Deprecate gfe2_reloadable_flag_quic_tls_enforce_valid_sni PiperOrigin-RevId: 318883809 Change-Id: I9b95e7fdbed1ba22beec30527875630e7cbcfb24
diff --git a/quic/core/tls_server_handshaker.cc b/quic/core/tls_server_handshaker.cc index 3894556..717d774 100644 --- a/quic/core/tls_server_handshaker.cc +++ b/quic/core/tls_server_handshaker.cc
@@ -510,14 +510,11 @@ hostname_ = hostname; crypto_negotiated_params_->sni = QuicHostnameUtils::NormalizeHostname(hostname_); - if (GetQuicReloadableFlag(quic_tls_enforce_valid_sni)) { - QUIC_RELOADABLE_FLAG_COUNT(quic_tls_enforce_valid_sni); - if (!QuicHostnameUtils::IsValidSNI(hostname_)) { - // TODO(b/151676147): Include this error string in the CONNECTION_CLOSE - // frame. - QUIC_LOG(ERROR) << "Invalid SNI provided: \"" << hostname_ << "\""; - return SSL_TLSEXT_ERR_ALERT_FATAL; - } + if (!QuicHostnameUtils::IsValidSNI(hostname_)) { + // TODO(b/151676147): Include this error string in the CONNECTION_CLOSE + // frame. + QUIC_LOG(ERROR) << "Invalid SNI provided: \"" << hostname_ << "\""; + return SSL_TLSEXT_ERR_ALERT_FATAL; } } else { QUIC_LOG(INFO) << "No hostname indicated in SNI";
diff --git a/quic/core/tls_server_handshaker_test.cc b/quic/core/tls_server_handshaker_test.cc index b766dfc..8b60122 100644 --- a/quic/core/tls_server_handshaker_test.cc +++ b/quic/core/tls_server_handshaker_test.cc
@@ -366,7 +366,6 @@ } TEST_F(TlsServerHandshakerTest, RejectInvalidSNI) { - SetQuicReloadableFlag(quic_tls_enforce_valid_sni, true); server_id_ = QuicServerId("invalid!.example.com", kServerPort, false); InitializeFakeClient(); static_cast<TlsClientHandshaker*>(