[07:22:23.383](0.025s) # setting up data directory # Checking port 52019 # Found port 52019 Name: primary Data directory: /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata Backup directory: /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/backup Archive directory: /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/archives Connection string: port=52019 host=/tmp/4Bh2Zq46x3 Log file: /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log [07:22:23.392](0.009s) # initializing database system by copying initdb template # Running: cp -RPp /tmp/cirrus-ci-build/build/tmp_install/initdb-template /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata # Running: /tmp/cirrus-ci-build/build/src/test/regress/pg_regress --config-auth /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata ### Starting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log -o --cluster-name=primary start waiting for server to start.... done server started # Postmaster PID for node "primary" is 38905 [07:22:23.645](0.252s) ok 1 - ssl_library parameter psql::1: WARNING: roles created by regression test cases should have names starting with "regress_" psql::1: WARNING: roles created by regression test cases should have names starting with "regress_" psql::1: WARNING: roles created by regression test cases should have names starting with "regress_" psql::1: WARNING: roles created by regression test cases should have names starting with "regress_" psql::1: WARNING: databases created by regression test cases should have names including "regression" psql::1: WARNING: databases created by regression test cases should have names including "regression" psql::1: WARNING: databases created by regression test cases should have names including "regression" psql::1: WARNING: databases created by regression test cases should have names including "regression" psql::1: WARNING: databases created by regression test cases should have names including "regression" psql::1: WARNING: databases created by regression test cases should have names including "regression" ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39195 [07:22:24.286](0.641s) # testing password-protected keys ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... stopped waiting pg_ctl: could not start server Examine the log output. # pg_ctl restart failed; see logfile for details: /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log # No postmaster PID for node "primary" [07:22:24.491](0.205s) ok 2 - restart fails with password-protected key file with wrong password ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart pg_ctl: PID file "/tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata/postmaster.pid" does not exist Is server running? trying to start server anyway waiting for server to start.... done server started # Postmaster PID for node "primary" is 39367 [07:22:24.595](0.104s) ok 3 - restart succeeds with password-protected key file ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... stopped waiting pg_ctl: could not start server Examine the log output. # pg_ctl restart failed; see logfile for details: /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log # No postmaster PID for node "primary" [07:22:24.809](0.214s) ok 4 - restart fails with incorrect SSL protocol bounds ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart pg_ctl: PID file "/tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata/postmaster.pid" does not exist Is server running? trying to start server anyway waiting for server to start.... done server started # Postmaster PID for node "primary" is 39484 [07:22:24.913](0.104s) ok 5 - restart succeeds with correct SSL protocol bounds [07:22:24.914](0.001s) # running client tests ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39527 [07:22:25.130](0.216s) ok 6 - server doesn't accept non-SSL connections [07:22:25.130](0.000s) ok 7 - server doesn't accept non-SSL connections: matches [07:22:25.143](0.013s) ok 8 - connect without server root cert sslmode=require [07:22:25.143](0.000s) ok 9 - connect without server root cert sslmode=require: no stderr [07:22:25.149](0.006s) ok 10 - connect without server root cert sslmode=verify-ca [07:22:25.149](0.000s) ok 11 - connect without server root cert sslmode=verify-ca: matches [07:22:25.155](0.006s) ok 12 - connect without server root cert sslmode=verify-full [07:22:25.155](0.000s) ok 13 - connect without server root cert sslmode=verify-full: matches [07:22:25.163](0.008s) ok 14 - connect with wrong server root cert sslmode=require [07:22:25.164](0.000s) ok 15 - connect with wrong server root cert sslmode=require: matches [07:22:25.171](0.008s) ok 16 - connect with wrong server root cert sslmode=verify-ca [07:22:25.172](0.000s) ok 17 - connect with wrong server root cert sslmode=verify-ca: matches [07:22:25.179](0.008s) ok 18 - connect with wrong server root cert sslmode=verify-full [07:22:25.179](0.000s) ok 19 - connect with wrong server root cert sslmode=verify-full: matches [07:22:25.187](0.008s) ok 20 - connect with server CA cert, without root CA [07:22:25.187](0.000s) ok 21 - connect with server CA cert, without root CA: matches [07:22:25.197](0.010s) ok 22 - connect with correct server CA cert file sslmode=require [07:22:25.197](0.000s) ok 23 - connect with correct server CA cert file sslmode=require: no stderr [07:22:25.207](0.009s) ok 24 - connect with correct server CA cert file sslmode=verify-ca [07:22:25.207](0.000s) ok 25 - connect with correct server CA cert file sslmode=verify-ca: no stderr [07:22:25.217](0.010s) ok 26 - connect with correct server CA cert file sslmode=verify-full [07:22:25.217](0.000s) ok 27 - connect with correct server CA cert file sslmode=verify-full: no stderr [07:22:25.227](0.010s) ok 28 - cert root file that contains two certificates, order 1 [07:22:25.228](0.000s) ok 29 - cert root file that contains two certificates, order 1: no stderr [07:22:25.238](0.010s) ok 30 - cert root file that contains two certificates, order 2 [07:22:25.238](0.000s) ok 31 - cert root file that contains two certificates, order 2: no stderr [07:22:25.247](0.010s) ok 32 - connect with sslcertmode=disable [07:22:25.248](0.000s) ok 33 - connect with sslcertmode=disable: no stderr [07:22:25.257](0.009s) ok 34 - connect with sslcertmode=allow [07:22:25.257](0.000s) ok 35 - connect with sslcertmode=allow: no stderr [07:22:25.267](0.009s) ok 36 - connect with sslcertmode=require fails without a client certificate [07:22:25.267](0.000s) ok 37 - connect with sslcertmode=require fails without a client certificate: matches [07:22:25.276](0.010s) ok 38 - sslcrl option with invalid file name [07:22:25.277](0.000s) ok 39 - sslcrl option with invalid file name: no stderr [07:22:25.285](0.008s) ok 40 - CRL belonging to a different CA [07:22:25.285](0.000s) ok 41 - CRL belonging to a different CA: matches [07:22:25.294](0.009s) ok 42 - directory CRL belonging to a different CA [07:22:25.294](0.000s) ok 43 - directory CRL belonging to a different CA: matches [07:22:25.304](0.010s) ok 44 - CRL with a non-revoked cert [07:22:25.304](0.000s) ok 45 - CRL with a non-revoked cert: no stderr [07:22:25.314](0.010s) ok 46 - directory CRL with a non-revoked cert [07:22:25.315](0.000s) ok 47 - directory CRL with a non-revoked cert: no stderr [07:22:25.325](0.010s) ok 48 - mismatch between host name and server certificate sslmode=require [07:22:25.325](0.000s) ok 49 - mismatch between host name and server certificate sslmode=require: no stderr [07:22:25.335](0.010s) ok 50 - mismatch between host name and server certificate sslmode=verify-ca [07:22:25.335](0.000s) ok 51 - mismatch between host name and server certificate sslmode=verify-ca: no stderr [07:22:25.344](0.009s) ok 52 - mismatch between host name and server certificate sslmode=verify-full [07:22:25.344](0.000s) ok 53 - mismatch between host name and server certificate sslmode=verify-full: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39639 [07:22:25.571](0.227s) ok 54 - IP address in the Common Name [07:22:25.572](0.001s) ok 55 - IP address in the Common Name: no stderr [07:22:25.581](0.010s) ok 56 - mismatch between host name and server certificate IP address [07:22:25.581](0.000s) ok 57 - mismatch between host name and server certificate IP address: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39673 [07:22:25.800](0.219s) ok 