feat(quic): live interop harness — picoquic Docker + InteropRunner main

Setup for driving the pure-Kotlin QUIC client against real reference
servers, kicking off the live-interop validation that closes the loop on
the audit cycles.

PermissiveCertificateValidator (commonMain test-only):
  Accepts any cert chain and any signature. For local dev servers (picoquic,
  quic-go, nests-rs in Docker) where the system trust store would reject the
  self-signed cert. Documented as test-only — must never be wired into
  production code.

InteropRunner.main (jvmTest):
  Standalone runnable that opens a UDP socket, builds a QuicConnection with
  PermissiveCertificateValidator, drives the handshake under a configurable
  timeout, and reports CONNECTED / HandshakeFailed / Timeout / UdpFailed
  with peer transport parameters on success. Exit code 0 on connect, 1 on
  any failure mode — wirable into CI.

`quic/scripts/run-picoquic.sh`:
  One-line Docker harness that runs Christian Huitema's picoquic reference
  server on UDP 4433. Picoquic is the IETF QUIC WG's reference impl and
  the most permissive target for a fresh client (clear qlog traces, accepts
  a wide range of transport params).

`./gradlew :quic:interop` Gradle task:
  Wraps the runner so live-interop is one command:
    ./gradlew :quic:interop -PinteropHost=127.0.0.1 -PinteropPort=4433
  Validated against a non-running server: returns Timeout cleanly with
  exit 1 (the failure-path proves the harness wires correctly).

Workflow documented in `quic/scripts/README.md` covering picoquic,
quic-go, aioquic, quiche, and the eventual graduation path to the
quic-interop-runner Docker matrix at https://interop.seemann.io.

Next step: actually run picoquic in Docker and chase whatever real-world
incompatibilities surface. Each will be a focused fix commit.

https://claude.ai/code/session_01EC1tfXfap8k8GyKvrxkxZx
This commit is contained in:
Claude
2026-04-25 23:08:18 +00:00
parent bd192fc649
commit d2a10c9e4a
5 changed files with 340 additions and 0 deletions
+25
View File
@@ -99,3 +99,28 @@ kotlin {
}
}
}
/**
* Run the live-interop runner against a real QUIC server. Configure target
* via -PinteropHost=… -PinteropPort=… -PinteropTimeoutSec=…
*
* Usage:
* ./gradlew :quic:interop -PinteropHost=127.0.0.1 -PinteropPort=4433
*/
tasks.register<JavaExec>("interop") {
group = "verification"
description = "Drive QuicConnection against a real QUIC server (default 127.0.0.1:4433)."
dependsOn("jvmTestClasses", "jvmJar")
classpath =
files(
tasks.named("jvmJar"),
configurations.named("jvmTestRuntimeClasspath"),
layout.buildDirectory.dir("classes/kotlin/jvm/test"),
)
mainClass.set("com.vitorpamplona.quic.interop.InteropRunnerKt")
val host = (project.findProperty("interopHost") as? String) ?: "127.0.0.1"
val port = (project.findProperty("interopPort") as? String) ?: "4433"
val timeoutSec = (project.findProperty("interopTimeoutSec") as? String) ?: "10"
args(host, port)
systemProperty("interopTimeoutSec", timeoutSec)
}