Skip to content

TLS ECH: cleanup tests and state management - #11626

Open
sebastian-carpenter wants to merge 1 commit into
wolfSSL:masterfrom
sebastian-carpenter:tls-ech-tweaks
Open

sebastian-carpenter wants to merge 1 commit into
wolfSSL:masterfrom
sebastian-carpenter:tls-ech-tweaks

Conversation

@sebastian-carpenter

@sebastian-carpenter sebastian-carpenter commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Description

Breaking some changes out of #10913.

Code:

  • The ECH configs are now accessed only through the ech struct instead of the CTX as well
    • This is to prepare for when the CTX switch is supported in the above mentioned PR
  • ECH response is now set at an appropriate time, rather than at TLSX_PopulateExtensions()
  • Reworked ECH checks to be more readable / cleaner checks
  • Prevent some unnecessary computations

Testing:

  • Generation of reject configs is much faster. It now reuses the old ones just flipping a bit to invalidate them
    • Related tests now only work for the default HPKE algorithm
  • Inlined some checks to prevent unnecessary handshakes
  • Some accept/connect/dohandshake checks were cast to (void). Removed this and checked the return.
  • Cleaned up various tests

Examples:

  • Log the ECH status

Openssl Interop:

  • Reject config is now built at runtime instead of from a stored config
  • Improved reliability of --reject arg in the script

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

@sebastian-carpenter sebastian-carpenter self-assigned this Oct 1, 2026
Copilot AI balanced review requested due to automatic review settings October 1, 2026 23:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The refactor removes the only HRR coverage for clearing retry configurations after authentication failure.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Cleans up TLS ECH state handling, diagnostics, interoperability, and tests.

Changes:

  • Routes ECH configuration and response state through the ECH extension.
  • Expands and simplifies ECH/SNI tests.
  • Adds ECH status logging and runtime-generated rejection configs.
File Description
wolfssl/​test.h Adds ECH status output helper.
tests/​api.c Refactors and expands ECH tests.
src/​tls13.c Simplifies ECH state access during TLS 1.3 handshakes.
src/​tls.c Moves ECH response setup and config access into parsing.
examples/​server/​server.c Logs server ECH status.
examples/​client/​client.c Logs client ECH status.
.github/​scripts/​openssl-ech.sh Generates rejection configs dynamically and improves synchronization.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tests/api.c
@padelsbach

Copy link
Copy Markdown
Contributor

jenkins retest this please

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11626

Scan targets checked: wolfssl-src, wolfssl-bugs
Coverage: 3 of 4 in-scope changed file(s) opened by the reviewer; not opened: wolfssl/test.h

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants