This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/qpid-proton.git

commit 93ecd4448cb75387face9b0678b35f3cec77afc0
Author: Andrew Stitcher <[email protected]>
AuthorDate: Wed Sep 23 19:37:40 2026 -0400

    PROTON-2973: Do not dereference a NULL credential path
    
    pn_ssl_domain_set_credentials() tests each of its two credential arguments 
with
    is_pkcs11_uri(), which calls strncmp() on them unconditionally. Both 
arguments
    can legitimately be NULL: the private key is documented as optional.
    
    Before PKCS#11 support the NULL reached SSL_CTX_use_PrivateKey_file(), which
    rejects it and leaves the function returning -4. The new check was simply
    inserted ahead of the call that absorbed it. Restore that behaviour by 
treating
    a NULL path as what it is - not a PKCS#11 URI - which covers the certificate
    argument at the same time.
    
    [Caused by PROTON-2594]
    
    Assisted-By: Claude Opus 5 <[email protected]>
---
 c/src/ssl/openssl.c  |  5 ++++-
 c/tests/ssl_test.cpp | 25 +++++++++++++++++++++++++
 2 files changed, 29 insertions(+), 1 deletion(-)

diff --git a/c/src/ssl/openssl.c b/c/src/ssl/openssl.c
index 4c3a76c5d..0b2dfa3c5 100644
--- a/c/src/ssl/openssl.c
+++ b/c/src/ssl/openssl.c
@@ -690,9 +690,12 @@ static EVP_PKEY *read_private_key_pkcs11( const char *uri, 
const char *key_pass
 }
 #endif
 
+/* A NULL path is no more a PKCS#11 URI than any other non-matching string.  
The private key
+   is documented as optional and pn_messenger passes whatever it was given 
straight through,
+   so this is reached with NULL in ordinary use. */
 static bool is_pkcs11_uri( const char *file_path )
 {
-  return strncmp(file_path, "pkcs11:", sizeof("pkcs11:") - 1) == 0;
+  return file_path && strncmp(file_path, "pkcs11:", sizeof("pkcs11:") - 1) == 
0;
 }
 
 int pn_ssl_domain_set_credentials( pn_ssl_domain_t *domain,
diff --git a/c/tests/ssl_test.cpp b/c/tests/ssl_test.cpp
index 122ad4ca7..4c74b5a75 100644
--- a/c/tests/ssl_test.cpp
+++ b/c/tests/ssl_test.cpp
@@ -21,6 +21,31 @@
 
 #include "./pn_test.hpp"
 
+#include <cstdlib>
+#include <filesystem>
+#include <string>
+
+static std::string ssl_file_path(const std::string &name) {
+  auto env = getenv("TEST_CERT_DIR");
+  const char *cert_dir = env ? env : "ssl-certs";
+  return (std::filesystem::path(cert_dir) / name).string();
+}
+
+// The private key is documented as optional, and pn_messenger passes it 
through unchecked,
+// so it reaches the backend as NULL whenever a certificate is configured 
without one.
+TEST_CASE("ssl_credentials_no_private_key") {
+  if (!pn_ssl_present()) {
+    WARN("SSL not available, skipping");
+    return;
+  }
+  pn_test::auto_free<pn_ssl_domain_t, pn_ssl_domain_free> sd(
+      pn_ssl_domain(PN_SSL_MODE_SERVER));
+
+  // Must report the missing key rather than crash - PROTON-2594 made this a 
NULL deref.
+  CHECK(pn_ssl_domain_set_credentials(
+            sd, ssl_file_path("tserver-certificate.pem").c_str(), NULL, NULL) 
!= 0);
+}
+
 TEST_CASE("ssl_protocols") {
   if (!pn_ssl_present()) {
     WARN("SSL not available, skipping");


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to