58 - IP address in a dNSName [07:22:25.801](0.000s) ok 59 - IP address in a dNSName: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39697 [07:22:26.023](0.222s) ok 60 - host name matching with X.509 Subject Alternative Names 1 [07:22:26.023](0.000s) ok 61 - host name matching with X.509 Subject Alternative Names 1: no stderr [07:22:26.034](0.011s) ok 62 - host name matching with X.509 Subject Alternative Names 2 [07:22:26.035](0.000s) ok 63 - host name matching with X.509 Subject Alternative Names 2: no stderr [07:22:26.045](0.011s) ok 64 - host name matching with X.509 Subject Alternative Names wildcard [07:22:26.046](0.000s) ok 65 - host name matching with X.509 Subject Alternative Names wildcard: no stderr [07:22:26.056](0.011s) ok 66 - host name not matching with X.509 Subject Alternative Names [07:22:26.057](0.000s) ok 67 - host name not matching with X.509 Subject Alternative Names: matches [07:22:26.067](0.010s) ok 68 - host name not matching with X.509 Subject Alternative Names wildcard [07:22:26.067](0.000s) ok 69 - host name not matching with X.509 Subject Alternative Names wildcard: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39726 [07:22:26.298](0.232s) ok 70 - host name matching with a single X.509 Subject Alternative Name [07:22:26.299](0.000s) ok 71 - host name matching with a single X.509 Subject Alternative Name: no stderr [07:22:26.309](0.010s) ok 72 - host name not matching with a single X.509 Subject Alternative Name [07:22:26.309](0.000s) ok 73 - host name not matching with a single X.509 Subject Alternative Name: matches [07:22:26.319](0.010s) ok 74 - host name not matching with a single X.509 Subject Alternative Name wildcard [07:22:26.319](0.000s) ok 75 - host name not matching with a single X.509 Subject Alternative Name wildcard: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39751 [07:22:26.553](0.234s) ok 76 - host matching an IPv4 address (Subject Alternative Name 1) [07:22:26.553](0.000s) ok 77 - host matching an IPv4 address (Subject Alternative Name 1): no stderr [07:22:26.564](0.011s) ok 78 - host matching an IPv4 address in alternate form (Subject Alternative Name 1) [07:22:26.565](0.000s) ok 79 - host matching an IPv4 address in alternate form (Subject Alternative Name 1): no stderr [07:22:26.578](0.013s) ok 80 - host not matching an IPv4 address (Subject Alternative Name 1) [07:22:26.578](0.000s) ok 81 - host not matching an IPv4 address (Subject Alternative Name 1): matches [07:22:26.589](0.011s) ok 82 - host matching an IPv6 address (Subject Alternative Name 2) [07:22:26.589](0.000s) ok 83 - host matching an IPv6 address (Subject Alternative Name 2): no stderr [07:22:26.600](0.011s) ok 84 - host matching an IPv6 address in alternate form (Subject Alternative Name 2) [07:22:26.600](0.000s) ok 85 - host matching an IPv6 address in alternate form (Subject Alternative Name 2): no stderr [07:22:26.610](0.010s) ok 86 - host matching an IPv6 address in mixed form (Subject Alternative Name 2) [07:22:26.611](0.000s) ok 87 - host matching an IPv6 address in mixed form (Subject Alternative Name 2): no stderr [07:22:26.619](0.008s) ok 88 - host not matching an IPv6 address (Subject Alternative Name 2) [07:22:26.619](0.000s) ok 89 - host not matching an IPv6 address (Subject Alternative Name 2): matches [07:22:26.629](0.010s) ok 90 - IPv6 host with CIDR mask does not match [07:22:26.629](0.000s) ok 91 - IPv6 host with CIDR mask does not match: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39792 [07:22:26.860](0.231s) ok 92 - certificate with both a CN and SANs 1 [07:22:26.861](0.000s) ok 93 - certificate with both a CN and SANs 1: no stderr [07:22:26.871](0.011s) ok 94 - certificate with both a CN and SANs 2 [07:22:26.872](0.000s) ok 95 - certificate with both a CN and SANs 2: no stderr [07:22:26.881](0.009s) ok 96 - certificate with both a CN and SANs ignores CN [07:22:26.881](0.000s) ok 97 - certificate with both a CN and SANs ignores CN: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39810 [07:22:27.113](0.232s) ok 98 - certificate with both a CN and IP SANs matches CN [07:22:27.113](0.000s) ok 99 - certificate with both a CN and IP SANs matches CN: no stderr [07:22:27.123](0.010s) ok 100 - certificate with both a CN and IP SANs matches SAN 1 [07:22:27.123](0.000s) ok 101 - certificate with both a CN and IP SANs matches SAN 1: no stderr [07:22:27.133](0.010s) ok 102 - certificate with both a CN and IP SANs matches SAN 2 [07:22:27.133](0.000s) ok 103 - certificate with both a CN and IP SANs matches SAN 2: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39824 [07:22:27.358](0.225s) ok 104 - certificate with both an IP CN and IP SANs 1 [07:22:27.358](0.000s) ok 105 - certificate with both an IP CN and IP SANs 1: no stderr [07:22:27.367](0.010s) ok 106 - certificate with both an IP CN and IP SANs 2 [07:22:27.368](0.000s) ok 107 - certificate with both an IP CN and IP SANs 2: no stderr [07:22:27.376](0.008s) ok 108 - certificate with both an IP CN and IP SANs ignores CN [07:22:27.376](0.000s) ok 109 - certificate with both an IP CN and IP SANs ignores CN: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39838 [07:22:27.606](0.229s) ok 110 - certificate with both an IP CN and DNS SANs matches CN [07:22:27.606](0.000s) ok 111 - certificate with both an IP CN and DNS SANs matches CN: no stderr [07:22:27.616](0.010s) ok 112 - certificate with both an IP CN and DNS SANs matches SAN 1 [07:22:27.616](0.000s) ok 113 - certificate with both an IP CN and DNS SANs matches SAN 1: no stderr [07:22:27.626](0.010s) ok 114 - certificate with both an IP CN and DNS SANs matches SAN 2 [07:22:27.626](0.000s) ok 115 - certificate with both an IP CN and DNS SANs matches SAN 2: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39852 [07:22:27.855](0.229s) ok 116 - server certificate without CN or SANs sslmode=verify-ca [07:22:27.855](0.000s) ok 117 - server certificate without CN or SANs sslmode=verify-ca: no stderr [07:22:27.863](0.008s) ok 118 - server certificate without CN or SANs sslmode=verify-full [07:22:27.863](0.000s) ok 119 - server certificate without CN or SANs sslmode=verify-full: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39864 [07:22:28.088](0.224s) ok 120 - sslrootcert=system does not connect with private CA [07:22:28.088](0.000s) ok 121 - sslrootcert=system does not connect with private CA: matches [07:22:28.092](0.004s) ok 122 - sslrootcert=system only accepts sslmode=verify-full [07:22:28.092](0.000s) ok 123 - sslrootcert=system only accepts sslmode=verify-full: matches [07:22:28.105](0.013s) ok 124 - sslrootcert=system connects with overridden SSL_CERT_FILE [07:22:28.105](0.000s) ok 125 - sslrootcert=system connects with overridden SSL_CERT_FILE: no stderr [07:22:28.113](0.008s) ok 126 - sslrootcert=system defaults to sslmode=verify-full [07:22:28.114](0.000s) ok 127 - sslrootcert=system defaults to sslmode=verify-full: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39879 [07:22:28.343](0.229s) ok 128 - connects without client-side CRL [07:22:28.343](0.000s) ok 129 - connects without client-side CRL: no stderr [07:22:28.351](0.008s) ok 130 - does not connect with client-side CRL file [07:22:28.351](0.000s) ok 131 - does not connect with client-side CRL file: matches [07:22:28.360](0.008s) ok 132 - does not connect with client-side CRL directory [07:22:28.360](0.000s) ok 133 - does not connect with client-side CRL directory: matches # Running: psql -X -A -F , -P null=_null_ -d sslkey=invalid sslcert=invalid sslrootcert=invalid sslcrl=invalid sslcrldir=invalid user=ssltestuser dbname=trustdb hostaddr=127.0.0.1 host=common-name.pg-ssltest.test sslrootcert=invalid -c SELECT * FROM pg_stat_ssl WHERE pid = pg_backend_pid() [07:22:28.370](0.010s) ok 134 - pg_stat_ssl view without client certificate: exit code 0 [07:22:28.370](0.000s) ok 135 - pg_stat_ssl view without client certificate: no stderr [07:22:28.370](0.000s) ok 136 - pg_stat_ssl view without client certificate: matches [07:22:28.380](0.009s) ok 137 - connection success with correct range of TLS protocol versions [07:22:28.380](0.000s) ok 138 - connection success with correct range of TLS protocol versions: no stderr [07:22:28.383](0.004s) ok 139 - connection failure with incorrect range of TLS protocol versions [07:22:28.384](0.000s) ok 140 - connection failure with incorrect range of TLS protocol versions: matches [07:22:28.387](0.004s) ok 141 - connection failure with an incorrect SSL protocol minimum bound [07:22:28.387](0.000s) ok 142 - connection failure with an incorrect SSL protocol minimum bound: matches [07:22:28.391](0.004s) ok 143 - connection failure with an incorrect SSL protocol maximum bound [07:22:28.391](0.000s) ok 144 - connection failure with an incorrect SSL protocol maximum bound: matches [07:22:28.391](0.000s) # running server tests [07:22:28.400](0.008s) ok 145 - certificate authorization fails without client cert [07:22:28.400](0.000s) ok 146 - certificate authorization fails without client cert: matches [07:22:28.414](0.014s) ok 147 - certificate authorization succeeds with correct client cert in PEM format [07:22:28.414](0.000s) ok 148 - certificate authorization succeeds with correct client cert in PEM format: no stderr [07:22:28.425](0.011s) ok 149 - certificate authorization succeeds with correct client cert in DER format [07:22:28.425](0.000s) ok 150 - certificate authorization succeeds with correct client cert in DER format: no stderr [07:22:28.437](0.012s) ok 151 - certificate authorization succeeds with correct client cert in encrypted PEM format [07:22:28.437](0.000s) ok 152 - certificate authorization succeeds with correct client cert in encrypted PEM format: no stderr [07:22:28.449](0.011s) ok 153 - certificate authorization succeeds with correct client cert in encrypted DER format [07:22:28.449](0.000s) ok 154 - certificate authorization succeeds with correct client cert in encrypted DER format: no stderr [07:22:28.460](0.011s) ok 155 - certificate authorization succeeds with correct client cert and sslcertmode=require [07:22:28.460](0.000s) ok 156 - certificate authorization succeeds with correct client cert and sslcertmode=require: no stderr [07:22:28.471](0.011s) ok 157 - certificate authorization succeeds with correct client cert and sslcertmode=allow [07:22:28.471](0.000s) ok 158 - certificate authorization succeeds with correct client cert and sslcertmode=allow: no stderr [07:22:28.480](0.009s) ok 159 - certificate authorization fails with correct client cert and sslcertmode=disable [07:22:28.480](0.000s) ok 160 - certificate authorization fails with correct client cert and sslcertmode=disable: matches [07:22:28.487](0.007s) ok 161 - certificate authorization fails with correct client cert and wrong password in encrypted PEM format [07:22:28.487](0.000s) ok 162 - certificate authorization fails with correct client cert and wrong password in encrypted PEM format: matches [07:22:28.501](0.014s) ok 163 - certificate authorization succeeds with DN mapping [07:22:28.502](0.000s) ok 164 - certificate authorization succeeds with DN mapping: no stderr [07:22:28.502](0.000s) ok 165 - certificate authorization succeeds with DN mapping: log matches [07:22:28.516](0.015s) ok 166 - certificate authorization succeeds with DN regex mapping [07:22:28.517](0.000s) ok 167 - certificate authorization succeeds with DN regex mapping: no stderr [07:22:28.531](0.014s) ok 168 - certificate authorization succeeds with CN mapping [07:22:28.531](0.000s) ok 169 - certificate authorization succeeds with CN mapping: no stderr [07:22:28.531](0.000s) ok 170 - certificate authorization succeeds with CN mapping: log matches [07:22:28.532](0.000s) not ok 171 # TODO & SKIP Need Pty support [07:22:28.532](0.000s) not ok 172 # TODO & SKIP Need Pty support [07:22:28.532](0.000s) not ok 173 # TODO & SKIP Need Pty support [07:22:28.532](0.000s) not ok 174 # TODO & SKIP Need Pty support # Running: psql -X -A -F , -P null=_null_ -d sslkey=invalid sslcert=invalid sslrootcert=invalid sslcrl=invalid sslcrldir=invalid sslrootcert=ssl/root+server_ca.crt sslmode=require dbname=certdb hostaddr=127.0.0.1 host=localhost user=ssltestuser sslcert=ssl/client.crt sslkey=/tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/tmp_test_mXnx/client.key -c SELECT * FROM pg_stat_ssl WHERE pid = pg_backend_pid() [07:22:28.560](0.028s) ok 175 - pg_stat_ssl with client certificate: exit code 0 [07:22:28.560](0.000s) ok 176 - pg_stat_ssl with client certificate: no stderr [07:22:28.560](0.000s) ok 177 - pg_stat_ssl with client certificate: matches [07:22:28.566](0.006s) ok 178 - certificate authorization fails because of file permissions [07:22:28.567](0.000s) ok 179 - certificate authorization fails because of file permissions: matches [07:22:28.577](0.010s) ok 180 - certificate authorization fails with client cert belonging to another user [07:22:28.577](0.000s) ok 181 - certificate authorization fails with client cert belonging to another user: matches [07:22:28.588](0.012s) ok 182 - certificate authorization fails with revoked client cert [07:22:28.589](0.000s) ok 183 - certificate authorization fails with revoked client cert: matches [07:22:28.589](0.000s) ok 184 - certificate authorization fails with revoked client cert: log does not match [07:22:28.603](0.014s) ok 185 - auth_option clientcert=verify-full succeeds with matching username and Common Name [07:22:28.603](0.000s) ok 186 - auth_option clientcert=verify-full succeeds with matching username and Common Name: no stderr [07:22:28.603](0.000s) ok 187 - auth_option clientcert=verify-full succeeds with matching username and Common Name: log matches [07:22:28.613](0.010s) ok 188 - auth_option clientcert=verify-full fails with mismatching username and Common Name [07:22:28.613](0.000s) ok 189 - auth_option clientcert=verify-full fails with mismatching username and Common Name: matches [07:22:28.613](0.000s) ok 190 - auth_option clientcert=verify-full fails with mismatching username and Common Name: log does not match [07:22:28.624](0.010s) ok 191 - auth_option clientcert=verify-ca succeeds with mismatching username and Common Name [07:22:28.624](0.000s) ok 192 - auth_option clientcert=verify-ca succeeds with mismatching username and Common Name: no stderr [07:22:28.624](0.000s) ok 193 - auth_option clientcert=verify-ca succeeds with mismatching username and Common Name: log matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39939 [07:22:28.854](0.230s) ok 194 - intermediate client certificate is provided by client [07:22:28.854](0.000s) ok 195 - intermediate client certificate is provided by client: no stderr [07:22:28.864](0.010s) ok 196 - intermediate client certificate is missing [07:22:28.864](0.000s) ok 197 - intermediate client certificate is missing: matches [07:22:28.874](0.010s) ok 198 - logged client certificate Subjects are truncated if they're too long [07:22:28.874](0.000s) ok 199 - logged client certificate Subjects are truncated if they're too long: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39953 [07:22:29.100](0.226s) ok 200 - intermediate client certificate is untrusted [07:22:29.100](0.000s) ok 201 - intermediate client certificate is untrusted: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39963 [07:22:29.326](0.225s) ok 202 - certificate authorization fails with revoked client cert with server-side CRL directory [07:22:29.326](0.000s) ok 203 - certificate authorization fails with revoked client cert with server-side CRL directory: matches [07:22:29.337](0.011s) ok 204 - certificate authorization fails with revoked UTF-8 client cert with server-side CRL directory [07:22:29.337](0.000s) ok 205 - certificate authorization fails with revoked UTF-8 client cert with server-side CRL directory: matches ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39975 [07:22:29.560](0.223s) not ok 206 - connect with valid stapled ocsp response when sslocspstapling=1 [07:22:29.560](0.000s) # Failed test 'connect with valid stapled ocsp response when sslocspstapling=1' # at /tmp/cirrus-ci-build/src/test/ssl/t/001_ssltests.pl line 923. [07:22:29.560](0.000s) # got: '2' # expected: '0' [07:22:29.560](0.000s) not ok 207 - connect with valid stapled ocsp response when sslocspstapling=1: no stderr [07:22:29.560](0.000s) # Failed test 'connect with valid stapled ocsp response when sslocspstapling=1: no stderr' # at /tmp/cirrus-ci-build/src/test/ssl/t/001_ssltests.pl line 923. [07:22:29.561](0.000s) # got: 'psql: error: connection to server at "127.0.0.1", port 52019 failed: SSL SYSCALL error: EOF detected' # expected: '' [07:22:29.574](0.013s) ok 208 - connect without requesting ocsp response when sslocspstapling=0 [07:22:29.574](0.000s) ok 209 - connect