Accepted a protocol violation and carried on. The anomaly was in the response the client read and delivered, so it was seen; this should have been rejected.
The client did something the clause forbids, or failed to do what it requires.
What was measured
- Client
- quiche — Cloudflare quiche, 0.30.0
- Test
- DATA frame before any HEADERS on the response stream —
h-data-before-headers - Clause
- RFC 9114 §4.1 (MUST)
- Class
- correctness — Rejected something invalid, with the code the RFC names.
- Required behaviour
- Close the connection with H3_FRAME_UNEXPECTED. A response begins with a field section, and §4.1 makes "receipt of an invalid sequence of frames" a connection error of that type — a body arriving before the headers that describe it is exactly that.
- Measured
- 2026-09-17
Reproduce it
The suite is the judge, so the reproduction is to point the same client at the same test and let the server report what it saw.
SESSION=$(curl -sX POST https://conformance.pqcrypta.com/session | jq -r .id)
# then drive quiche at the test URL and read the verdict:
curl -s https://conformance.pqcrypta.com/report/$SESSION.json | jq '.results["h-data-before-headers"]'
What this suite is · The full grid · All clients · All tests · Findings