On Sun, Sep 01, 2002, Patrick McCormick via RT wrote:
>
> In this method in ssl/s3_clnt.c, there's a race condition with the static
> init variable that is causing a crash in my multithreaded program. init
> gets set to 0 before the static structures have been set up. I believe a
> lock is needed.
>
> 142 SSL_METHOD *SSLv3_client_method(void)
> 143 {
> 144 static int init=1;
> 145 static SSL_METHOD SSLv3_client_data;
> 146
> 147 if (init)
> 148 {
> 149 init=0;
> 150 memcpy((char *)&SSLv3_client_data,(char
> *)sslv3_base_method(),
> 151 sizeof(SSL_METHOD));
> 152 SSLv3_client_data.ssl_connect=ssl3_connect;
> 153 SSLv3_client_data.get_ssl_method=ssl3_get_client_method;
> 154 }
> 155 return(&SSLv3_client_data);
> 156 }
>
> Has anyone run into this before? What method does OpenSSL use to lock
> access to data structures?
>
Normally application create a single SSL_CTX structure before starting
any threads and muliple SSL structure from that SSL_CTX so that problem
doesn't arise.
I suppose it should be locked though. A simple workaround is to make a
dummy SSL_v3_client_method() call before starting any threads.
Steve.
--
Dr. Stephen Henson [EMAIL PROTECTED]
OpenSSL Project http://www.openssl.org/~steve/
______________________________________________________________________
OpenSSL Project http://www.openssl.org
Development Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]