This is an automated email from the ASF dual-hosted git repository. asf-gitbox-commits pushed a commit to branch main in repository https://gitbox.apache.org/repos/asf/qpid-proton.git
commit 93ecd4448cb75387face9b0678b35f3cec77afc0 Author: Andrew Stitcher <[email protected]> AuthorDate: Wed Sep 23 19:37:40 2026 -0400 PROTON-2973: Do not dereference a NULL credential path pn_ssl_domain_set_credentials() tests each of its two credential arguments with is_pkcs11_uri(), which calls strncmp() on them unconditionally. Both arguments can legitimately be NULL: the private key is documented as optional. Before PKCS#11 support the NULL reached SSL_CTX_use_PrivateKey_file(), which rejects it and leaves the function returning -4. The new check was simply inserted ahead of the call that absorbed it. Restore that behaviour by treating a NULL path as what it is - not a PKCS#11 URI - which covers the certificate argument at the same time. [Caused by PROTON-2594] Assisted-By: Claude Opus 5 <[email protected]> --- c/src/ssl/openssl.c | 5 ++++- c/tests/ssl_test.cpp | 25 +++++++++++++++++++++++++ 2 files changed, 29 insertions(+), 1 deletion(-) diff --git a/c/src/ssl/openssl.c b/c/src/ssl/openssl.c index 4c3a76c5d..0b2dfa3c5 100644 --- a/c/src/ssl/openssl.c +++ b/c/src/ssl/openssl.c @@ -690,9 +690,12 @@ static EVP_PKEY *read_private_key_pkcs11( const char *uri, const char *key_pass } #endif +/* A NULL path is no more a PKCS#11 URI than any other non-matching string. The private key + is documented as optional and pn_messenger passes whatever it was given straight through, + so this is reached with NULL in ordinary use. */ static bool is_pkcs11_uri( const char *file_path ) { - return strncmp(file_path, "pkcs11:", sizeof("pkcs11:") - 1) == 0; + return file_path && strncmp(file_path, "pkcs11:", sizeof("pkcs11:") - 1) == 0; } int pn_ssl_domain_set_credentials( pn_ssl_domain_t *domain, diff --git a/c/tests/ssl_test.cpp b/c/tests/ssl_test.cpp index 122ad4ca7..4c74b5a75 100644 --- a/c/tests/ssl_test.cpp +++ b/c/tests/ssl_test.cpp @@ -21,6 +21,31 @@ #include "./pn_test.hpp" +#include <cstdlib> +#include <filesystem> +#include <string> + +static std::string ssl_file_path(const std::string &name) { + auto env = getenv("TEST_CERT_DIR"); + const char *cert_dir = env ? env : "ssl-certs"; + return (std::filesystem::path(cert_dir) / name).string(); +} + +// The private key is documented as optional, and pn_messenger passes it through unchecked, +// so it reaches the backend as NULL whenever a certificate is configured without one. +TEST_CASE("ssl_credentials_no_private_key") { + if (!pn_ssl_present()) { + WARN("SSL not available, skipping"); + return; + } + pn_test::auto_free<pn_ssl_domain_t, pn_ssl_domain_free> sd( + pn_ssl_domain(PN_SSL_MODE_SERVER)); + + // Must report the missing key rather than crash - PROTON-2594 made this a NULL deref. + CHECK(pn_ssl_domain_set_credentials( + sd, ssl_file_path("tserver-certificate.pem").c_str(), NULL, NULL) != 0); +} + TEST_CASE("ssl_protocols") { if (!pn_ssl_present()) { WARN("SSL not available, skipping"); --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
