]> git.ipfire.org Git - thirdparty/haproxy.git/commitdiff
REGTESTS: workaround for a crash with recent libressl on http-reuse sni
authorAmaury Denoyelle <adenoyelle@haproxy.com>
Fri, 19 Feb 2021 14:37:40 +0000 (15:37 +0100)
committerWilly Tarreau <w@1wt.eu>
Fri, 19 Feb 2021 15:47:20 +0000 (16:47 +0100)
Disable the ssl-reuse for the sni test on http_reuse_conn_hash vtc. This
seems to be the origin of a crash with libressl environment from 3.2.2
up to 3.3.1 included.

For now, it is not determined if the root cause is in haproxy or
libressl.

Please look for the github issue #1115 for all the details.

reg-tests/connection/http_reuse_conn_hash.vtc

index 991e86f7a8e411599d9a222ae831fa362a02ff7a..81d16f96371e98124a5ecb00170ebcb24c2ae324 100644 (file)
@@ -9,9 +9,11 @@ haproxy h1 -conf {
                mode http
 
        # sni
+       # ssl-reuse is disabled because it seems to be the origin of a crash with
+       # libressl from 3.2.2 on the CI (cf github issue #1115)
        listen sender-sni
                bind "fd@${feS_sni}"
-               server srv2 ${h1_feR_ssl_addr}:${h1_feR_ssl_port} ssl sni "req.hdr(x-sni)" verify none pool-low-conn 2
+               server srv2 ${h1_feR_ssl_addr}:${h1_feR_ssl_port} ssl sni "req.hdr(x-sni)" verify none pool-low-conn 2 no-ssl-reuse
 
        # set-dst
        # specify dst1_addr for server, which should be identical to dst2_addr