diff --git a/src/utils.py b/src/utils.py index bfb80a2..054b7c3 100644 --- a/src/utils.py +++ b/src/utils.py @@ -46,13 +46,15 @@ if len(logger.handlers) == 0: # v2.1.0 did via camoufox's disable_coop=True) restores that access, and the # solver then clicks the checkbox successfully. # -# It is not a demonstrated win: from a datacenter IP Cloudflare rejects the -# click regardless -- measured across eight sites, nine clicks, and an -# undetectable shadow-root patch -- so no outcome changed here. It is kept for -# parity with v2, which users report worked on these sites, because reaching -# the checkbox is a precondition for ever passing an interactive challenge and -# Byparr mostly runs from residential addresses that Cloudflare treats far -# better than CI does. +# The COOP/COEP pair is not a demonstrated win: toggling it changed no outcome +# on any site measured, from either a datacenter or a residential address. It is +# kept for parity with v2.1.0, which clears the interactive challenge where this +# stack does not, because reaching the checkbox is a precondition for ever +# passing one. +# +# devtools.jsonview.enabled is load-bearing and must stay. Firefox renders +# application/json in a viewer whose CSP blocks eval, so page.evaluate() dies +# with "call to eval() blocked by CSP" and /v1 500s on every JSON API (#394). BROWSER_PREFS = { "devtools.jsonview.enabled": False, "browser.tabs.remote.useCrossOriginOpenerPolicy": False, diff --git a/tests/main_test.py b/tests/main_test.py index 9c1209b..c6c4dc9 100644 --- a/tests/main_test.py +++ b/tests/main_test.py @@ -35,14 +35,29 @@ test_websites = [ 'https://www.yggtorrent.top/engine/search?do=search&order=desc&sort=publish_date&name="UNESCAPED"+"DOUBLEQUOTES"&category=2145', ] -# Cloudflare hands these its interactive checkbox challenge and then refuses the -# click from datacenter ranges: the widget goes to "verifying you are human" and -# comes back as a fresh unchecked box, indefinitely. Measured over four fresh -# navigations and nine clicks, and reproduced from two unrelated hosting -# providers on two architectures -- it is the visitor's IP being judged, not our -# code. They still run rather than being skipped, so a real regression is -# visible in the report and a pass is recorded as xpass, but the runner's luck -# with Cloudflare cannot turn the build red. +# Cloudflare hands these its interactive checkbox challenge. The press lands on +# the widget's visible pixels and Cloudflare declines it, returning a fresh +# unchecked box indefinitely. +# +# This is our browser stack, not the visitor's address. Measured 2026-08-16 from +# one datacenter IP within the same hour: byparr v2.1.0 +# (ghcr.io/thephaseless/byparr:2.1.0, camoufox) cleared ext.to in 18s, +# speed.cd/login in 20s and extratorrent.st in 19s, each returning cf_clearance. +# No configuration of the current invisible_playwright stack clears any of them: +# tested with and without new_context(), with and without the shadow-root init +# script, with and without the COOP/COEP prefs, and with both locator.click() +# and a pixel press. +# +# Two candidate explanations were measured and eliminated. The JS fingerprint is +# not it -- camoufox is the less coherent of the two (no WebGL at all, oscpu +# leaking Linux under a Windows UA) and passes anyway. The TLS handshake is not +# it either -- setting security.ssl3.ecdhe_ecdsa_aes_128_sha=True reproduces +# camoufox's JA4 byte for byte (t13d1717h2_5b57614c22b0_3cbfd9057e0d) and the +# challenge is still refused. +# +# They run rather than being skipped, so a real regression stays visible in the +# report and a pass is recorded as xpass, but a Cloudflare verdict we do not yet +# understand cannot turn the build red. datacenter_hostile_websites = [ "https://ext.to/", # "https://www.ygg.re/", @@ -84,7 +99,10 @@ def test_bypass(website: str): @pytest.mark.xfail( - reason="Cloudflare refuses the checkbox click from datacenter IPs", + reason=( + "Cloudflare's interactive challenge refuses the press on " + "invisible_playwright; v2.1.0's camoufox clears these from the same IP" + ), strict=False, ) @pytest.mark.parametrize("website", datacenter_hostile_websites)