asyncnet, net: call SSL_shutdown only when connection established

This commit prevents "SSL_shutdown while in init" errors from happening.

See https://github.com/openssl/openssl/issues/710#issuecomment-253897666
This commit is contained in:
Leorize 2020-06-01 17:10:02 -05:00 • committed by Andreas Rumpf
commit 82092b3bb7
4 changed files with 52 additions and 12 deletions

View file

@ -713,7 +713,14 @@ proc close*(socket: AsyncSocket) =
socket.fd.AsyncFD.closeSocket()
when defineSsl:
if socket.isSsl:
let res = SSL_shutdown(socket.sslHandle)
let res =
# Don't call SSL_shutdown if the connection has not been fully
# established, see:
# https://github.com/openssl/openssl/issues/710#issuecomment-253897666
if SSL_in_init(socket.sslHandle) == 0:
SSL_shutdown(socket.sslHandle)
else:
0
SSL_free(socket.sslHandle)
if res == 0:
discard

View file

@ -1007,15 +1007,19 @@ proc close*(socket: Socket) =
when defineSsl:
if socket.isSsl and socket.sslHandle != nil:
ErrClearError()
# As we are closing the underlying socket immediately afterwards,
# it is valid, under the TLS standard, to perform a unidirectional
# shutdown i.e not wait for the peers "close notify" alert with a second
# call to SSL_shutdown
let res = SSL_shutdown(socket.sslHandle)
if res == 0:
discard
elif res != 1:
socketError(socket, res)
# Don't call SSL_shutdown if the connection has not been fully
# established, see:
# https://github.com/openssl/openssl/issues/710#issuecomment-253897666
if SSL_in_init(socket.sslHandle) == 0:
# As we are closing the underlying socket immediately afterwards,
# it is valid, under the TLS standard, to perform a unidirectional
# shutdown i.e not wait for the peers "close notify" alert with a second
# call to SSL_shutdown
let res = SSL_shutdown(socket.sslHandle)
if res == 0:
discard
elif res != 1:
socketError(socket, res)
finally:
when defineSsl:
if socket.isSsl and socket.sslHandle != nil: