# SRS timestamps and signatures vary by hostname and from run to run
- s/SRS0=....=.[^=]?=([^=]+)=([^@]+)\@([^ ]+)/SRS0=ZZZZ=YY=$1=$2\@$3/;
+ s/(?i)SRS0=....=.[^=]?=([^=]+)=([^@]+)\@([^ ]+)/SRS0=ZZZZ=YY=$1=$2\@$3/g;
# ======== Output from the "fd" program about open descriptors ========
# this is timing-dependent
next if /^OpenSSL: creating STEK$/;
+ # only OpenSSL speaks of these
+ next if /^TLS: preloading DH params for server/;
+ next if /^Diffie-Hellman initialized from default/;
+ next if /^TLS: preloading ECDH curve for server/;
+ next if /^ECDH OpenSSL [\d.+]+ temp key parameter settings: default selection$/;
+ next if /^watch dir '\/etc\/pki\/tls'$/;
+
+ # only GnuTLS speaks of these
+ next if /^GnuTLS global init required$/;
+ next if /^TLS: basic cred init, server/;
+ next if /^TLS: preloading cipher list for server: NULL$/;
+ s/^GnuTLS using default session cipher\/priority "NORMAL"$/TLS: not preloading cipher list for server/;
+ next if /^GnuTLS<2>: added \d+ protocols, \d+ ciphersuites, \d+ sig algos and \d+ groups into priority list$/;
+
+ # there happen in different orders for OpenSSL/GnuTLS/noTLS
+ next if /^TLS: not preloading (CA bundle|cipher list) for server$/;
+ next if /^TLS: not preloading server certs$/;
+
# drop lookups
next if /^Lookups \(built-in\):/;
next if /^Loading lookup modules from/;
next if /^date:\w+,\{SP\}/;
next if /^DKIM \[[^[]+\] (Header hash|b) computed:/;
+ # Timing variable over runs. Collapse repeated memssages.
+ if (/notify triggered queue run/)
+ {
+ my $line = $_;
+ while (/notify triggered queue run/) { $_ = <IN>; }
+ $_ = $line . $_;
+ }
+
# Not all platforms support TCP Fast Open, and the compile omits the check
if (s/\S+ in hosts_try_fastopen\? (no \(option unset\)|no \(end of list\)|yes \(matched "\*"\))\n$//)
{