0948e6e0e3 (master): [ruby/openssl] ssl: keep original SSLContext alive after servername_cb

0 views
Skip to first unread message

Kazuki Yamaguchi

unread,
Oct 5, 2026, 12:50:19 PM (yesterday) Oct 5
to ruby...@g.ruby-lang.org
Kazuki Yamaguchi 2026-08-05 19:26:39 +0000 (Wed, 05 Aug 2026)

New Revision: 0948e6e0e3

https://github.com/ruby/ruby/commit/0948e6e0e3

Log:
[ruby/openssl] ssl: keep original SSLContext alive after servername_cb

Keep the original SSLContext in a separate instance variable to prevent
it from being GC'ed while its underlying SSL_CTX is still in use.

When the SNI callback accepts the provided server name, it can replace
the SSL_CTX with SSL_set_SSL_CTX() and update SSLSocket#context.
However, although this is poorly documented, SSL_set_SSL_CTX() does not
appear to replace all uses of the original SSL_CTX with the new one. In
particular, session management still uses the original SSL_CTX and
therefore requires that the corresponding SSLContext object to remain
alive for the lifetime of SSLSocket.

https://github.com/ruby/openssl/commit/77e8b6d041

Modified files:
ext/openssl/ossl_ssl.c
Reply all
Reply to author
Forward
0 new messages