From 2bc1230252ee990b1fc916fc2d60e76752d68ee1 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 22:08:52 +0200 Subject: [PATCH] The certificate bed's backend is a real server: its netcat loop never listened MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Every request through the proxy was refused by the backend, which read as the certificate never arriving and hid behind the authority's refusal — until the second authority issued one and the request behind the handshake still failed. --- test/integration/certificates.test.ts | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/test/integration/certificates.test.ts b/test/integration/certificates.test.ts index 30fc1b4..59a32f7 100644 --- a/test/integration/certificates.test.ts +++ b/test/integration/certificates.test.ts @@ -135,9 +135,18 @@ before(async () => { given: [{ from: "photos", node: "", at: "", values: { name: NAME, port: 8080 } }], }))} > ${ACME}/routes.json`, ); - await must( - `nohup sh -c 'while true; do printf "HTTP/1.1 200 OK\\r\\nContent-Length: 5\\r\\n\\r\\nhello" | nc -l -p 8080 -q 1; done' >/dev/null 2>&1 &`, - ); + // A real small server, not a netcat loop: the loop's `nc -l -p … -q` is not this machine's netcat, + // so it never listened, and every request through the proxy was refused by the backend — which + // read as the certificate never arriving, and hid behind the authority's refusal until the + // second authority issued one. + await must(`mkdir -p ${ACME}/www && printf hello > ${ACME}/www/index.html`); + await must(`nohup python3 -m http.server 8080 --bind 127.0.0.1 --directory ${ACME}/www >${ACME}/backend.log 2>&1 &`); + let backend = false; + for (let i = 0; i < 20 && !backend; i++) { + ({ ok: backend } = await on(`curl -sf http://127.0.0.1:8080/ -o /dev/null`)); + if (!backend) await new Promise((r) => setTimeout(r, 1000)); + } + assert.ok(backend, `the backend behind the route never answered:\n${(await on(`cat ${ACME}/backend.log`)).out}`); }, { timeout: 1_200_000 }); after(async () => {