Copilot commented on code in PR #13795:
URL: https://github.com/apache/trafficserver/pull/13795#discussion_r4189064656


##########
src/iocore/net/SSLNetVConnection.cc:
##########
@@ -2016,6 +2016,11 @@ SSLNetVConnection::_isTryingRenegotiation() const
 shared_SSL_CTX
 SSLNetVConnection::_lookupContextByName(const std::string &servername, 
SSLCertContextType ctxType)
 {
+  // Return null if this vc is already configured as a tunnel
+  if (this->attributes == HttpProxyPort::TRANSPORT_BLIND_TUNNEL) {
+    return nullptr;

Review Comment:
   Add an AuTest that configures a transparent TLS port with a name-specific 
`action: tunnel` entry plus a `dest_ip: "*"` fallback, and verify under 
BoringSSL that an unmatched fallback cannot replace the tunnel decision. The 
updated dual-certificate test never enables transparent mode or `action: 
tunnel`, so it does not exercise this guard and the production regression could 
return unnoticed.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to