https://bugs.openldap.org/show_bug.cgi?id=10579
Issue ID: 10579 Summary: tlso_sb_{read,write} don't handle the opposite condition Product: OpenLDAP Version: 2.7.0 Hardware: All OS: All Status: UNCONFIRMED Keywords: needs_review Severity: normal Priority: --- Component: lloadd Assignee: bugs@openldap.org Reporter: ondra@mistotebe.net Target Milestone: ---
With non-blocking BIO (lloadd), a SSL_write can error out with SSL_ERROR_WANT_READ and vice versa, e.g. at renegotiation or more points if TLS 1.3 is in place. Without knowing that, lloadd (or other applications if we ever say non-blocking OpenSSL use is supported) cannot make the right decisions, e.g. close a healthy connection.
Of course lloadd also needs to expect this situation and arm the correct callback otherwise things get even worse.
https://bugs.openldap.org/show_bug.cgi?id=10579
Ondřej Kuzník ondra@mistotebe.net changed:
What |Removed |Added ---------------------------------------------------------------------------- See Also| |https://bugs.openldap.org/s | |how_bug.cgi?id=10578
https://bugs.openldap.org/show_bug.cgi?id=10579
Quanah Gibson-Mount quanah@openldap.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Target Milestone|--- |2.6.15 Version|2.7.0 |2.6.14 Keywords|needs_review |
https://bugs.openldap.org/show_bug.cgi?id=10579
Quanah Gibson-Mount quanah@openldap.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Ever confirmed|0 |1 Assignee|bugs@openldap.org |ondra@mistotebe.net Status|UNCONFIRMED |IN_PROGRESS
--- Comment #1 from Quanah Gibson-Mount quanah@openldap.org --- https://git.openldap.org/openldap/openldap/-/merge_requests/916
https://bugs.openldap.org/show_bug.cgi?id=10579
Quanah Gibson-Mount quanah@openldap.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|IN_PROGRESS |RESOLVED Resolution|--- |TEST
--- Comment #2 from Quanah Gibson-Mount quanah@openldap.org --- head:
• da8f9237 by Ondřej Kuzník at 2026-09-04T21:29:03+00:00 ITS#10579 libldap: resync I/O flags after TLS read/write
• f760ba97 by Ondřej Kuzník at 2026-09-04T21:29:03+00:00 ITS#10579 lloadd: handle pending reads blocking a write path
RE27:
• 868f55ab by Ondřej Kuzník at 2026-09-08T16:30:22+00:00 ITS#10579 libldap: resync I/O flags after TLS read/write
• 5a1fae8d by Ondřej Kuzník at 2026-09-08T16:30:28+00:00 ITS#10579 lloadd: handle pending reads blocking a write path
RE26:
• 4666e007 by Ondřej Kuzník at 2026-09-08T16:31:51+00:00 ITS#10579 libldap: resync I/O flags after TLS read/write
• 5efbfeaf by Ondřej Kuzník at 2026-09-08T16:32:03+00:00 ITS#10579 lloadd: handle pending reads blocking a write path
https://bugs.openldap.org/show_bug.cgi?id=10579
Quanah Gibson-Mount quanah@openldap.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|RESOLVED |VERIFIED Resolution|TEST |FIXED
https://bugs.openldap.org/show_bug.cgi?id=10579
Ondřej Kuzník ondra@mistotebe.net changed:
What |Removed |Added ---------------------------------------------------------------------------- See Also| |https://bugs.openldap.org/s | |how_bug.cgi?id=10601