[
https://issues.apache.org/jira/browse/THRIFT-6248?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jens Geyer resolved THRIFT-6248.
--------------------------------
Assignee: Jens Geyer
Resolution: Fixed
> TSSLSocket does not compile against OpenSSL 1.1.1
> -------------------------------------------------
>
> Key: THRIFT-6248
> URL: https://issues.apache.org/jira/browse/THRIFT-6248
> Project: Thrift
> Issue Type: Bug
> Components: C++ - Library
> Reporter: Jens Geyer
> Assignee: Jens Geyer
> Priority: Major
> Fix For: 0.25.0
>
> Time Spent: 20m
> Remaining Estimate: 0h
>
> {{TSSLSocket.cpp}} has not compiled against OpenSSL 1.1.1 since THRIFT-6174.
> The {{authorize()}} commonName block selects const-qualified X509 types from
> 1.1.0 onwards:
> {code}
> #if OPENSSL_VERSION_NUMBER >= 0x10100000L && !defined(LIBRESSL_VERSION_NUMBER)
> const X509_NAME* name = hasDnsName ? nullptr : X509_get_subject_name(cert);
> {code}
> but {{X509_NAME_get_index_by_NID()}} was only constified in 3.0. At the exact
> release tags:
> * {{OpenSSL_1_1_1w}}: {{int X509_NAME_get_index_by_NID(X509_NAME *name, int
> nid, int lastpos);}}
> * {{openssl-3.0.0}}: {{int X509_NAME_get_index_by_NID(const X509_NAME *name,
> int nid, int lastpos);}}
> so on 1.1.x the const name cannot be passed to it.
> AppVeyor is the only CI configuration that builds against a pre-3.0 library;
> it reports {{Found OpenSSL ... (found version "1.1.1w")}}, and it is the only
> one that went red. Every GitHub Actions job builds against 3.x and compiles
> the const path without complaint.
> All five MSVC jobs of build 54711447 (master):
> {code}
> TSSLSocket.cpp(885,14): error C2664: 'int
> X509_NAME_get_index_by_NID(X509_NAME *,int,int)': cannot convert argument 1
> from 'const X509_NAME *' to 'X509_NAME *'
> {code}
> Reproduced with gcc against a from-source 1.1.1w, same single error at the
> same line:
> {code}
> TSSLSocket.cpp:885:41: error: invalid conversion from 'const X509_NAME*' to
> 'X509_NAME*' [-fpermissive]
> {code}
> It is the only error in the build. c_glib is unaffected:
> {{thrift_ssl_socket.c}} does no X509_NAME lookup at all, it uses
> {{SSL_set1_host()}}.
> Fix: move the three guards in that block from {{0x10100000L}} to
> {{0x30000000L}}. At 3.0 the const path is still compiled by the CI
> configurations that do have 3.x, which was THRIFT-6174's reason for choosing
> 1.1.0 over 4.0 in the first place.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)