Skip to content

ssl: keep original SSLContext alive after servername_cb - #1090

Merged
rhenium merged 1 commit into
ruby:masterfrom
rhenium:ky/ssl-mark-orig-sslctx
Oct 5, 2026
Merged

rhenium merged 1 commit into
ruby:masterfrom
rhenium:ky/ssl-mark-orig-sslctx

Conversation

@rhenium

@rhenium rhenium commented Aug 5, 2026 •

Copy link
Copy Markdown
Member

Keep the original SSLContext in a separate instance variable to prevent it from being GC'ed.

When the SNI callback accepts the provided server name, it may replace the SSL_CTX with SSL_set_SSL_CTX() and update SSLSocket#context. However, despite its name, SSL_set_SSL_CTX() does not use all parameters from the new SSL_CTX. In particular, callbacks set by the original SSL_CTX remain in use and therefore require the corresponding SSLContext object to stay alive.


Noticed while reviewing #1089.

@rhenium

rhenium commented Aug 6, 2026

Copy link
Copy Markdown
Member Author

This turned out not to be needed for now, so I'm closing this.

@rhenium rhenium closed this Aug 6, 2026
@rhenium rhenium reopened this Oct 5, 2026
@rhenium

rhenium commented Oct 5, 2026

Copy link
Copy Markdown
Member Author

Reopening because it seems that this is actually still required.

SSL appears to keep using the original SSL_CTX for session management even after SSL_set_SSL_CTX() has been called, and SSLContext#session_remove_cb requires that the corresponding SSLContext to be alive.

Keep the original SSLContext in a separate instance variable to prevent
it from being GC'ed while its underlying SSL_CTX is still in use.

When the SNI callback accepts the provided server name, it can replace
the SSL_CTX with SSL_set_SSL_CTX() and update SSLSocket#context.
However, although this is poorly documented, SSL_set_SSL_CTX() does not
appear to replace all uses of the original SSL_CTX with the new one. In
particular, session management still uses the original SSL_CTX and
therefore requires that the corresponding SSLContext object to remain
alive for the lifetime of SSLSocket.
@rhenium
rhenium force-pushed the ky/ssl-mark-orig-sslctx branch from 801c7df to 77e8b6d Compare October 5, 2026 16:45
@rhenium
rhenium merged commit ede609b into ruby:master Oct 5, 2026
48 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant