Repository navigation
Conversation
…al works post-handshake SSL_get0_selected_credential reads the handshake state, which BoringSSL frees before SSL_do_handshake returns, so SSL.getSelectedCredential always returned 0 once the handshake completed. Sample the credential in ssl_info_callback on SSL_CB_HANDSHAKE_DONE, hold a ref in tcn_ssl_state_t and release it in free_ssl_state. On renegotiation the previous ref is released and replaced, so the cache reflects the most recent completed handshake. getSelectedCredential tries the live lookup first (non-NULL only while the handshake state exists) and falls back to the cached credential.
choulos
force-pushed
the
achoulos/cache-selected-credential
branch
from
October 8, 2026 17:36
871a40e to
dda31e3
Compare
added 4 commits
October 8, 2026 14:55
…Credential works post-handshake" This reverts commit dda31e3.
…he id in existing padding
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
We would like to know which SSL Credential was selected post-handshake within netty, so that we may accurately track the effects of rolling out BoringSSL SSL Credential API to more endpoints.
SSL.getSelectedCredentialwrapsSSL_get0_selected_credential, which reads the handshake state. BoringSSL frees that state beforeSSL_do_handshakereturns, so the call returns 0 once the handshake has completed, for both TLS 1.2 and 1.3.Each credential created by
SSLCredential.newX509()ornewDelegated()now gets a unique id, stored in credential ex_data. When enabled withSSLContext.setRecordSelectedCredential,ssl_info_callbackrecords the selected credential's id onSSL_CB_HANDSHAKE_DONE, overwriting it on every handshake.SSL.getSelectedCredentialIdreturns it. tcnative takes no new references on the credential, and callers map the id to their own metadata.Recording is off by default, following the
setUseTaskspattern. The id is stored in existing padding intcn_ssl_state_t, so the struct size is unchanged, and when disabled the cost is one flag check per completed handshake.