This is an automated email from the ASF dual-hosted git repository.

markt-asf pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomcat.git


The following commit(s) were added to refs/heads/main by this push:
     new 50e345dca2 Align missing FIPS handling with APR listener
50e345dca2 is described below

commit 50e345dca2f0cb5dfa7f802628ca10e6629cdc61
Author: Mark Thomas <[email protected]>
AuthorDate: Thu Sep 17 14:52:35 2026 +0100

    Align missing FIPS handling with APR listener
---
 .../catalina/core/OpenSSLLifecycleListener.java    | 77 +++++++++++++---------
 webapps/docs/changelog.xml                         |  5 ++
 2 files changed, 50 insertions(+), 32 deletions(-)

diff --git a/java/org/apache/catalina/core/OpenSSLLifecycleListener.java 
b/java/org/apache/catalina/core/OpenSSLLifecycleListener.java
index 02ba1d5132..b887d472e3 100644
--- a/java/org/apache/catalina/core/OpenSSLLifecycleListener.java
+++ b/java/org/apache/catalina/core/OpenSSLLifecycleListener.java
@@ -117,57 +117,70 @@ public class OpenSSLLifecycleListener implements 
LifecycleListener {
     @Override
     public void lifecycleEvent(LifecycleEvent event) {
 
-        boolean initError = false;
         if (Lifecycle.BEFORE_INIT_EVENT.equals(event.getType())) {
             if (!(event.getLifecycle() instanceof Server)) {
                 log.warn(sm.getString("listener.notServer", 
event.getLifecycle().getClass().getSimpleName()));
             }
             synchronized (lock) {
-                if (!JreCompat.isJre22Available()) {
-                    log.info(sm.getString("openssllistener.java22"));
-                    OpenSSLStatus.setInitialized(true);
-                    return;
-                }
+                boolean initError = false;
                 try {
-                    Class<?> openSSLLibraryClass =
-                            
Class.forName("org.apache.tomcat.util.net.openssl.panama.OpenSSLLibrary");
-                    openSSLLibraryClass.getMethod("init").invoke(null);
-                } catch (Throwable t) {
-                    Throwable throwable = 
ExceptionUtils.unwrapInvocationTargetException(t);
-                    ExceptionUtils.handleThrowable(throwable);
-                    log.error(sm.getString("openssllistener.sslInit"), 
throwable);
-                    initError = true;
-                }
-                // Failure to initialize FIPS mode is fatal
-                if (!(null == getFIPSMode() || 
"off".equalsIgnoreCase(getFIPSMode())) && !isFIPSModeActive()) {
-                    String errorMessage = 
sm.getString("openssllistener.initializeFIPSFailed");
-                    Error e = new Error(errorMessage);
-                    // Log here, because thrown error might be not logged
-                    log.fatal(errorMessage, e);
-                    initError = true;
+                    if (!JreCompat.isJre22Available()) {
+                        log.info(sm.getString("openssllistener.java22"));
+                        OpenSSLStatus.setInitialized(true);
+                        return;
+                    }
+                    try {
+                        Class<?> openSSLLibraryClass =
+                                
Class.forName("org.apache.tomcat.util.net.openssl.panama.OpenSSLLibrary");
+                        openSSLLibraryClass.getMethod("init").invoke(null);
+                    } catch (Throwable t) {
+                        Throwable throwable = 
ExceptionUtils.unwrapInvocationTargetException(t);
+                        ExceptionUtils.handleThrowable(throwable);
+                        log.error(sm.getString("openssllistener.sslInit"), 
throwable);
+                        initError = true;
+                    }
+                    // Failure to initialize FIPS mode is fatal
+                    if (!(null == getFIPSMode() || 
"off".equalsIgnoreCase(getFIPSMode())) && !isFIPSModeActive()) {
+                        String errorMessage = 
sm.getString("openssllistener.initializeFIPSFailed");
+                        Error e = new Error(errorMessage);
+                        // Log here, because thrown error might be not logged
+                        log.fatal(errorMessage, e);
+                        initError = true;
+                        throw e;
+                    }
+                } finally {
+                    if (initError) {
+                        doDestroy();
+                    }
                 }
             }
         }
-        if (initError || 
Lifecycle.AFTER_DESTROY_EVENT.equals(event.getType())) {
+        if (Lifecycle.AFTER_DESTROY_EVENT.equals(event.getType())) {
             synchronized (lock) {
                 if (!JreCompat.isJre22Available()) {
                     return;
                 }
                 // Note: Without the listener, destroy will never be called 
(which is not a significant problem)
-                try {
-                    Class<?> openSSLLibraryClass =
-                            
Class.forName("org.apache.tomcat.util.net.openssl.panama.OpenSSLLibrary");
-                    openSSLLibraryClass.getMethod("destroy").invoke(null);
-                } catch (Throwable t) {
-                    Throwable throwable = 
ExceptionUtils.unwrapInvocationTargetException(t);
-                    ExceptionUtils.handleThrowable(throwable);
-                    log.warn(sm.getString("openssllistener.destroy"), 
throwable);
-                }
+                doDestroy();
             }
         }
 
     }
 
+
+    private void doDestroy() {
+        try {
+            Class<?> openSSLLibraryClass =
+                    
Class.forName("org.apache.tomcat.util.net.openssl.panama.OpenSSLLibrary");
+            openSSLLibraryClass.getMethod("destroy").invoke(null);
+        } catch (Throwable t) {
+            Throwable throwable = 
ExceptionUtils.unwrapInvocationTargetException(t);
+            ExceptionUtils.handleThrowable(throwable);
+            log.warn(sm.getString("openssllistener.destroy"), throwable);
+        }
+    }
+
+
     /**
      * Returns the SSL engine information.
      *
diff --git a/webapps/docs/changelog.xml b/webapps/docs/changelog.xml
index bc568e92a8..2cdda74a3e 100644
--- a/webapps/docs/changelog.xml
+++ b/webapps/docs/changelog.xml
@@ -287,6 +287,11 @@
         premature end of stream as an I/O error. Based on pull request
         <pr>1067</pr> by aoto-tech. (markt)
       </fix>
+      <fix>
+        Align <code>OpenSSLLifecycleListener</code> with
+        <code>AprLifecycleListener</code> and throw an Error when FIPS is
+        requested but not available. (markt)
+      </fix>
     </changelog>
   </subsection>
   <subsection name="Coyote">


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to