Skip to content

Commit f39f2e1

Browse files
author
Alex Choulos
committed
Make recording the selected credential opt-in per context and store the id in existing padding
1 parent 86cecc7 commit f39f2e1

5 files changed

Lines changed: 31 additions & 8 deletions

File tree

‎boringssl-static/src/test/java/io/netty/internal/tcnative/SSLCredentialIdTest.java‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,7 @@ public void newCredentialsHavePositiveDistinctIds() throws Exception {
6161
public void freshSslHasNoSelectedCredentialId() throws Exception {
6262
long ctx = SSLContext.make(SSL.SSL_PROTOCOL_TLSV1_2, SSL.SSL_MODE_SERVER);
6363
try {
64+
SSLContext.setRecordSelectedCredential(ctx, true);
6465
long ssl = SSL.newSSL(ctx, true);
6566
try {
6667
assertEquals(0, SSL.getSelectedCredentialId(ssl));

‎openssl-classes/src/main/java/io/netty/internal/tcnative/SSL.java‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1011,9 +1011,10 @@ public static AsyncTask getAsyncTask(long ssl) {
10111011
* <p>Returns:
10121012
* <ul>
10131013
* <li>during a handshake that has already selected a credential, the id of that credential;</li>
1014-
* <li>otherwise, the id recorded by the most recent completed handshake;</li>
1015-
* <li>{@code 0} when no credential was selected, when the credential came from a legacy API, or when no
1016-
* handshake has completed yet.</li>
1014+
* <li>otherwise, the id recorded by the most recent completed handshake, if
1015+
* {@link SSLContext#setRecordSelectedCredential(long, boolean)} is enabled;</li>
1016+
* <li>{@code 0} when no credential was selected, when the credential came from a legacy API, when recording is
1017+
* disabled, or when no handshake has completed yet.</li>
10171018
* </ul>
10181019
*
10191020
* <p>This is a BoringSSL-specific feature.</p>

‎openssl-classes/src/main/java/io/netty/internal/tcnative/SSLContext.java‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -683,6 +683,17 @@ public static void setAlpnProtos(long ctx, String[] alpnProtos, int selectorFail
683683
*/
684684
public static native void setUseTasks(long ctx, boolean useTasks);
685685

686+
/**
687+
* Enable or disable recording the credential selected by each completed handshake, so that it can be obtained
688+
* via {@link SSL#getSelectedCredentialId(long)} after the handshake. Disabled by default.
689+
*
690+
* <p>This only has an effect when using BoringSSL.</p>
691+
*
692+
* @param ctx context to use
693+
* @param record {@code true} to enable, {@code false} to disable.
694+
*/
695+
public static native void setRecordSelectedCredential(long ctx, boolean record);
696+
686697
/**
687698
* Adds a certificate compression algorithm to the given {@link SSLContext} or throws an
688699
* exception if certificate compression is not supported or the algorithm not recognized.

‎openssl-dynamic/src/main/c/ssl_private.h‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -389,6 +389,7 @@ struct tcn_ssl_ctxt_t {
389389
unsigned char context_id[SHA_DIGEST_LENGTH];
390390

391391
int use_tasks;
392+
int record_selected_credential;
392393
};
393394

394395
// Store the callback to run and also if it was consumed via SSL.getTask(...).
@@ -404,16 +405,15 @@ void tcn_ssl_task_free(JNIEnv*, tcn_ssl_task_t*);
404405
typedef struct tcn_ssl_state_t tcn_ssl_state_t;
405406
struct tcn_ssl_state_t {
406407
int handshakeCount;
408+
// Fills the padding before ctx so recording the selected credential adds no per-connection memory.
409+
apr_uint32_t selected_credential_id;
407410
tcn_ssl_ctxt_t *ctx;
408411
tcn_ssl_task_t* ssl_task;
409412
tcn_ssl_verify_config_t verify_config;
410413
// Saved at async task creation time so the retry path can reproduce the
411414
// len < sk_CRYPTO_BUFFER_num(chain) check (both locals are 0/NULL there).
412415
int task_array_len;
413416
int task_chain_num;
414-
#ifdef OPENSSL_IS_BORINGSSL
415-
jlong selected_credential_id;
416-
#endif
417417
};
418418

419419
#define TCN_GET_SSL_CTX(ssl, C) \

‎openssl-dynamic/src/main/c/sslcontext.c‎

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -194,8 +194,9 @@ static void ssl_info_callback(const SSL *ssl, int where, int ret) {
194194
if (0 != (where & SSL_CB_HANDSHAKE_DONE)) {
195195
// BoringSSL frees the handshake state (and its selected credential) before SSL_do_handshake returns,
196196
// so record the selection here. Assign unconditionally so a later handshake without one clears it.
197-
if ((state = tcn_SSL_get_app_state(ssl)) != NULL) {
198-
state->selected_credential_id = tcn_SSL_CREDENTIAL_get_id(SSL_get0_selected_credential(ssl));
197+
if ((state = tcn_SSL_get_app_state(ssl)) != NULL && state->ctx->record_selected_credential != 0) {
198+
state->selected_credential_id =
199+
(apr_uint32_t) tcn_SSL_CREDENTIAL_get_id(SSL_get0_selected_credential(ssl));
199200
}
200201
}
201202
#endif
@@ -2917,6 +2918,14 @@ TCN_IMPLEMENT_CALL(void, SSLContext, setUseTasks)(TCN_STDARGS, jlong ctx, jboole
29172918
c->use_tasks = useTasks == JNI_TRUE ? 1 : 0;
29182919
}
29192920

2921+
TCN_IMPLEMENT_CALL(void, SSLContext, setRecordSelectedCredential)(TCN_STDARGS, jlong ctx, jboolean record) {
2922+
tcn_ssl_ctxt_t *c = J2P(ctx, tcn_ssl_ctxt_t *);
2923+
2924+
TCN_CHECK_NULL(c, ctx, /* void */);
2925+
2926+
c->record_selected_credential = record == JNI_TRUE ? 1 : 0;
2927+
}
2928+
29202929

29212930
TCN_IMPLEMENT_CALL(jboolean, SSLContext, setCurvesList0)(TCN_STDARGS, jlong ctx, jstring curves) {
29222931
tcn_ssl_ctxt_t *c = J2P(ctx, tcn_ssl_ctxt_t *);
@@ -3113,6 +3122,7 @@ static const JNINativeMethod fixed_method_table[] = {
31133122
{ TCN_METHOD_TABLE_ENTRY(disableOcsp, (J)V, SSLContext) },
31143123
{ TCN_METHOD_TABLE_ENTRY(getSslCtx, (J)J, SSLContext) },
31153124
{ TCN_METHOD_TABLE_ENTRY(setUseTasks, (JZ)V, SSLContext) },
3125+
{ TCN_METHOD_TABLE_ENTRY(setRecordSelectedCredential, (JZ)V, SSLContext) },
31163126
{ TCN_METHOD_TABLE_ENTRY(setNumTickets, (JI)Z, SSLContext) },
31173127
{ TCN_METHOD_TABLE_ENTRY(setCurvesList0, (JLjava/lang/String;)Z, SSLContext) },
31183128
{ TCN_METHOD_TABLE_ENTRY(setMaxCertList, (JI)V, SSLContext) },

0 commit comments

Comments
 (0)