tree f0cd03507628649334bb128712dce40c5b2d9901
parent 17ca6b0e1a45d3ae966632ba71f7a9485980e269
author fayang <fayang@google.com> 1623932972 -0700
committer Copybara-Service <copybara-worker@google.com> 1623933010 -0700

Do not send PATH_CHALLENGE or PATH_RESPONSE when 1-RTT write key is not available. This does not have functional because:
1) Client does not initiated path validation until handshake confirmed.
2) Server does not allow peer address change during handshake (no reverse path validation until handshake complete).
3) Server can only receive PATH_CHALLENGE in ENCRYPTION_ZERO_RTT and ENCRYPTION_FORWARD_SECURE, while server must have 1-RTT write key. Client can only receive PATH_CHALLENGE in ENCRYPTION_FORWARD_SECURE, while client must have 1-RTT write key.

This is needed since we are going to allow address change during the handshake.

PiperOrigin-RevId: 379936797
