Kazuki Yamaguchi 2026-08-05 19:26:39 +0000 (Wed, 05 Aug 2026)
New Revision: 0948e6e0e3
https://github.com/ruby/ruby/commit/0948e6e0e3
Log:
[ruby/openssl] ssl: keep original SSLContext alive after servername_cb
Keep the original SSLContext in a separate instance variable to prevent
it from being GC'ed while its underlying SSL_CTX is still in use.
When the SNI callback accepts the provided server name, it can replace
the SSL_CTX with SSL_set_SSL_CTX() and update SSLSocket#context.
However, although this is poorly documented, SSL_set_SSL_CTX() does not
appear to replace all uses of the original SSL_CTX with the new one. In
particular, session management still uses the original SSL_CTX and
therefore requires that the corresponding SSLContext object to remain
alive for the lifetime of SSLSocket.
https://github.com/ruby/openssl/commit/77e8b6d041
Modified files:
ext/openssl/ossl_ssl.c