haproxy/reg-tests
Willy Tarreau 00941af7b7 BUG/MEDIUM: mux-h2: fix the detection of the ext connect support
As reported by Huangbin Zhan (@zhanhb) in github issue #3355, latest
commit 96f7ff4fdd ("MINOR: mux-h2: add a new message flag to indicate
ext connect support") was not correct and can break RFC8441-compliant
clients, as it did for them with a variant of Chrome 142.

The problem is that while RFC9113 says that new pseudo-headers are only
permitted with *negotiated* extensions, and RFC8441 doesn't indicate
whether or not SETTINGS_ENABLE_CONNECT_PROTOCOL is needed from clients,
it only says that clients know that servers support the extension when
seeing it in their settings and can use it, which seems to imply that
they don't need to send it to indicate their willingness to use it.
This also means that the server cannot know if a client is expected to
use it or not by default. It only know that a client is not allowed to
use it if the server didn't emit support mentioning it, which haproxy
can do using h2-workaround-bogus-websocket-clients.

Thus the fix proposed by @zhanhb is right, when presetting the flag for
the parser to indicate whether or not we're willing to accept RFC8441's
:protocol pseudo-header, we should:
  - consider the received setting on the backend side (though the
    pseudo-header is neither used nor supported there, but at least
    we pass the info regarding the support of the extension)
  - consider the configuration for the frontend (since it's the only
    place where we can decide on support or not)

This patch does just that and reverts the accompanying changes to the
regtests that made them want to see the client's setting. It must be
backported to 2.6.

In the mean time, placing this option in the global section will force
the clients to downgrade to h1:

    h2-workaround-bogus-websocket-clients

Many thanks again to @zhanbb this feedback and proposing a tested fix.
2026-05-07 17:34:39 +02:00
..
balance BUG/MAJOR: lb-chash: fix key calculation when using default hash-key id 2025-10-16 10:43:09 +02:00
cache REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
checks MINOR: http_fetch: Add support for checks to unique-id fetch 2026-04-13 20:02:21 +02:00
compression REGTESTS: ssl: Move all the SSL certificates, keys, crt-lists inside "certs" directory 2025-12-08 10:40:59 +01:00
connection MEDIUM: mux-h1: Return an error on h2 upgrade attempts if not allowed 2026-05-07 14:59:28 +02:00
contrib REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
converter REGTESTS: ssl: Add tests for new aes cbc converters 2026-01-15 10:56:27 +01:00
filters REGTESTS: add a test for "filter-sequence" directive 2026-04-03 12:10:32 +02:00
http-capture REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
http-cookies REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
http-errorfiles REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
http-messaging BUG/MEDIUM: mux-h2: fix the detection of the ext connect support 2026-05-07 17:34:39 +02:00
http-rules REG-TESTS: map_redirect: Don't use hdr_dom in ACLs with "-m end" matching method 2025-09-01 15:45:05 +02:00
http-set-timeout REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
jwt REGTESTS: Never reuse server connection in jwt/jws_verify.vtc 2026-04-23 10:56:06 +02:00
log REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
lua REGTESTS: lua: add tune.lua.openlibs to all Lua reg-tests 2026-04-09 14:32:12 +02:00
mailers REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
mcli Revert "BUG/MEDIUM: cli: fix master CLI connection slot leak on client disconnect" 2026-05-07 16:37:33 +02:00
peers REGTESTS: ssl: Move all the SSL certificates, keys, crt-lists inside "certs" directory 2025-12-08 10:40:59 +01:00
pki REGTESTS: pki: add a pki for SSL tests 2023-10-09 21:54:31 +02:00
proxy REGTESTS: complete "del backend" with unnamed defaults ref free 2026-03-02 14:15:53 +01:00
quic REGTESTS: add QUIC test for max-total streams setting 2026-04-15 15:18:37 +02:00
sample_fetches REGTESTS: explicitly use "balance roundrobin" where RR is needed 2025-09-04 08:18:53 +02:00
seamless-reload REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
server REGTESTS: Never reuse server connection in server/cli_delete_dynamic_server.vtc 2026-04-23 10:56:10 +02:00
spoe REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
ssl REGTESTS: ssl: mark ssl_dh.vtc as broken 2026-04-22 15:30:48 +02:00
startup REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
stats MEDIUM: stats: add persistent state to typed output format 2025-07-01 14:15:03 +02:00
stick-table REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
stickiness REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
stream MEDIUM: proxy: force traffic on unpublished/disabled backends 2026-01-15 09:08:19 +01:00
tcp-rules REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
webstats REGTESTS: restrict execution to a single thread group 2025-06-30 18:54:35 +02:00
README CI: vtest: Rely on VTest2 to run regression tests 2025-05-27 14:38:46 +02:00

                 * Regression testing for HAProxy with VTest *


This little README file is about how to compile and run vtest test case files (VTC files)
to test HAProxy for any regression.

To do so, you will have to compile vtest program sources which depends on
Varnish cache application sources. vtest, formerly varnishtest, is a very useful
program which has been developed to test Varnish cache application. vtest has been
modified in collaboration with Varnish cache conceptor Poul-Henning Kamp to support
HAProxy in addition to Varnish cache.

See also: doc/regression-testing.txt

* vtest compilation *

    $ git clone https://github.com/vtest/VTest2

    $ cd VTest

    $ make vtest

  Then vtest program may be found at the root directory of vtest sources directory.
  The Varnish cache manuals are located in 'man' directory of Varnish cache sources
  directory. You will have to have a look at varnishtest(7) and vtc(7) manuals to
  use vtest.

  Some information may also be found in doc/regression-testing.txt in HAProxy
  sources.

  Note that VTC files for Varnish cache may be found in bin/varnishtest/tests directory
  of Varnish cache sources directory which may be found here:
  https://github.com/varnishcache/varnish-cache


* vtest execution *

  You must set HAPROXY_PROGRAM environment variable to give the location
  of the HAProxy program to test to vtest:

    $ HAPROXY_PROGRAM=<my haproxy program> vtest ...

  The HAProxy VTC files found in HAProxy sources may be run with the reg-tests
  Makefile target. You must set the VTEST_PROGRAM environment variable to
  give the location of the vtest program which has been previously compiled.

    $ VTEST_PROGRAM=<my vtest program> make reg-tests

  "reg-tests" Makefile target run scripts/run-regtest.sh script.
  To get more information about this script run it with --help option.

  Note that vtest is run with -t10 and -l option. -l option is to keep
  keep vtest temporary directory in case of failed test cases. core files
  may be found in this directory (if enabled by ulimit).


* vtest patches for HAProxy VTC files *

  When producing a patch to add a VTC regression testing file to reg-tests directory,
  please follow these simple rules:

    - If your VTC file needs others files, if possible, use the same basename as that
      of the VTC file,
    - Put these files in a directory with the same name as the code area concerned
      by the bug ('peers', 'lua', 'acl' etc).

Please note that most tests use a common set of timeouts defined by the
environment variable HAPROXY_TEST_TIMEOUT. As much as possible, for regular I/O
(i.e. not errors), please try to reuse that setting so that the value may
easily be adjusted when running in some particularly slow environments, or be
shortened to fail faster on developers' machines.