Skip to content

ssl module with OpenSSL 3.0 does not throw SSLEOFError on unclean shutdown #95494

Description

@davidben

Patch incoming. Filing this so there's a bug to attach the PR to.

GH-25309 enabled SSL_OP_IGNORE_UNEXPECTED_EOF by default, with a comment that it restores OpenSSL 1.1.1 behavior, but this wasn't quite right. That option causes OpenSSL to treat transport EOF as the same as close_notify (i.e SSL_ERROR_ZERO_RETURN), whereas Python actually has distinct SSLEOFError and SSLZeroReturnError exceptions. (The latter is usually mapped to a zero return from read.) In OpenSSL 1.1.1, the ssl module would raise them for transport EOF and close_notify, respectively. In OpenSSL 3.0, both act like close_notify.

Linked PRs

Activity

  1. added a commit that references this issue on Jul 31, 2022
  2. added
    3.11only security fixes
    3.12only security fixes
    on Aug 3, 2022
  3. added a commit that references this issue on Mar 22, 2023
  4. added 2 commits that reference this issue on Mar 24, 2023
  5. added a commit that references this issue on Mar 27, 2023
  6. added a commit that references this issue on Mar 27, 2023
  7. ambv commented on Mar 27, 2023

    @ambv
    Contributor

    This is now landed in all Python versions that support OpenSSL 3.0.

  8. added a commit that references this issue on Mar 27, 2023
  9. added a commit that references this issue on Apr 11, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.10 (EOL)end of life3.11only security fixes3.12only security fixestopic-SSLtype-bugAn unexpected behavior, bug, or error

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions