Repository navigation
Delete local references to Java-returned result arrays in JNI callbacks - #1016
Merged
Merged
Conversation
Motivation: resultArray in cert_compress.c compress()/decompress() and resultBytes in the SSL_PRIVATE_KEY_METHOD callbacks in sslcontext.c are obtained from CallObjectMethod/GetObjectField but were never deleted on any exit path. These are invoked repeatedly as native callbacks from OpenSSL/BoringSSL (once per certificate needing (de)compression, or per sign/decrypt/complete call), so the leaked local references accumulate and can exhaust the JNI local reference table. Modifications: - cert_compress.c: delete resultArray before every return in compress() and decompress() once it has been obtained. - sslcontext.c: delete resultBytes at the complete: label in tcn_private_key_sign_java and tcn_private_key_decrypt_java, and before every return in tcn_private_key_complete_java. Result: No longer leak local references to compression/private-key callback result arrays.
franz1981
approved these changes
Sep 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation:
resultArray in cert_compress.c compress()/decompress() and resultBytes
in the SSL_PRIVATE_KEY_METHOD callbacks in sslcontext.c are obtained
from CallObjectMethod/GetObjectField but were never deleted on any
exit path. These are invoked repeatedly as native callbacks from
OpenSSL/BoringSSL (once per certificate needing (de)compression, or
per sign/decrypt/complete call), so the leaked local references
accumulate and can exhaust the JNI local reference table.
Modifications:
and decompress() once it has been obtained.
tcn_private_key_sign_java and tcn_private_key_decrypt_java, and
before every return in tcn_private_key_complete_java.
Result:
No longer leak local references to compression/private-key callback
result arrays.