The certificate bed's backend is a real server: its netcat loop never listened
Every request through the proxy was refused by the backend, which read as the certificate never arriving and hid behind the authority's refusal — until the second authority issued one and the request behind the handshake still failed.
This commit is contained in:
@@ -135,9 +135,18 @@ before(async () => {
|
||||
given: [{ from: "photos", node: "", at: "", values: { name: NAME, port: 8080 } }],
|
||||
}))} > ${ACME}/routes.json`,
|
||||
);
|
||||
await must(
|
||||
`nohup sh -c 'while true; do printf "HTTP/1.1 200 OK\\r\\nContent-Length: 5\\r\\n\\r\\nhello" | nc -l -p 8080 -q 1; done' >/dev/null 2>&1 &`,
|
||||
);
|
||||
// A real small server, not a netcat loop: the loop's `nc -l -p … -q` is not this machine's netcat,
|
||||
// so it never listened, and every request through the proxy was refused by the backend — which
|
||||
// read as the certificate never arriving, and hid behind the authority's refusal until the
|
||||
// second authority issued one.
|
||||
await must(`mkdir -p ${ACME}/www && printf hello > ${ACME}/www/index.html`);
|
||||
await must(`nohup python3 -m http.server 8080 --bind 127.0.0.1 --directory ${ACME}/www >${ACME}/backend.log 2>&1 &`);
|
||||
let backend = false;
|
||||
for (let i = 0; i < 20 && !backend; i++) {
|
||||
({ ok: backend } = await on(`curl -sf http://127.0.0.1:8080/ -o /dev/null`));
|
||||
if (!backend) await new Promise((r) => setTimeout(r, 1000));
|
||||
}
|
||||
assert.ok(backend, `the backend behind the route never answered:\n${(await on(`cat ${ACME}/backend.log`)).out}`);
|
||||
}, { timeout: 1_200_000 });
|
||||
|
||||
after(async () => {
|
||||
|
||||
Reference in New Issue
Block a user