mirror of
https://github.com/postgres/postgres.git
synced 2025-11-24 00:23:06 +03:00
SSL_read/SSL_write do not approximate the return conventions of recv()
and send() very well at all; and in any case we can't use retval==0 for EOF due to race conditions. Make the same fixes in the backend as are required in libpq.
This commit is contained in:
@@ -11,7 +11,7 @@
|
|||||||
*
|
*
|
||||||
*
|
*
|
||||||
* IDENTIFICATION
|
* IDENTIFICATION
|
||||||
* $Header: /cvsroot/pgsql/src/backend/libpq/be-secure.c,v 1.15.2.11 2003/04/10 23:03:13 tgl Exp $
|
* $Header: /cvsroot/pgsql/src/backend/libpq/be-secure.c,v 1.15.2.12 2003/08/04 17:58:25 tgl Exp $
|
||||||
*
|
*
|
||||||
* Since the server static private key ($DataDir/server.key)
|
* Since the server static private key ($DataDir/server.key)
|
||||||
* will normally be stored unencrypted so that the database
|
* will normally be stored unencrypted so that the database
|
||||||
@@ -287,18 +287,22 @@ secure_read(Port *port, void *ptr, size_t len)
|
|||||||
if (n == -1)
|
if (n == -1)
|
||||||
elog(COMMERROR, "SSL SYSCALL error: %m");
|
elog(COMMERROR, "SSL SYSCALL error: %m");
|
||||||
else
|
else
|
||||||
|
{
|
||||||
elog(COMMERROR, "SSL SYSCALL error: EOF detected");
|
elog(COMMERROR, "SSL SYSCALL error: EOF detected");
|
||||||
|
errno = ECONNRESET;
|
||||||
|
n = -1;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
case SSL_ERROR_SSL:
|
case SSL_ERROR_SSL:
|
||||||
elog(COMMERROR, "SSL error: %s", SSLerrmessage());
|
elog(COMMERROR, "SSL error: %s", SSLerrmessage());
|
||||||
/* fall through */
|
/* fall through */
|
||||||
case SSL_ERROR_ZERO_RETURN:
|
case SSL_ERROR_ZERO_RETURN:
|
||||||
secure_close(port);
|
|
||||||
errno = ECONNRESET;
|
errno = ECONNRESET;
|
||||||
n = -1;
|
n = -1;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
elog(COMMERROR, "Unknown SSL error code");
|
elog(COMMERROR, "Unknown SSL error code");
|
||||||
|
n = -1;
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -352,18 +356,22 @@ secure_write(Port *port, void *ptr, size_t len)
|
|||||||
if (n == -1)
|
if (n == -1)
|
||||||
elog(COMMERROR, "SSL SYSCALL error: %m");
|
elog(COMMERROR, "SSL SYSCALL error: %m");
|
||||||
else
|
else
|
||||||
|
{
|
||||||
elog(COMMERROR, "SSL SYSCALL error: EOF detected");
|
elog(COMMERROR, "SSL SYSCALL error: EOF detected");
|
||||||
|
errno = ECONNRESET;
|
||||||
|
n = -1;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
case SSL_ERROR_SSL:
|
case SSL_ERROR_SSL:
|
||||||
elog(COMMERROR, "SSL error: %s", SSLerrmessage());
|
elog(COMMERROR, "SSL error: %s", SSLerrmessage());
|
||||||
/* fall through */
|
/* fall through */
|
||||||
case SSL_ERROR_ZERO_RETURN:
|
case SSL_ERROR_ZERO_RETURN:
|
||||||
secure_close(port);
|
|
||||||
errno = ECONNRESET;
|
errno = ECONNRESET;
|
||||||
n = -1;
|
n = -1;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
elog(COMMERROR, "Unknown SSL error code");
|
elog(COMMERROR, "Unknown SSL error code");
|
||||||
|
n = -1;
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user