mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The rx-stall tests and the background connect timeout test need a local TCP address whose SYNs go unanswered. They build it from a listener whose accept queue is full, which Linux, macOS and Windows leave unanswered. FreeBSD answers such a SYN from its syncache and then resets the connection, so the helper panicked and eleven tests failed in the FreeBSD package build on every branch. On FreeBSD the helper now fills by replacing the listener with a bound socket that does not listen, and drains by listening on it. That address is silent only with net.inet.tcp.blackhole=2 and blackhole_local=1, which also stop every refused connect on the host, so the FreeBSD package workflow runs the tests in two passes: everything else with the settings off, then the blackhole tests alone with them on. A connect that is not silent still fails the helper, naming the settings. Once the helper worked, three tests failed on FreeBSD because they took one read() as one frame: FreeBSD delivered the link announce that follows a msg2 in a read of its own, where Linux returned the two together. The tests now read each frame by its length with the transport's own frame reader, and drain the announces after the handshake.