From 2eec92ff399a9096c89ca6ae7be4b4dbcc8b29ff Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= Date: Tue, 14 Aug 2018 17:45:15 +0200 Subject: [PATCH] Avoid SIGPIPE in t/local/36_verify.t --- ...Avoid-SIGPIPE-in-t-local-36_verify.t.patch | 57 +++++++++++++++++++ perl-Net-SSLeay.spec | 8 ++- 2 files changed, 64 insertions(+), 1 deletion(-) create mode 100644 Net-SSLeay-1.85-Avoid-SIGPIPE-in-t-local-36_verify.t.patch diff --git a/Net-SSLeay-1.85-Avoid-SIGPIPE-in-t-local-36_verify.t.patch b/Net-SSLeay-1.85-Avoid-SIGPIPE-in-t-local-36_verify.t.patch new file mode 100644 index 0000000..953d39f --- /dev/null +++ b/Net-SSLeay-1.85-Avoid-SIGPIPE-in-t-local-36_verify.t.patch @@ -0,0 +1,57 @@ +From 173cd9c1340f1f5231625a1dd4ecaea10c207622 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= +Date: Tue, 14 Aug 2018 16:55:52 +0200 +Subject: [PATCH] Avoid SIGPIPE in t/local/36_verify.t +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +t/local/36_verify.t fails randomly with OpenSSL 1.1.1: + + # Failed test 'Verify callback result and get_verify_result are equal' + # at t/local/36_verify.t line 111. + # got: '-1' + # expected: '0' + # Failed test 'Verify result is X509_V_ERR_NO_EXPLICIT_POLICY' + # at t/local/36_verify.t line 118. + # got: '-1' + # expected: '43' + Bailout called. Further testing stopped: failed to connect to server: Connection refused + FAILED--Further testing stopped: failed to connect to server: Connection refused + +I believe this because TLSv1.3 server can generate SIGPIPE if a client +disconnects too soon. + +Signed-off-by: Petr Písař +--- + t/local/36_verify.t | 10 ++++++++++ + 1 file changed, 10 insertions(+) + +diff --git a/t/local/36_verify.t b/t/local/36_verify.t +index e55b138..2837288 100644 +--- a/t/local/36_verify.t ++++ b/t/local/36_verify.t +@@ -266,10 +266,20 @@ sub run_server + + return if $pid != 0; + ++ $SIG{'PIPE'} = 'IGNORE'; + my $ctx = Net::SSLeay::CTX_new(); + Net::SSLeay::set_cert_and_key($ctx, $cert_pem, $key_pem); + my $ret = Net::SSLeay::CTX_check_private_key($ctx); + BAIL_OUT("Server: CTX_check_private_key failed: $cert_pem, $key_pem") unless $ret == 1; ++ if (&Net::SSLeay::OPENSSL_VERSION_NUMBER >= 0x1010100f) { ++ # TLS 1.3 server sends session tickets after a handhake as part of ++ # the SSL_accept(). If a client finishes all its job including closing ++ # TCP connectino before a server sends the tickets, SSL_accept() fails ++ # with SSL_ERROR_SYSCALL and EPIPE errno and the server receives ++ # SIGPIPE signal. ++ my $ret = Net::SSLeay::CTX_set_num_tickets($ctx, 0); ++ BAIL_OUT("Session tickets disabled") unless $ret; ++ } + + while (1) + { +-- +2.14.4 + diff --git a/perl-Net-SSLeay.spec b/perl-Net-SSLeay.spec index 411f095..1927002 100644 --- a/perl-Net-SSLeay.spec +++ b/perl-Net-SSLeay.spec @@ -9,7 +9,7 @@ Name: perl-Net-SSLeay Version: 1.85 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Perl extension for using OpenSSL License: Artistic 2.0 URL: https://metacpan.org/release/Net-SSLeay @@ -18,6 +18,8 @@ Source0: https://cpan.metacpan.org/authors/id/M/MI/MIKEM/Net-SSLeay-%{version}.t Patch0: Net-SSLeay-1.85-Adapt-to-OpenSSL-1.1.1.patch # Adapt tests to system-wide crypto policy, bug #1614884 Patch1: Net-SSLeay-1.85-Adapt-CTX_get_min_proto_version-tests-to-system-wide.patch +# Avoid SIGPIPE in t/local/36_verify.t, bug #1614884, CPAN RT#125218 +Patch2: Net-SSLeay-1.85-Avoid-SIGPIPE-in-t-local-36_verify.t.patch # =========== Module Build =========================== BuildRequires: coreutils BuildRequires: findutils @@ -75,6 +77,7 @@ so you can write servers or clients for more complicated applications. %setup -q -n Net-SSLeay-%{version} %patch0 -p1 %patch1 -p1 +%patch2 -p1 # Fix permissions in examples to avoid bogus doc-file dependencies chmod -c 644 examples/* @@ -122,6 +125,9 @@ perl -Iblib/{arch,lib} -MNet::SSLeay -e 'Net::SSLeay::CTX_v3_new()' %{_mandir}/man3/Net::SSLeay::Handle.3* %changelog +* Tue Aug 14 2018 Petr Pisar - 1.85-5 +- Avoid SIGPIPE in t/local/36_verify.t (bug #1614884) + * Mon Aug 13 2018 Petr Pisar - 1.85-4 - Adapt to OpenSSL 1.1.1 (bug #1614884) - Adapt tests to system-wide crypto policy (bug #1614884)