protocol: resolve TLS transport from the bound session, not thread-local io_ssl

file_send.c chose between sendfile() and the TLS-aware buffered path by
calling io_get_ssl(), which reads the thread-local io_ssl. A worker thread
that bound a TLS ProtocolSession via protocol_session_bind() never ran the
handshake in that thread, so io_ssl is NULL there and a TLS + --threads
transfer took the raw sendfile() path on an encrypted socket.

Add protocol_current_ssl(), which prefers the bound session's SSL and falls
back to io_ssl on the fd-shim path, and use it in file_send.c. Un-xfail
test_tls_with_multithreading.
This commit is contained in:
2026-09-23 00:18:29 +02:00
parent 6db9827b87
commit 1f8d60e30d
4 changed files with 26 additions and 3 deletions
-1
View File
@@ -146,7 +146,6 @@ class TestTLSBasic:
assert not missing, f"Missing files: {missing}"
assert not mismatches, f"Mismatched files: {mismatches}"
@pytest.mark.xfail(reason="TLS multithreading has architectural limitations with per-thread SSL context")
def test_tls_with_multithreading(self, certs):
"""TLS + multithreading."""
clean_dir(DEST_DIR)