protocol: resolve TLS transport from the bound session, not thread-local io_ssl
file_send.c chose between sendfile() and the TLS-aware buffered path by calling io_get_ssl(), which reads the thread-local io_ssl. A worker thread that bound a TLS ProtocolSession via protocol_session_bind() never ran the handshake in that thread, so io_ssl is NULL there and a TLS + --threads transfer took the raw sendfile() path on an encrypted socket. Add protocol_current_ssl(), which prefers the bound session's SSL and falls back to io_ssl on the fd-shim path, and use it in file_send.c. Un-xfail test_tls_with_multithreading.
This commit is contained in:
@@ -124,8 +124,12 @@ bool file_send_sendfile_with_skip(File* file, int file_descriptor, bool use_meta
|
||||
}
|
||||
|
||||
/* sendfile cannot encrypt TLS records. Keep the framing identical but
|
||||
route encrypted transfers through the deadline-aware IO layer. */
|
||||
if (io_get_ssl() != NULL) {
|
||||
route encrypted transfers through the deadline-aware IO layer. Resolve
|
||||
the transport from the bound session, not the thread-local io_ssl: a
|
||||
worker thread running a TLS transfer has its SSL only on the session it
|
||||
bound, so io_get_ssl() would be NULL there and the raw sendfile() path
|
||||
would be taken on an encrypted socket. */
|
||||
if (protocol_current_ssl() != NULL) {
|
||||
unsigned char buffer[64 * 1024];
|
||||
unsigned long long remaining = file_size;
|
||||
bool ok = true;
|
||||
|
||||
Reference in New Issue
Block a user