This is an automated email from the ASF dual-hosted git repository.
markt-asf pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomcat.git
The following commit(s) were added to refs/heads/main by this push:
new 50e345dca2 Align missing FIPS handling with APR listener
50e345dca2 is described below
commit 50e345dca2f0cb5dfa7f802628ca10e6629cdc61
Author: Mark Thomas <[email protected]>
AuthorDate: Thu Sep 17 14:52:35 2026 +0100
Align missing FIPS handling with APR listener
---
.../catalina/core/OpenSSLLifecycleListener.java | 77 +++++++++++++---------
webapps/docs/changelog.xml | 5 ++
2 files changed, 50 insertions(+), 32 deletions(-)
diff --git a/java/org/apache/catalina/core/OpenSSLLifecycleListener.java
b/java/org/apache/catalina/core/OpenSSLLifecycleListener.java
index 02ba1d5132..b887d472e3 100644
--- a/java/org/apache/catalina/core/OpenSSLLifecycleListener.java
+++ b/java/org/apache/catalina/core/OpenSSLLifecycleListener.java
@@ -117,57 +117,70 @@ public class OpenSSLLifecycleListener implements
LifecycleListener {
@Override
public void lifecycleEvent(LifecycleEvent event) {
- boolean initError = false;
if (Lifecycle.BEFORE_INIT_EVENT.equals(event.getType())) {
if (!(event.getLifecycle() instanceof Server)) {
log.warn(sm.getString("listener.notServer",
event.getLifecycle().getClass().getSimpleName()));
}
synchronized (lock) {
- if (!JreCompat.isJre22Available()) {
- log.info(sm.getString("openssllistener.java22"));
- OpenSSLStatus.setInitialized(true);
- return;
- }
+ boolean initError = false;
try {
- Class<?> openSSLLibraryClass =
-
Class.forName("org.apache.tomcat.util.net.openssl.panama.OpenSSLLibrary");
- openSSLLibraryClass.getMethod("init").invoke(null);
- } catch (Throwable t) {
- Throwable throwable =
ExceptionUtils.unwrapInvocationTargetException(t);
- ExceptionUtils.handleThrowable(throwable);
- log.error(sm.getString("openssllistener.sslInit"),
throwable);
- initError = true;
- }
- // Failure to initialize FIPS mode is fatal
- if (!(null == getFIPSMode() ||
"off".equalsIgnoreCase(getFIPSMode())) && !isFIPSModeActive()) {
- String errorMessage =
sm.getString("openssllistener.initializeFIPSFailed");
- Error e = new Error(errorMessage);
- // Log here, because thrown error might be not logged
- log.fatal(errorMessage, e);
- initError = true;
+ if (!JreCompat.isJre22Available()) {
+ log.info(sm.getString("openssllistener.java22"));
+ OpenSSLStatus.setInitialized(true);
+ return;
+ }
+ try {
+ Class<?> openSSLLibraryClass =
+
Class.forName("org.apache.tomcat.util.net.openssl.panama.OpenSSLLibrary");
+ openSSLLibraryClass.getMethod("init").invoke(null);
+ } catch (Throwable t) {
+ Throwable throwable =
ExceptionUtils.unwrapInvocationTargetException(t);
+ ExceptionUtils.handleThrowable(throwable);
+ log.error(sm.getString("openssllistener.sslInit"),
throwable);
+ initError = true;
+ }
+ // Failure to initialize FIPS mode is fatal
+ if (!(null == getFIPSMode() ||
"off".equalsIgnoreCase(getFIPSMode())) && !isFIPSModeActive()) {
+ String errorMessage =
sm.getString("openssllistener.initializeFIPSFailed");
+ Error e = new Error(errorMessage);
+ // Log here, because thrown error might be not logged
+ log.fatal(errorMessage, e);
+ initError = true;
+ throw e;
+ }
+ } finally {
+ if (initError) {
+ doDestroy();
+ }
}
}
}
- if (initError ||
Lifecycle.AFTER_DESTROY_EVENT.equals(event.getType())) {
+ if (Lifecycle.AFTER_DESTROY_EVENT.equals(event.getType())) {
synchronized (lock) {
if (!JreCompat.isJre22Available()) {
return;
}
// Note: Without the listener, destroy will never be called
(which is not a significant problem)
- try {
- Class<?> openSSLLibraryClass =
-
Class.forName("org.apache.tomcat.util.net.openssl.panama.OpenSSLLibrary");
- openSSLLibraryClass.getMethod("destroy").invoke(null);
- } catch (Throwable t) {
- Throwable throwable =
ExceptionUtils.unwrapInvocationTargetException(t);
- ExceptionUtils.handleThrowable(throwable);
- log.warn(sm.getString("openssllistener.destroy"),
throwable);
- }
+ doDestroy();
}
}
}
+
+ private void doDestroy() {
+ try {
+ Class<?> openSSLLibraryClass =
+
Class.forName("org.apache.tomcat.util.net.openssl.panama.OpenSSLLibrary");
+ openSSLLibraryClass.getMethod("destroy").invoke(null);
+ } catch (Throwable t) {
+ Throwable throwable =
ExceptionUtils.unwrapInvocationTargetException(t);
+ ExceptionUtils.handleThrowable(throwable);
+ log.warn(sm.getString("openssllistener.destroy"), throwable);
+ }
+ }
+
+
/**
* Returns the SSL engine information.
*
diff --git a/webapps/docs/changelog.xml b/webapps/docs/changelog.xml
index bc568e92a8..2cdda74a3e 100644
--- a/webapps/docs/changelog.xml
+++ b/webapps/docs/changelog.xml
@@ -287,6 +287,11 @@
premature end of stream as an I/O error. Based on pull request
<pr>1067</pr> by aoto-tech. (markt)
</fix>
+ <fix>
+ Align <code>OpenSSLLifecycleListener</code> with
+ <code>AprLifecycleListener</code> and throw an Error when FIPS is
+ requested but not available. (markt)
+ </fix>
</changelog>
</subsection>
<subsection name="Coyote">
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]