On Fri, Sep 25, 2026 at 11:56 AM <[email protected]> wrote:
>
> This is an automated email from the ASF dual-hosted git repository.
>
> rmaucher pushed a commit to branch main
> in repository https://gitbox.apache.org/repos/asf/tomcat.git
>
>
> The following commit(s) were added to refs/heads/main by this push:
> new c4d26896b1 Move SSL_in_init to compat
> c4d26896b1 is described below
>
> commit c4d26896b1e95d3a18b1d5f1d9d48c9d8279916b
> Author: remm <[email protected]>
> AuthorDate: Fri Sep 25 11:56:10 2026 +0200
>
> Move SSL_in_init to compat
>
> This check can be best effort.
So I added this due to the CI failure, but LibreSSL 3.3.6 is supposed
to have this symbol already. I'll keep researching.
Rémy
> ---
> .../util/net/openssl/panama/OpenSSLEngine.java | 4 +-
> java/org/apache/tomcat/util/openssl/openssl_h.java | 51
> ----------------------
> .../util/openssl/openssl_h_Compatibility.java | 24 ++++++++++
> 3 files changed, 26 insertions(+), 53 deletions(-)
>
> diff --git
> a/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLEngine.java
> b/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLEngine.java
> index 4f40283470..e92dbaf43e 100644
> --- a/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLEngine.java
> +++ b/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLEngine.java
> @@ -1031,7 +1031,7 @@ public final class OpenSSLEngine extends SSLEngine
> implements SSLUtil.ProtocolIn
>
> // No pending data to be sent to the peer
> // Check to see if we have finished handshaking
> - if (state.handshakeCount != currentHandshake &&
> SSL_in_init(state.ssl) == 0 &&
> + if (state.handshakeCount != currentHandshake &&
> openssl_h_Compatibility.SSL_in_init(state.ssl) == 0 &&
> SSL_renegotiate_pending(state.ssl) == 0 &&
> (state.phaState != PHAState.START)) {
> if (alpn) {
> @@ -1674,7 +1674,7 @@ public final class OpenSSLEngine extends SSLEngine
> implements SSLUtil.ProtocolIn
> byte[] clientCert;
> byte[][] chain;
> synchronized (OpenSSLEngine.this) {
> - if (destroyed || SSL_in_init(state.ssl) != 0) {
> + if (destroyed ||
> openssl_h_Compatibility.SSL_in_init(state.ssl) != 0) {
> throw new
> SSLPeerUnverifiedException(sm.getString("engine.unverifiedPeer"));
> }
> chain = getPeerCertChain();
> diff --git a/java/org/apache/tomcat/util/openssl/openssl_h.java
> b/java/org/apache/tomcat/util/openssl/openssl_h.java
> index 36265aeef9..b91b7bbf40 100644
> --- a/java/org/apache/tomcat/util/openssl/openssl_h.java
> +++ b/java/org/apache/tomcat/util/openssl/openssl_h.java
> @@ -4860,57 +4860,6 @@ public class openssl_h {
> }
> }
>
> - private static class SSL_in_init {
> - public static final FunctionDescriptor DESC =
> FunctionDescriptor.of(openssl_h.C_INT, openssl_h.C_POINTER);
> -
> - public static final MemorySegment ADDR =
> openssl_h.findOrThrow("SSL_in_init");
> -
> - public static final MethodHandle HANDLE =
> Linker.nativeLinker().downcallHandle(ADDR, DESC);
> - }
> -
> - /**
> - * Function descriptor for:
> - * {@snippet lang = c : * int SSL_in_init(const SSL *s)
> - * }
> - */
> - public static FunctionDescriptor SSL_in_init$descriptor() {
> - return SSL_in_init.DESC;
> - }
> -
> - /**
> - * Downcall method handle for:
> - * {@snippet lang = c : * int SSL_in_init(const SSL *s)
> - * }
> - */
> - public static MethodHandle SSL_in_init$handle() {
> - return SSL_in_init.HANDLE;
> - }
> -
> - /**
> - * Address for:
> - * {@snippet lang = c : * int SSL_in_init(const SSL *s)
> - * }
> - */
> - public static MemorySegment SSL_in_init$address() {
> - return SSL_in_init.ADDR;
> - }
> -
> - /**
> - * {@snippet lang = c : * int SSL_in_init(const SSL *s)
> - * }
> - */
> - public static int SSL_in_init(MemorySegment s) {
> - var mh$ = SSL_in_init.HANDLE;
> - try {
> - if (TRACE_DOWNCALLS) {
> - traceDowncall("SSL_in_init", s);
> - }
> - return (int) mh$.invokeExact(s);
> - } catch (Throwable ex$) {
> - throw new AssertionError("should not reach here", ex$);
> - }
> - }
> -
> private static class SSL_CTX_set0_tmp_dh_pkey {
> public static final FunctionDescriptor DESC =
> FunctionDescriptor.of(openssl_h.C_INT, openssl_h.C_POINTER,
> openssl_h.C_POINTER);
> diff --git a/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> b/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> index dfb231836d..6aa4da7117 100644
> --- a/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> +++ b/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> @@ -18,6 +18,7 @@
> package org.apache.tomcat.util.openssl;
>
> import java.lang.invoke.MethodHandle;
> +
> import java.lang.foreign.*;
> import static java.lang.foreign.ValueLayout.*;
> import static org.apache.tomcat.util.openssl.openssl_h.OpenSSL_version;
> @@ -472,4 +473,27 @@ public class openssl_h_Compatibility {
> return ENGINE_METHOD_ALL;
> }
>
> + /**
> + * Function descriptor for:
> + * {@snippet lang = c : * int SSL_in_init(const SSL *s)
> + * }
> + */
> + public static int SSL_in_init(MemorySegment e) {
> + if (OPENSSL3 || BORINGSSL) {
> + class Holder {
> + static final FunctionDescriptor DESC =
> FunctionDescriptor.of(openssl_h.C_INT, openssl_h.C_POINTER);
> +
> + static final MethodHandle MH = Linker.nativeLinker()
> +
> .downcallHandle(openssl_h.findOrThrow("SSL_in_init"), DESC);
> + }
> + var mh$ = Holder.MH;
> + try {
> + return (int) mh$.invokeExact(e);
> + } catch (Throwable ex$) {
> + throw new AssertionError("should not reach here", ex$);
> + }
> + } else {
> + return 0;
> + }
> + }
> }
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]