bneradt commented on PR #13763:
URL: https://github.com/apache/trafficserver/pull/13763#issuecomment-5955289501

   @bryancall I reproduced the environment and protocol differences and updated 
the patch and description.
   
   - **Inbound handshake reconciliation:** our validation checkout included 
#13761, now merged as `fe7cfc94278d05e0eb772f08a14628a0141437e3`. The 
standalone head of this PR predates that fix. I rebuilt the same OpenSSL 4.0.2 
ATS configuration with only that patch removed/restored: without it the first 
`remap_https` HTTPS run stalls after curl's handshake and reaches a 
three-second diagnostic client deadline; restoring it makes all eight runs 
pass. The description now explicitly identifies that prerequisite and does not 
claim that this test-only PR alone makes the Fedora 45 suite green. These runs 
still use Fedora's `openssl-libs-4.0.2-2.fc45.aarch64`, not 4.0.3.
   - **Remaining fixtures:** the patch deliberately scopes the framing changes 
to the affected empty responses and is not a comprehensive audit of every TLS 
origin. I reran the unchanged `tls_verify_base`: all four runs pass while curl 
negotiates HTTP/2. A diagnostic copy forcing HTTP/1.1 hangs on its first empty 
200 response and exits curl 28 at the three-second deadline. Thus the 
HTTPS-only fixtures are not necessarily hidden behind the handshake failure 
once #13761 is present; the negotiated client protocol also changes the 
completion path. The description now names the remaining unframed registrations 
as follow-up work and does not claim they are safe. HTTP/2 success does not 
establish the validity of the abrupt TLS origin shutdown either.
   - **Plaintext remap coverage:** the plaintext and TLS origins now have 
separate response objects in both remap variants. Only the TLS origin is 
framed. I restored the plaintext `remap-https-200.gold` and `_3.gold` files to 
their original chunked-response assertions.
   - **Fallback registrations:** the comments now identify an explicitly 
registered `/` response and state that the default lookup key is `{PATH}`, so 
the response applies to every Host header. They no longer describe the 
registrations as microserver's built-in default.
   - **Other observations:** the description explains why the timeout replay 
anchor's `Content-Length: 16` was ineffective. The core tunnel defect is 
tracked in #13784 with a standalone reproducer and the source citations; this 
PR does not fix it. The AuTest 2of4 rerun has also passed ([build 
44597](https://ci.trafficserver.apache.org/job/Github_Builds/job/autest/44597/)).
   
   Formatting and the incremental build succeeded. All 18 final focused AuTests 
passed against the native ARM Fedora 45/OpenSSL 4.0.2 validation installation, 
including the updated remap golds, client-certificate tests, 
verification/override tests, certificate selection, inactive-client timeout, 
and proxy protocol.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to