From: Yeonggi Kim <[email protected]>

Add a new QUIC regtest for Retry emission through a listener bound on a
wildcard address. The Retry must be emitted with the address targeted
by the client as source, else a client relying on a connected socket
drops it and the handshake never completes.

This test relies on two haproxy instances, as QUIC client and server.
The QUIC server is reached through 127.0.0.2, while the kernel would
select 127.0.0.1 as source to reply to the client. As 127.0.0.2 is a
local address by default only on Linux, the BSD, macOS, Solaris and
generic targets are excluded. The wildcard listener port reuses the
number of the TCP port allocated by vtest for the same frontend, and the
CLI is used to wait for the QUIC listener to be ready before starting
the client.

This test is related to github issue #3503. As it requires QUIC backend
support, it may only be backported to 3.3 and above, along with the fix
"BUG/MEDIUM: quic: use datagram destination as source for Retry".
---
 reg-tests/quic/retry_wildcard.vtc | 75 +++++++++++++++++++++++++++++++
 1 file changed, 75 insertions(+)
 create mode 100644 reg-tests/quic/retry_wildcard.vtc

diff --git a/reg-tests/quic/retry_wildcard.vtc 
b/reg-tests/quic/retry_wildcard.vtc
new file mode 100644
index 000000000..f56da410d
--- /dev/null
+++ b/reg-tests/quic/retry_wildcard.vtc
@@ -0,0 +1,75 @@
+varnishtest "QUIC Retry source address on a wildcard listener"
+
+# A QUIC listener bound on a wildcard address must use the address targeted by
+# the client as source for its replies, as the client socket may be connected
+# and will silently drop datagrams from another address. Retry packets are
+# emitted before any connection exists, directly through the listener socket.
+#
+# Here the QUIC server is reached through 127.0.0.2 while the kernel would
+# select 127.0.0.1 as source to reply to the client. The QUIC backend socket
+# is connected so a Retry emitted without an explicit source address is dropped
+# and the handshake never completes.
+#
+# This relies on 127.0.0.2 being a local address, which by default is only the
+# case on Linux. As vtest can only provide sockets bound on 127.0.0.1, the
+# wildcard QUIC listener port reuses the number of the TCP port allocated by
+# vtest for the same frontend.
+
+#EXCLUDE_TARGETS=freebsd,freebsd-glibc,osx,openbsd,netbsd,dragonfly,solaris,generic
+#REGTEST_TYPE=bug
+
+feature cmd "$HAPROXY_PROGRAM -cc 'version_atleast(3.3-dev2)'"
+# QUIC backend are not supported with USE_QUIC_OPENSSL_COMPAT
+feature cmd "$HAPROXY_PROGRAM -cc 'feature(QUIC) && 
!feature(QUIC_OPENSSL_COMPAT) && !feature(OPENSSL_WOLFSSL)'"
+feature ignore_unknown_macro
+
+haproxy ha_qsrv -conf {
+    global
+        .if feature(THREAD)
+            thread-groups 1
+        .endif
+
+    defaults
+        mode http
+        timeout connect "${HAPROXY_TEST_TIMEOUT-5s}"
+        timeout client  "${HAPROXY_TEST_TIMEOUT-5s}"
+        timeout server  "${HAPROXY_TEST_TIMEOUT-5s}"
+
+    frontend fe
+        bind "fd@${fe_tcp}"
+        bind [email protected]:${ha_qsrv_fe_tcp_port} ssl crt 
${testdir}/certs/common.pem quic-force-retry
+        http-request return status 200
+} -start
+
+# The wildcard QUIC listener is bound by haproxy itself and not by vtest, so
+# wait for the CLI to answer, which ensures all listeners are ready.
+haproxy ha_qsrv -cli {
+    send "show info"
+    expect ~ "Name: HAProxy"
+}
+
+haproxy ha_qcli -conf {
+    global
+        expose-experimental-directives
+        .if feature(THREAD)
+            thread-groups 1
+        .endif
+
+    defaults
+        mode http
+        # fail fast if the QUIC handshake cannot complete
+        timeout connect 3s
+        timeout client  "${HAPROXY_TEST_TIMEOUT-5s}"
+        timeout server  "${HAPROXY_TEST_TIMEOUT-5s}"
+        retries 0
+
+    listen li
+        bind "fd@${fe}"
+        server quic [email protected]:${ha_qsrv_fe_tcp_port} ssl verify none
+} -start
+
+client c1 -connect ${ha_qcli_fe_sock} {
+    txreq
+    rxresp
+    expect resp.status == 200
+} -run
-- 
2.50.1 (Apple Git-155)



Reply via email to