Copilot commented on code in PR #13795:
URL: https://github.com/apache/trafficserver/pull/13795#discussion_r4189064656
##########
src/iocore/net/SSLNetVConnection.cc:
##########
@@ -2016,6 +2016,11 @@ SSLNetVConnection::_isTryingRenegotiation() const
shared_SSL_CTX
SSLNetVConnection::_lookupContextByName(const std::string &servername,
SSLCertContextType ctxType)
{
+ // Return null if this vc is already configured as a tunnel
+ if (this->attributes == HttpProxyPort::TRANSPORT_BLIND_TUNNEL) {
+ return nullptr;
Review Comment:
Add an AuTest that configures a transparent TLS port with a name-specific
`action: tunnel` entry plus a `dest_ip: "*"` fallback, and verify under
BoringSSL that an unmatched fallback cannot replace the tunnel decision. The
updated dual-certificate test never enables transparent mode or `action:
tunnel`, so it does not exercise this guard and the production regression could
return unnoticed.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]