Re: [PATCH] ssl-bump only bump handled CONNECT requests

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Sat, 07 May 2011 14:24:05 +1200

On 07/05/11 05:55, Tsantilas Christos wrote:
> On 05/06/2011 06:21 PM, Amos Jeffries wrote:
>> This patch makes Squid only ssl-bump CONNECT requests if they are about
>> to be tunneled.
>>
>> Currently all CONNECT requests are bumped, even if the redirectors and
>> adaptors have determined a 3xx, 4xx or 5xx reply should happen.
>
> Unfortunately one more ssl-bump related bug.
> This patch required..
>
>>
>> Whether Squid should be reaching this part of the code when a reply is
>> known is out of scope for this fix. This logic change needs to happen
>> anyway.
>>
>> Amos
>

Alex pointed me at the correct code for judging adaptor. It seems they
duplicate the reply handling form ACLs to short-circuit the reply. So
are not affected. Redirectors are.

Applied to trunk as revno 11417.

Amos

-- 
Please be using
   Current Stable Squid 2.7.STABLE9 or 3.1.12
   Beta testers wanted for 3.2.0.7 and 3.1.12.1
Received on Sat May 07 2011 - 02:24:23 MDT

This archive was generated by hypermail 2.2.0 : Sat May 07 2011 - 12:00:04 MDT