Tolerated it and continued. The specification permits this but does not require it; a client that rejected it would also be conformant.
The client did what the clause requires.
What was measured
- Client
- ngtcp2 — ngtcp2 + nghttp3 (direct), 3c23148
- Test
- SETTINGS containing the same identifier twice —
h-duplicate-setting - Clause
- RFC 9114 §7.2.4 (MAY)
- Class
- discretionary — The RFC permits either behaviour; the report says which was chosen.
- Required behaviour
- Either reject with H3_SETTINGS_ERROR or ignore the repeat — the specification says a receiver MAY treat this as an error, so both are conformant.
- Measured
- 2026-09-18
Reproduce it
The suite is the judge, so the reproduction is to point the same client at the same test and let the server report what it saw.
SESSION=$(curl -sX POST https://conformance.pqcrypta.com/session | jq -r .id)
# then drive ngtcp2 at the test URL and read the verdict:
curl -s https://conformance.pqcrypta.com/report/$SESSION.json | jq '.results["h-duplicate-setting"]'
What this suite is · The full grid · All clients · All tests · Findings