moonchen commented on issue #13730: URL: https://github.com/apache/trafficserver/issues/13730#issuecomment-5959541251
Following up from #13729, let’s track both callback resume fixes here. These apply to **OpenSSL and BoringSSL**. - **ClientHello — `ssl_client_hello_callback()`:** Skip completed hooks on retry, even after the handshake advances to SNI. This prevents dispatching SNI hooks with the ClientHello event. - **Certificate — `ssl_cert_callback()`:** Skip completed certificate selection and cert hooks. Preserve the plugin-selected certificate and finish any remaining CA and session-ticket setup. This also prevents dispatching verify-client hooks with the cert event. Make these callbacks safe to retry: resume from the saved state, skip completed hooks, and finish any remaining finalization. Regression tests should cover: - Delayed ClientHello hooks followed by delayed cert hooks. - Correct hook event IDs. - Switching certificate contexts during a cert-hook pause and preserving the plugin-selected certificate after resuming. - No verify-client hook invocation when client authentication is disabled. - Both backends, with TLS 1.2 and TLS 1.3. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
