Make sure we treat records written after HRR as TLSv1.3