Skip to content

Avoid building SslStreamCertificateContexts inside Listener in Quic tests - #134418

Merged
rzikm merged 3 commits into
dotnet:mainfrom
rzikm:rzikm/quic-certificate-handshake-timeout
Oct 8, 2026
Merged

rzikm merged 3 commits into
dotnet:mainfrom
rzikm:rzikm/quic-certificate-handshake-timeout

Conversation

@rzikm

@rzikm rzikm commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Summary

Related to #133645.

This change prevents QUIC tests from repeatedly constructing certificate contexts from leaf certificates when the issuer material is already known:

  • Cache one offline SslStreamCertificateContext for the default server certificate and one for the default client certificate at the QuicTestCollection fixture lifetime.
  • Reuse those contexts across tests while continuing to give individual test instances disposable certificate clones for assertions.
  • Explicitly clear the cached server context in tests that provide a different certificate or a certificate-selection callback, preserving the intended SslServerAuthenticationOptions precedence.
  • Keep leaf/selection-callback setup in tests whose purpose is to exercise those client-certificate source APIs.
  • Build and pass an offline server context containing the generated issuer chain in ConnectWithCertificateForLoopbackIP_IndicatesExpectedError.

The temporary certificate-provisioning experiment, selectors, standalone chain probes, and runbook have been removed.

Motivation

On Windows with Schannel, a leaf-only QUIC credential configuration can cause MsQuicConfiguration to build an SslStreamCertificateContext with online issuer discovery before native credential acquisition. Controlled responder delays demonstrated that this managed context construction can perform two sequential AIA downloads and exceed the test's ten-second handshake timeout.

After the AIA-related runtime changes in #134585, native MsQuic credential acquisition is cache-only, but the preceding managed context construction can still perform issuer discovery. In an isolated server-credential control with six-second AIA response delays:

  • Leaf-only configuration took 12.231 seconds and issued two AIA requests.
  • A prebuilt offline server context took 44 ms and issued no AIA requests.

The same delayed-AIA control caused the leaf-only QUIC handshake to time out, while the prebuilt-context configuration connected without AIA requests. This establishes the blocking mechanism under controlled fault injection; it does not prove that every historical failure had the same external delay source.

Behavioral invariants

The loopback certificate test retains:

  • TargetHost = "localhost".
  • Both 127.0.0.1 and ::1 IP SANs.
  • The expected DNS mismatch for the badhost certificate.
  • Subject, issuer, and name-mismatch assertions.
  • X509RevocationMode.NoCheck client semantics and the existing ten-second handshake deadline.

No retry, timeout increase, validation bypass, or trusted-root change is introduced.

Validation

After rebasing onto main at 122c28feba4:

.\dotnet.cmd build src\libraries\System.Net.Quic\tests\FunctionalTests\System.Net.Quic.Functional.Tests.csproj /t:Test /p:Outerloop=true

Result: 479 total, 478 passed, 1 expected platform skip, 0 failures/errors. No unobserved exceptions were reported.

Note

This PR description was generated with GitHub Copilot.

@rzikm rzikm added the NO-REVIEW Experimental/testing PR, do NOT review it label Sep 22, 2026
@azure-pipelines

azure-pipelines Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/area-meta
See info in area-owners.md if you want to be subscribed.

@rzikm

rzikm commented Sep 23, 2026

Copy link
Copy Markdown
Member Author

/azp run runtime-libraries-coreclr outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

rzikm and others added 3 commits October 7, 2026 14:50
Preserve the original loopback certificate test while adding independently selectable server/client provisioning arms, standalone chain probes, and a diagnostic runbook.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove the completed diagnostic experiment and its runbook.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@rzikm
rzikm force-pushed the rzikm/quic-certificate-handshake-timeout branch from 95fc7d2 to a6d2907 Compare October 7, 2026 12:54
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @karelz, @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

@rzikm rzikm removed the NO-REVIEW Experimental/testing PR, do NOT review it label Oct 7, 2026
@rzikm
rzikm marked this pull request as ready for review October 7, 2026 14:17
@rzikm rzikm changed the title [Experiment] Diagnose QUIC loopback certificate-chain handshake timeouts Avoid building SslStreamCertificateContexts inside Listener in Quic tests Oct 7, 2026

@ManickaP ManickaP left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hope this helps!

@rzikm

rzikm commented Oct 8, 2026

Copy link
Copy Markdown
Member Author

/ba-g SmtpClientTlsTest failures are known and unrelated

@rzikm
rzikm merged commit 4040599 into dotnet:main Oct 8, 2026
95 of 97 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants