a new tab works fine. It's just the first load when it does it.

We have three situations:

  1. IPv6 address is not available (everything is ok)
  2. IPv6 address is available AND IPv6 connectivity is ok (everything works good in this case)
  3. IPv6 address is available AND IPv6 connectivity is NOT ok (that's our issue)

We should detect network change (for instance like it's done here http://stackoverflow.com/questions/11532144/how-to-detect-ip-address-change-on-osx-programmatically-in-c-or-c) and check IPv6 connectivity.

@BooBerry
Copy link

BooBerry commented Nov 9, 2015

Some things to note for this;

  • It only seems to happen on the first page load. Refreshing or re-opening the page in a new tab works fine. To try to reproduce the issue again, you'll need to reboot the Mac.
  • Having Safari set to a HTTPS homepage, in my case https://news.google.com/ and setting Safari to load a home page when opening Safari seems the best way to reproduce this issue.
  • It'll happen randomly on other HTTPS sites - Netflix, Wikipedia, YouTube, Google, etc.

@ameshkov
Copy link
Member Author

ameshkov commented Nov 9, 2015

@AwesomeDonkey one more thing: could you please take a screenshot of the error?

@BooBerry
Copy link

BooBerry commented Nov 9, 2015

Yup, here you go: http://i.imgur.com/OuJ3yXu.png

Sadly it's not very descriptive.

@ameshkov
Copy link
Member Author

ameshkov commented Nov 9, 2015

Good enough, thank you!:)

@BooBerry
Copy link

BooBerry commented Nov 9, 2015

Interesting, it's real easy for me to reproduce repeatedly on https://www.yahoo.com/

@ameshkov
Copy link
Member Author

ameshkov commented Nov 9, 2015

I guess we'll need debug logs here.
@Stillness-2 could you please come here?

@vityevato
Copy link
Member

yes, we need to compile debug build specially for @AwesomeDonkey, and try to receive debug log.

@BooBerry
Copy link

BooBerry commented Nov 9, 2015

Alright, I'll be ready!

@vityevato
Copy link
Member

This is the link to the debug version: https://www.dropbox.com/s/ctig2ihmzqq8i94/Adguard.zip?dl=1

Test instructions.

close all browsers
close Adguard
open debug version Adguard and enter admin login/password when prompt appears
when Adguard becomes «green» close it
open Console.app, and find ProtocolFiltersLog.txt
02

delete ProtocolFiltersLog.txt
then open Safari with a blank page
open debug version Adguard
in Safari, enter https url, for example https://news.google.com/
close Adguard if error occurs.
in Console.app find ProtocolFiltersLog.txt, and send it on devteam@adguard.com

Thank you! :)

@BooBerry
Copy link

Got it, sent it in.

The mail is called Mac Safari ProtocolFiltersLog.txt

@BooBerry
Copy link

Did another from Google News and sent it in, same subject as above with Google News added.

@ameshkov
Copy link
Member Author

@Stillness-2 told me that this issue is more like our old IPv6 problem (when browser decides that ipv6 is available and tries it prior to ipv4).

@BooBerry
Copy link

Interesting. Until yesterday for the last month or so I've had IPv6 disabled. I re-enabled it last night but haven't tried testing Safari again.

@BooBerry
Copy link

Yep, confirmed. With IPv6 re-enabled, Safari seems to be working fine now without this issue.

So I assume this can be fixed, yes?

@ameshkov
Copy link
Member Author

Not yet:) Now we know that the issue is not with SSL, but with our IPv6/IPv4 support:)

We should come up with some way to properly check if IPv6 is available and do not try to handle IPv6 connections in the cases like yours.

So will you be able to test a patch when it's ready?

@ameshkov ameshkov changed the title SSL is broken in Safari SSL is broken in Safari (because of IPv6) Nov 21, 2015
@BooBerry
Copy link

Yep, I can test the patch when it's ready. :)

@ameshkov
Copy link
Member Author

@Stillness-2 I've updated issue text, plz take a look

@ameshkov
Copy link
Member Author

ameshkov commented Dec 2, 2015

Hey @Stillness-2, instead of closing maybe you give @AwesomeDonkey a test build to check it?

@vityevato vityevato reopened this Dec 2, 2015
@vityevato
Copy link
Member

@AwesomeDonkey, new test build: https://www.dropbox.com/s/ctig2ihmzqq8i94/Adguard.zip?dl=1
In this build bug must be fixed.

@BooBerry
Copy link

BooBerry commented Dec 2, 2015

Yep, encountering no more issues here with Safari (posting from it right now). :)

@ameshkov
Copy link
Member Author

ameshkov commented Dec 4, 2015

Thanks god, finally! @Stillness-2 good job, thank you!

@ameshkov
Copy link
Member Author

ameshkov commented Dec 8, 2015

One more thing: we should not cache connectivity check result if it is unsuccessful.

For instance, this may be some sort of a temporary network issue. So if we have cached that unsuccessful result, it will break connection even when network is stable again.

@ameshkov ameshkov reopened this Dec 8, 2015
@vityevato
Copy link
Member

Now, kext caches only positive result of the connection checking. Also cache timeout is 60 sec.

@vityevato vityevato modified the milestone: 1.1.3 Dec 14, 2015
@vityevato vityevato modified the milestones: 1.1.3, 1.1.2-beta Dec 21, 2015
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants