git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: SSL_CTX leak?

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 28, 2014, 17:23 UTC
Message-ID
<xmqqr45mb5k7.fsf@gitster.dls.corp.google.com>
In-Reply-To
<20140327231156.GE32434@sigill.intra.peff.net>
Jeff King <peff@peff.net> writes:
Show 10 quoted lines
> On Thu, Mar 27, 2014 at 10:37:07AM -0300, Thiago Farina wrote:
>
>> Do we leak the context we allocate in imap-send.c:280 intentionally?
>
> It was never mentioned on the mailing list when the patches came
> originally, so I suspect is just an omission.
>
> Presumably the SSL_CTX is needed by the connection that survives after
> the function, but my reading of SSL_CTX_free implies that the data is
> reference-counted, and the library would presumably handle it fine.

Yes, I was reading the SSL_new() yesterday and found out that at least in a recent code it increments the reference count on the ctx it is fed. So it would be the right thing to decrement the refcount in the caller that created the context and used to call SSL_new(), but I fully agree with the analysis below (with s/a huge/any/):

> OTOH, it is probably not causing a huge problem (since we wouldn't end
> up freeing it until the end of the program anyway), so I would not
> personally devote to many brain cycles to figuring out how OpenSSL
> handles it.
Heh.  So you are saying that I wasted 30 minutes yesterday? ;-)
Thanks.
Previous: Jeff King
Message 3 of 3 in “SSL_CTX leak?”
  1. Thiago FarinaMar 27, 2014
  2. Jeff KingMar 27, 2014
  3. Junio C HamanoMar 28, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.