cmcfarlen opened a new pull request, #13781:
URL: https://github.com/apache/trafficserver/pull/13781

   Final cherry-pick for the 10.2.1 release: **#13725** (`738cd651`), *Include 
signature
   algorithms in JA4 fingerprints*, from the `For v10.2.1` column of the
   [ATS v10.2.x project](https://github.com/orgs/apache/projects/573).
   
   This one was held back from the 2026-10-01 batch (#13775) while its 
`Incompatible` label was
   discussed. The label has since been removed, so it lands now, timed with the 
rest of 10.2.1.
   
   ### Operator impact — please note in the release notes
   
   This changes the `c` section of nearly every JA4 fingerprint these plugins 
emit, bringing it
   in line with the [JA4 
spec](https://github.com/FoxIO-LLC/ja4/blob/main/technical_details/JA4.md)
   and with FoxIO's reference implementations. Stored fingerprints, and any 
abuse_shield rules or
   allow/deny lists built from ATS-generated JA4 values, need to be regenerated.
   
   ### Out-of-order pick, verified by composition
   
   On master the JA4 changes merged #13725 → #13728 → #13719, but #13728 and 
#13719 already
   landed on 10.2.x in #13775, so this pick applies the *earliest* of the three 
onto a branch that
   already has the later two. It applied with no conflicts, and rather than 
trust that, the result
   was checked by composition: every file the three PRs touch was compared 
against master at
   `a2416f28` (the state right after all three), and only those three commits 
touch these files in
   that range.
   
   9 of 11 files are now **identical to master**. The two that differ are 
pre-existing 10.2.x
   drift, unrelated to JA4 and confirmed present before this pick:
   
   - `ja4_fingerprint/plugin.cc` — master's `JA4_data` struct comes from #13013 
(ASAN plugin
     fixes), not on this branch, so 10.2.x keeps the older `std::string *` 
user-arg form. #13725's
     additions compile against it unchanged.
   - `jax_fingerprint/ja4/tls_client_hello_summary.cc` — the local `DbgCtl` and 
include reshuffle
     come from #13586 (abuse_shield plugin), not on this branch.
   
   ### AuTest harness adaptation
   
   The new `jax_fingerprint_sigalgs.test.py` used master's 
`ts.Disk.ssl_multicert_yaml`; converted
   to 10.2.x's flat `ssl_multicert_config` form and folded into the commit via 
`--fixup` +
   `--autosquash`. The test self-guards with 
`Condition.PluginExists('jax_fingerprint.so')`, and
   the branch's jax plugin already accepts the `--standalone` / `--method` / 
`--log-filename`
   options it passes. The doc hunk is plain prose and adds no cross-reference 
targets.
   
   ### Local verification (macOS, `dev` preset, JA4/JAX enabled)
   
   - `cmake --build build-dev -- -k 0` — clean.
   - `ctest -j4` — 128/129; only `test_jsonrpcserver` fails, the known 
macOS-local
     unix-socket/restart timing flake.
   - `test_ja4` and `test_jax` pass, including the spec's worked example now 
asserting the
     published `t13d1516h2_8daaf6152771_e5627efa2ab1`.
   - The new AuTest is not run by this preset on macOS — this CI run is its 
gate.
   
   Draft on purpose: to be landed by fast-forward once CI is green, not merged 
via the UI.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to