On Fri, Sep 25, 2026 at 12:31 PM <[email protected]> wrote:
>
> This is an automated email from the ASF dual-hosted git repository.
>
> rmaucher pushed a commit to branch main
> in repository https://gitbox.apache.org/repos/asf/tomcat.git
>
>
> The following commit(s) were added to refs/heads/main by this push:
> new bed68d66fb Fix LibreSSL compatibility
> bed68d66fb is described below
>
> commit bed68d66fb5886b3c34eaf73787a5980fcda0416
> Author: remm <[email protected]>
> AuthorDate: Fri Sep 25 12:30:50 2026 +0200
>
> Fix LibreSSL compatibility
>
> It is actually a macro there, so reproduce it with code.
It's not the end of the issues though:
- As far as I can tell, SSL_CTX_set_psk_client_callback is not in
LibreSSL at all (it is in BoringSSL)
- SSL_CTX_set_psk_use_session_callback is OpenSSL 1.1+ only
So I get the right behavior in that case is to throw a SSLException if
the symbol does not exist.
Rémy
> ---
> .../tomcat/util/openssl/openssl_h_Compatibility.java | 20
> ++++++++++++++++++++
> 1 file changed, 20 insertions(+)
>
> diff --git a/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> b/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> index 6aa4da7117..c04bb3e92f 100644
> --- a/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> +++ b/java/org/apache/tomcat/util/openssl/openssl_h_Compatibility.java
> @@ -492,6 +492,26 @@ public class openssl_h_Compatibility {
> } catch (Throwable ex$) {
> throw new AssertionError("should not reach here", ex$);
> }
> + } else if (LIBRESSL) {
> + // Here it is a macro:
> + // #define SSL_ST_CONNECT 0x1000
> + // #define SSL_ST_ACCEPT 0x2000
> + // #define SSL_ST_INIT (SSL_ST_CONNECT|SSL_ST_ACCEPT)
> + // #define SSL_in_init (SSL_state((a))&SSL_ST_INIT)
> + final int SSL_ST_CONNECT = 0x1000;
> + final int SSL_ST_ACCEPT = 0x2000;
> + class Holder {
> + static final FunctionDescriptor DESC =
> FunctionDescriptor.of(openssl_h.C_INT, openssl_h.C_POINTER);
> +
> + static final MethodHandle MH = Linker.nativeLinker()
> + .downcallHandle(openssl_h.findOrThrow("SSL_state"),
> DESC);
> + }
> + var mh$ = Holder.MH;
> + try {
> + return ((int) mh$.invokeExact(e) & ((SSL_ST_CONNECT |
> SSL_ST_ACCEPT)));
> + } catch (Throwable ex$) {
> + throw new AssertionError("should not reach here", ex$);
> + }
> } else {
> return 0;
> }
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]