bneradt commented on PR #13763:
URL: https://github.com/apache/trafficserver/pull/13763#issuecomment-5955289501
@bryancall I reproduced the environment and protocol differences and updated
the patch and description.
- **Inbound handshake reconciliation:** our validation checkout included
#13761, now merged as `fe7cfc94278d05e0eb772f08a14628a0141437e3`. The
standalone head of this PR predates that fix. I rebuilt the same OpenSSL 4.0.2
ATS configuration with only that patch removed/restored: without it the first
`remap_https` HTTPS run stalls after curl's handshake and reaches a
three-second diagnostic client deadline; restoring it makes all eight runs
pass. The description now explicitly identifies that prerequisite and does not
claim that this test-only PR alone makes the Fedora 45 suite green. These runs
still use Fedora's `openssl-libs-4.0.2-2.fc45.aarch64`, not 4.0.3.
- **Remaining fixtures:** the patch deliberately scopes the framing changes
to the affected empty responses and is not a comprehensive audit of every TLS
origin. I reran the unchanged `tls_verify_base`: all four runs pass while curl
negotiates HTTP/2. A diagnostic copy forcing HTTP/1.1 hangs on its first empty
200 response and exits curl 28 at the three-second deadline. Thus the
HTTPS-only fixtures are not necessarily hidden behind the handshake failure
once #13761 is present; the negotiated client protocol also changes the
completion path. The description now names the remaining unframed registrations
as follow-up work and does not claim they are safe. HTTP/2 success does not
establish the validity of the abrupt TLS origin shutdown either.
- **Plaintext remap coverage:** the plaintext and TLS origins now have
separate response objects in both remap variants. Only the TLS origin is
framed. I restored the plaintext `remap-https-200.gold` and `_3.gold` files to
their original chunked-response assertions.
- **Fallback registrations:** the comments now identify an explicitly
registered `/` response and state that the default lookup key is `{PATH}`, so
the response applies to every Host header. They no longer describe the
registrations as microserver's built-in default.
- **Other observations:** the description explains why the timeout replay
anchor's `Content-Length: 16` was ineffective. The core tunnel defect is
tracked in #13784 with a standalone reproducer and the source citations; this
PR does not fix it. The AuTest 2of4 rerun has also passed ([build
44597](https://ci.trafficserver.apache.org/job/Github_Builds/job/autest/44597/)).
Formatting and the incremental build succeeded. All 18 final focused AuTests
passed against the native ARM Fedora 45/OpenSSL 4.0.2 validation installation,
including the updated remap golds, client-certificate tests,
verification/override tests, certificate selection, inactive-client timeout,
and proxy protocol.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]