Repository navigation
Avoid building SslStreamCertificateContexts inside Listener in Quic tests - #134418
Merged
rzikm merged 3 commits intoOct 8, 2026
Merged
Conversation
|
Azure Pipelines: Successfully started running 3 pipeline(s). 13 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
|
Tagging subscribers to this area: @dotnet/area-meta |
3 tasks
Member
Author
|
/azp run runtime-libraries-coreclr outerloop |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
Preserve the original loopback certificate test while adding independently selectable server/client provisioning arms, standalone chain probes, and a diagnostic runbook. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Remove the completed diagnostic experiment and its runbook. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
rzikm
force-pushed
the
rzikm/quic-certificate-handshake-timeout
branch
from
October 7, 2026 12:54
95fc7d2 to
a6d2907
Compare
Contributor
|
Tagging subscribers to this area: @karelz, @dotnet/ncl |
rzikm
marked this pull request as ready for review
October 7, 2026 14:17
This was referenced Oct 7, 2026
Closed
Member
Author
|
/ba-g SmtpClientTlsTest failures are known and unrelated |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Related to #133645.
This change prevents QUIC tests from repeatedly constructing certificate contexts from leaf certificates when the issuer material is already known:
SslStreamCertificateContextfor the default server certificate and one for the default client certificate at theQuicTestCollectionfixture lifetime.SslServerAuthenticationOptionsprecedence.ConnectWithCertificateForLoopbackIP_IndicatesExpectedError.The temporary certificate-provisioning experiment, selectors, standalone chain probes, and runbook have been removed.
Motivation
On Windows with Schannel, a leaf-only QUIC credential configuration can cause
MsQuicConfigurationto build anSslStreamCertificateContextwith online issuer discovery before native credential acquisition. Controlled responder delays demonstrated that this managed context construction can perform two sequential AIA downloads and exceed the test's ten-second handshake timeout.After the AIA-related runtime changes in #134585, native MsQuic credential acquisition is cache-only, but the preceding managed context construction can still perform issuer discovery. In an isolated server-credential control with six-second AIA response delays:
The same delayed-AIA control caused the leaf-only QUIC handshake to time out, while the prebuilt-context configuration connected without AIA requests. This establishes the blocking mechanism under controlled fault injection; it does not prove that every historical failure had the same external delay source.
Behavioral invariants
The loopback certificate test retains:
TargetHost = "localhost".127.0.0.1and::1IP SANs.badhostcertificate.X509RevocationMode.NoCheckclient semantics and the existing ten-second handshake deadline.No retry, timeout increase, validation bypass, or trusted-root change is introduced.
Validation
After rebasing onto
mainat122c28feba4:Result: 479 total, 478 passed, 1 expected platform skip, 0 failures/errors. No unobserved exceptions were reported.
Note
This PR description was generated with GitHub Copilot.