On Fri, Sep 25, 2026 at 12:31 PM <[email protected]> wrote:
>
> This is an automated email from the ASF dual-hosted git repository.
>
> rmaucher pushed a commit to branch main
> in repository https://gitbox.apache.org/repos/asf/tomcat.git
>
>
> The following commit(s) were added to refs/heads/main by this push:
>      new bed68d66fb Fix LibreSSL compatibility
> bed68d66fb is described below
>
> commit bed68d66fb5886b3c34eaf73787a5980fcda0416
> Author: remm <[email protected]>
> AuthorDate: Fri Sep 25 12:30:50 2026 +0200
>
>     Fix LibreSSL compatibility
>
>     It is actually a macro there, so reproduce it with code.

It's not the end of the issues though:
- As far as I can tell, SSL_CTX_set_psk_client_callback is not in
LibreSSL at all (it is in BoringSSL)
- SSL_CTX_set_psk_use_session_callback is OpenSSL 1.1+ only

So I get the right behavior in that case is to throw a SSLException if
the symbol does not exist.

Rémy

> ---
>  .../tomcat/util/openssl/openssl_h_Compatibility.java | 20 
> ++++++++++++++++++++
>  1 file changed, 20 insertions(+)
>
> diff --git a/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java 
> b/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> index 6aa4da7117..c04bb3e92f 100644
> --- a/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> +++ b/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> @@ -492,6 +492,26 @@ public class openssl_h_Compatibility {
>              } catch (Throwable ex$) {
>                  throw new AssertionError("should not reach here", ex$);
>              }
> +        } else if (LIBRESSL) {
> +            // Here it is a macro:
> +            // #define SSL_ST_CONNECT 0x1000
> +            // #define SSL_ST_ACCEPT 0x2000
> +            // #define SSL_ST_INIT (SSL_ST_CONNECT|SSL_ST_ACCEPT)
> +            // #define SSL_in_init (SSL_state((a))&SSL_ST_INIT)
> +            final int SSL_ST_CONNECT = 0x1000;
> +            final int SSL_ST_ACCEPT = 0x2000;
> +            class Holder {
> +                static final FunctionDescriptor DESC = 
> FunctionDescriptor.of(openssl_h.C_INT, openssl_h.C_POINTER);
> +
> +                static final MethodHandle MH = Linker.nativeLinker()
> +                        .downcallHandle(openssl_h.findOrThrow("SSL_state"), 
> DESC);
> +            }
> +            var mh$ = Holder.MH;
> +            try {
> +                return ((int) mh$.invokeExact(e) & ((SSL_ST_CONNECT | 
> SSL_ST_ACCEPT)));
> +            } catch (Throwable ex$) {
> +                throw new AssertionError("should not reach here", ex$);
> +            }
>          } else {
>              return 0;
>          }
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to