summaryrefslogtreecommitdiff
path: root/lib/libtls/tls.c
diff options
context:
space:
mode:
authorJoel Sing <jsing@cvs.openbsd.org>2015-04-15 16:08:44 +0000
committerJoel Sing <jsing@cvs.openbsd.org>2015-04-15 16:08:44 +0000
commitd350fab25416ca3123d7c4e42c1b2a54713cf8bf (patch)
tree8cf018dd68cabea3371ce6094a9530e19e519e36 /lib/libtls/tls.c
parentf5373ca74d503db5ee99c3648fad956832b038b7 (diff)
Treat SSL_ERROR_ZERO_RETURN as a success, rather than a failure. Also
ensure that outlen is set to zero so that tls_read() has read(2) like semantics for EOF. Spotted by doug@
Diffstat (limited to 'lib/libtls/tls.c')
-rw-r--r--lib/libtls/tls.c11
1 files changed, 6 insertions, 5 deletions
diff --git a/lib/libtls/tls.c b/lib/libtls/tls.c
index 002cccda5f6..f4bd108daca 100644
--- a/lib/libtls/tls.c
+++ b/lib/libtls/tls.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: tls.c,v 1.10 2015/04/15 16:05:23 jsing Exp $ */
+/* $OpenBSD: tls.c,v 1.11 2015/04/15 16:08:43 jsing Exp $ */
/*
* Copyright (c) 2014 Joel Sing <jsing@openbsd.org>
*
@@ -246,11 +246,8 @@ tls_ssl_error(struct tls *ctx, SSL *ssl_conn, int ssl_ret, const char *prefix)
ssl_err = SSL_get_error(ssl_conn, ssl_ret);
switch (ssl_err) {
case SSL_ERROR_NONE:
- return (0);
-
case SSL_ERROR_ZERO_RETURN:
- tls_set_error(ctx, "%s failed: TLS connection closed", prefix);
- return (-1);
+ return (0);
case SSL_ERROR_WANT_READ:
return (TLS_READ_AGAIN);
@@ -301,6 +298,8 @@ tls_read(struct tls *ctx, void *buf, size_t buflen, size_t *outlen)
return (0);
}
+ *outlen = 0;
+
return tls_ssl_error(ctx, ctx->ssl_conn, ssl_ret, "read");
}
@@ -320,6 +319,8 @@ tls_write(struct tls *ctx, const void *buf, size_t buflen, size_t *outlen)
return (0);
}
+ *outlen = 0;
+
return tls_ssl_error(ctx, ctx->ssl_conn, ssl_ret, "write");
}