d3dcc064df
- _ssl_interop_hint: also match ssl.SSLError instances (and one level of __cause__/__context__) plus the bare UNEXPECTED_EOF marker, so an SSLEOFError whose text httpx did not repeat still gets the hint. The hint now names the TLS 1.2 diagnostic and links the providers docs note instead of an issue number. - tests: 3 -> 2 invariants (parametrized login_post/poll SSL case keeps the raw text + hint + cause; a plain httpx timeout gets no hint). - docs: providers.md Codex note carries the reporter's exact openssl.cnf classic-groups snippet (EN + existing zh-Hans copy). Refs #106384. The TLS max-version cap itself stays PR #44392's scope.