without requesting ocsp response when sslocspstapling=0: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39987 [07:22:29.796](0.222s) ok 210 - failed with a revoked ocsp response when sslocspstapling=1 [07:22:29.809](0.013s) ok 211 - connect without requesting ocsp response when sslocspstapling=0 [07:22:29.809](0.000s) ok 212 - connect without requesting ocsp response when sslocspstapling=0: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 39999 [07:22:30.033](0.223s) ok 213 - failed with a revoked ocsp response when sslocspstapling=1 [07:22:30.047](0.014s) ok 214 - connect without requesting ocsp response when sslocspstapling=0 [07:22:30.047](0.000s) ok 215 - connect without requesting ocsp response when sslocspstapling=0: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 40011 [07:22:30.269](0.222s) ok 216 - failed with an expired ocsp response when sslocspstapling=1 [07:22:30.283](0.013s) ok 217 - connect without requesting ocsp response when sslocspstapling=0 [07:22:30.283](0.000s) ok 218 - connect without requesting ocsp response when sslocspstapling=0: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 40023 [07:22:30.505](0.222s) not ok 219 - connect with valid stapled ocsp response when sslocspstapling=1 [07:22:30.505](0.000s) # Failed test 'connect with valid stapled ocsp response when sslocspstapling=1' # at /tmp/cirrus-ci-build/src/test/ssl/t/001_ssltests.pl line 1001. [07:22:30.505](0.000s) # got: '2' # expected: '0' [07:22:30.506](0.000s) not ok 220 - connect with valid stapled ocsp response when sslocspstapling=1: no stderr [07:22:30.506](0.000s) # Failed test 'connect with valid stapled ocsp response when sslocspstapling=1: no stderr' # at /tmp/cirrus-ci-build/src/test/ssl/t/001_ssltests.pl line 1001. [07:22:30.506](0.000s) # got: 'psql: error: connection to server at "127.0.0.1", port 52019 failed: SSL SYSCALL error: EOF detected' # expected: '' [07:22:30.519](0.013s) ok 221 - connect without requesting ocsp response when sslocspstapling=0 [07:22:30.519](0.000s) ok 222 - connect without requesting ocsp response when sslocspstapling=0: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 40035 [07:22:30.742](0.223s) ok 223 - failed with a revoked ocsp response when sslocspstapling=1 [07:22:30.755](0.013s) ok 224 - connect without requesting ocsp response when sslocspstapling=0 [07:22:30.755](0.000s) ok 225 - connect without requesting ocsp response when sslocspstapling=0: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 40047 [07:22:30.978](0.222s) ok 226 - failed with a revoked ocsp response when sslocspstapling=1 [07:22:30.991](0.013s) ok 227 - connect without requesting ocsp response when sslocspstapling=0 [07:22:30.991](0.000s) ok 228 - connect without requesting ocsp response when sslocspstapling=0: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 40059 [07:22:31.213](0.223s) ok 229 - failed with an expired ocsp response when sslocspstapling=1 [07:22:31.226](0.013s) ok 230 - connect without requesting ocsp response when sslocspstapling=0 [07:22:31.227](0.000s) ok 231 - connect without requesting ocsp response when sslocspstapling=0: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... done server started # Postmaster PID for node "primary" is 40071 [07:22:31.448](0.222s) ok 232 - failed with an expired ocsp response when sslocspstapling=1 [07:22:31.461](0.013s) ok 233 - connect without requesting ocsp response when sslocspstapling=0 [07:22:31.461](0.000s) ok 234 - connect without requesting ocsp response when sslocspstapling=0: no stderr ### Restarting node "primary" # Running: pg_ctl -w -D /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/data/t_001_ssltests_primary_data/pgdata -l /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log restart waiting for server to shut down.... done server stopped waiting for server to start.... stopped waiting pg_ctl: could not start server Examine the log output. # pg_ctl restart failed; see logfile for details: /tmp/cirrus-ci-build/build/testrun/ssl/001_ssltests/log/001_ssltests_primary.log # No postmaster PID for node "primary" [07:22:31.672](0.211s) Bail out! pg_ctl restart failed # No postmaster PID for node "primary"