From: Willy Tarreau Date: Mon, 18 May 2026 15:46:10 +0000 (+0200) Subject: REGTESTS: quic/issuers_chain_path: do not forget to enable QUIC compat mode X-Git-Tag: v3.4-dev13~54 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=fdb569c2eac18da1b3d361e7b53790371b740f8c;p=thirdparty%2Fhaproxy.git REGTESTS: quic/issuers_chain_path: do not forget to enable QUIC compat mode This test is compatible with QUIC_OPENSSL_COMPAT but the "limited-quic" directive was not set, making it fail on older libs with no QUIC support despite being declared as compatible. --- diff --git a/reg-tests/quic/tls13_ssl_crt-list_filters.vtc b/reg-tests/quic/tls13_ssl_crt-list_filters.vtc index 0eb0d14cd..443d9b600 100644 --- a/reg-tests/quic/tls13_ssl_crt-list_filters.vtc +++ b/reg-tests/quic/tls13_ssl_crt-list_filters.vtc @@ -6,6 +6,7 @@ feature cmd "$HAPROXY_PROGRAM -cc 'feature(QUIC) && !feature(QUIC_OPENSSL_COMPAT # Note that USE_OPENSSL is always set if USE_QUIC is set # Same conditions as for ssl/tls13_ssl_crt-list_filters.vtc about TLS library versions feature cmd "$HAPROXY_PROGRAM -cc 'ssllib_name_startswith(OpenSSL) && openssl_version_atleast(1.1.1) || feature(OPENSSL_AWSLC)'" + # This test checks if the multiple certificate types works correctly with the # SNI, and that the negative filters are correctly excluded # diff --git a/reg-tests/ssl/issuers_chain_path.vtci b/reg-tests/ssl/issuers_chain_path.vtci index 0daf7c3c5..8c740698b 100644 --- a/reg-tests/ssl/issuers_chain_path.vtci +++ b/reg-tests/ssl/issuers_chain_path.vtci @@ -6,6 +6,10 @@ haproxy h1 -conf { thread-groups 1 .endif + .if feature(QUIC_OPENSSL_COMPAT) + limited-quic + .endif + stats socket "${tmpdir}/h1/stats" level admin issuers-chain-path "${testdir}/certs/issuers-chain-path/ca/" crt-base "${testdir}/certs/issuers-chain-path"