pgsql: Set type identifier on BIO - Mailing list pgsql-committers

From Daniel Gustafsson
Subject pgsql: Set type identifier on BIO
Date
Msg-id E1mFyNS-00081V-4A@gemulon.postgresql.org
Whole thread Raw
List pgsql-committers
Set type identifier on BIO

In OpenSSL there are two types of BIO's (I/O abstractions):
source/sink and filters. A source/sink BIO is a source and/or
sink of data, ie one acting on a socket or a file. A filter
BIO takes a stream of input from another BIO and transforms it.
In order for BIO_find_type() to be able to traverse the chain
of BIO's and correctly find all BIO's of a certain type they
shall have the type bit set accordingly, source/sink BIO's
(what PostgreSQL implements) use BIO_TYPE_SOURCE_SINK and
filter BIO's use BIO_TYPE_FILTER. In addition to these, file
descriptor based BIO's should have the descriptor bit set,
BIO_TYPE_DESCRIPTOR.

The PostgreSQL implementation didn't set the type bits, which
went unnoticed for a long time as it's only really relevant
for code auditing the OpenSSL installation, or doing similar
tasks. It is required by the API though, so this fixes it.

Backpatch through 9.6 as this has been wrong for a long time.

Author: Itamar Gafni
Discussion: https://postgr.es/m/SN6PR06MB39665EC10C34BB20956AE4578AF39@SN6PR06MB3966.namprd06.prod.outlook.com
Backpatch-through: 9.6

Branch
------
REL9_6_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/0a88d4ece83cc20f0d64be7930666e8900991cdc

Modified Files
--------------
src/backend/libpq/be-secure-openssl.c    | 1 +
src/interfaces/libpq/fe-secure-openssl.c | 1 +
2 files changed, 2 insertions(+)


pgsql-committers by date:

Previous
From: Daniel Gustafsson
Date:
Subject: pgsql: Set type identifier on BIO
Next
From: Michael Meskes
Date:
Subject: pgsql: Improved ECPG warning as suggested by Michael Paquier and remove