asyncnet, net: clear openssl error queue before performing I/O

Per SSL_get_error(3):

  The current thread's error queue must be empty before the TLS/SSL I/O
  operation is attempted, or SSL_get_error() will not work reliably.

There has been records of not clearing the error queue causing weird SSL
errors when there shouldn't be any, see:

https://github.com/openssl/openssl/issues/11889
This commit is contained in:
Leorize 2020-06-03 15:11:10 -05:00 • committed by Andreas Rumpf
commit 6cb94b5da6
3 changed files with 9 additions and 0 deletions

View file

@ -718,6 +718,7 @@ proc close*(socket: AsyncSocket) =
# established, see:
# https://github.com/openssl/openssl/issues/710#issuecomment-253897666
if SSL_in_init(socket.sslHandle) == 0:
ErrClearError()
SSL_shutdown(socket.sslHandle)
else:
0