On Fri, Sep 25, 2026 at 11:56 AM <[email protected]> wrote:
>
> This is an automated email from the ASF dual-hosted git repository.
>
> rmaucher pushed a commit to branch main
> in repository https://gitbox.apache.org/repos/asf/tomcat.git
>
>
> The following commit(s) were added to refs/heads/main by this push:
>      new c4d26896b1 Move SSL_in_init to compat
> c4d26896b1 is described below
>
> commit c4d26896b1e95d3a18b1d5f1d9d48c9d8279916b
> Author: remm <[email protected]>
> AuthorDate: Fri Sep 25 11:56:10 2026 +0200
>
>     Move SSL_in_init to compat
>
>     This check can be best effort.

So I added this due to the CI failure, but LibreSSL 3.3.6 is supposed
to have this symbol already. I'll keep researching.

Rémy

> ---
>  .../util/net/openssl/panama/OpenSSLEngine.java     |  4 +-
>  java/org/apache/tomcat/util/openssl/openssl_h.java | 51 
> ----------------------
>  .../util/openssl/openssl_h_Compatibility.java      | 24 ++++++++++
>  3 files changed, 26 insertions(+), 53 deletions(-)
>
> diff --git 
> a/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLEngine.java 
> b/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLEngine.java
> index 4f40283470..e92dbaf43e 100644
> --- a/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLEngine.java
> +++ b/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLEngine.java
> @@ -1031,7 +1031,7 @@ public final class OpenSSLEngine extends SSLEngine 
> implements SSLUtil.ProtocolIn
>
>              // No pending data to be sent to the peer
>              // Check to see if we have finished handshaking
> -            if (state.handshakeCount != currentHandshake && 
> SSL_in_init(state.ssl) == 0 &&
> +            if (state.handshakeCount != currentHandshake && 
> openssl_h_Compatibility.SSL_in_init(state.ssl) == 0 &&
>                      SSL_renegotiate_pending(state.ssl) == 0 &&
>                      (state.phaState != PHAState.START)) {
>                  if (alpn) {
> @@ -1674,7 +1674,7 @@ public final class OpenSSLEngine extends SSLEngine 
> implements SSLUtil.ProtocolIn
>                  byte[] clientCert;
>                  byte[][] chain;
>                  synchronized (OpenSSLEngine.this) {
> -                    if (destroyed || SSL_in_init(state.ssl) != 0) {
> +                    if (destroyed || 
> openssl_h_Compatibility.SSL_in_init(state.ssl) != 0) {
>                          throw new 
> SSLPeerUnverifiedException(sm.getString("engine.unverifiedPeer"));
>                      }
>                      chain = getPeerCertChain();
> diff --git a/java/org/apache/tomcat/util/openssl/openssl_h.java 
> b/java/org/apache/tomcat/util/openssl/openssl_h.java
> index 36265aeef9..b91b7bbf40 100644
> --- a/java/org/apache/tomcat/util/openssl/openssl_h.java
> +++ b/java/org/apache/tomcat/util/openssl/openssl_h.java
> @@ -4860,57 +4860,6 @@ public class openssl_h {
>          }
>      }
>
> -    private static class SSL_in_init {
> -        public static final FunctionDescriptor DESC = 
> FunctionDescriptor.of(openssl_h.C_INT, openssl_h.C_POINTER);
> -
> -        public static final MemorySegment ADDR = 
> openssl_h.findOrThrow("SSL_in_init");
> -
> -        public static final MethodHandle HANDLE = 
> Linker.nativeLinker().downcallHandle(ADDR, DESC);
> -    }
> -
> -    /**
> -     * Function descriptor for:
> -     * {@snippet lang = c : * int SSL_in_init(const SSL *s)
> -     * }
> -     */
> -    public static FunctionDescriptor SSL_in_init$descriptor() {
> -        return SSL_in_init.DESC;
> -    }
> -
> -    /**
> -     * Downcall method handle for:
> -     * {@snippet lang = c : * int SSL_in_init(const SSL *s)
> -     * }
> -     */
> -    public static MethodHandle SSL_in_init$handle() {
> -        return SSL_in_init.HANDLE;
> -    }
> -
> -    /**
> -     * Address for:
> -     * {@snippet lang = c : * int SSL_in_init(const SSL *s)
> -     * }
> -     */
> -    public static MemorySegment SSL_in_init$address() {
> -        return SSL_in_init.ADDR;
> -    }
> -
> -    /**
> -     * {@snippet lang = c : * int SSL_in_init(const SSL *s)
> -     * }
> -     */
> -    public static int SSL_in_init(MemorySegment s) {
> -        var mh$ = SSL_in_init.HANDLE;
> -        try {
> -            if (TRACE_DOWNCALLS) {
> -                traceDowncall("SSL_in_init", s);
> -            }
> -            return (int) mh$.invokeExact(s);
> -        } catch (Throwable ex$) {
> -            throw new AssertionError("should not reach here", ex$);
> -        }
> -    }
> -
>      private static class SSL_CTX_set0_tmp_dh_pkey {
>          public static final FunctionDescriptor DESC =
>                  FunctionDescriptor.of(openssl_h.C_INT, openssl_h.C_POINTER, 
> openssl_h.C_POINTER);
> diff --git a/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java 
> b/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> index dfb231836d..6aa4da7117 100644
> --- a/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> +++ b/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> @@ -18,6 +18,7 @@
>  package org.apache.tomcat.util.openssl;
>
>  import java.lang.invoke.MethodHandle;
> +
>  import java.lang.foreign.*;
>  import static java.lang.foreign.ValueLayout.*;
>  import static org.apache.tomcat.util.openssl.openssl_h.OpenSSL_version;
> @@ -472,4 +473,27 @@ public class openssl_h_Compatibility {
>          return ENGINE_METHOD_ALL;
>      }
>
> +    /**
> +     * Function descriptor for:
> +     * {@snippet lang = c : * int SSL_in_init(const SSL *s)
> +     * }
> +     */
> +    public static int SSL_in_init(MemorySegment e) {
> +        if (OPENSSL3 || BORINGSSL) {
> +            class Holder {
> +                static final FunctionDescriptor DESC = 
> FunctionDescriptor.of(openssl_h.C_INT, openssl_h.C_POINTER);
> +
> +                static final MethodHandle MH = Linker.nativeLinker()
> +                        
> .downcallHandle(openssl_h.findOrThrow("SSL_in_init"), DESC);
> +            }
> +            var mh$ = Holder.MH;
> +            try {
> +                return (int) mh$.invokeExact(e);
> +            } catch (Throwable ex$) {
> +                throw new AssertionError("should not reach here", ex$);
> +            }
> +        } else {
> +            return 0;
> +        }
> +    }
>  }
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to