diff options
author | Pablo Galindo Salgado <Pablogsal@gmail.com> | 2023-08-03 12:37:14 (GMT) |
---|---|---|
committer | GitHub <noreply@github.com> | 2023-08-03 12:37:14 (GMT) |
commit | 77e09192b5f1caf14cd5f92ccb53a4592e83e8bc (patch) | |
tree | 39824d48fecb08bd0979236d393cdd32c708feef | |
parent | a73daf54ebd7bd6bf32e82766a605ebead2f128c (diff) | |
download | cpython-77e09192b5f1caf14cd5f92ccb53a4592e83e8bc.zip cpython-77e09192b5f1caf14cd5f92ccb53a4592e83e8bc.tar.gz cpython-77e09192b5f1caf14cd5f92ccb53a4592e83e8bc.tar.bz2 |
gh-107077: Raise SSLCertVerificationError even if the error is set via SSL_ERROR_SYSCALL (#107586)
Co-authored-by: T. Wouters <thomas@python.org>
-rw-r--r-- | Misc/NEWS.d/next/Library/2023-08-03-12-52-19.gh-issue-107077.-pzHD6.rst | 6 | ||||
-rw-r--r-- | Modules/_ssl.c | 4 |
2 files changed, 10 insertions, 0 deletions
diff --git a/Misc/NEWS.d/next/Library/2023-08-03-12-52-19.gh-issue-107077.-pzHD6.rst b/Misc/NEWS.d/next/Library/2023-08-03-12-52-19.gh-issue-107077.-pzHD6.rst new file mode 100644 index 0000000..ecaf437 --- /dev/null +++ b/Misc/NEWS.d/next/Library/2023-08-03-12-52-19.gh-issue-107077.-pzHD6.rst @@ -0,0 +1,6 @@ +Seems that in some conditions, OpenSSL will return ``SSL_ERROR_SYSCALL`` +instead of ``SSL_ERROR_SSL`` when a certification verification has failed, +but the error parameters will still contain ``ERR_LIB_SSL`` and +``SSL_R_CERTIFICATE_VERIFY_FAILED``. We are now detecting this situation and +raising the appropiate ``ssl.SSLCertVerificationError``. Patch by Pablo +Galindo diff --git a/Modules/_ssl.c b/Modules/_ssl.c index b61d10d..c001b87 100644 --- a/Modules/_ssl.c +++ b/Modules/_ssl.c @@ -667,6 +667,10 @@ PySSL_SetError(PySSLSocket *sslsock, int ret, const char *filename, int lineno) errstr = "Some I/O error occurred"; } } else { + if (ERR_GET_LIB(e) == ERR_LIB_SSL && + ERR_GET_REASON(e) == SSL_R_CERTIFICATE_VERIFY_FAILED) { + type = state->PySSLCertVerificationErrorObject; + } p = PY_SSL_ERROR_SYSCALL; } break; |