Skip to content

Ensure that a resumed session properly handles client auth. Clear session ticket resumption state in wolfSSL_clear. - #11600

Open
kareem-wolfssl wants to merge 8 commits into
wolfSSL:masterfrom
kareem-wolfssl:zd22516
Open

kareem-wolfssl wants to merge 8 commits into
wolfSSL:masterfrom
kareem-wolfssl:zd22516

Conversation

@kareem-wolfssl

Copy link
Copy Markdown
Contributor

Description

Partially fixes zd#22516

Testing

Built in tests, provided reproducers, added tests

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

MemBrowse Memory Report

gcc-arm-cortex-m3

  • FLASH: .text +104 B (+0.1%, 128,029 B / 262,144 B, total: 49% used)

gcc-arm-cortex-m4

  • FLASH: .text +192 B (+0.1%, 206,828 B / 262,144 B, total: 79% used)

gcc-arm-cortex-m4-dtls13

  • FLASH: .text +192 B (+0.1%, 191,172 B / 1,048,576 B, total: 18% used)

gcc-arm-cortex-m4-openssl-compat

  • FLASH: .text +384 B (+0.0%, 789,404 B / 1,048,576 B, total: 75% used)
  • RAM: .bss +48 B (+0.0%, 138,556 B / 262,144 B, total: 53% used)

gcc-arm-cortex-m4-pq

  • FLASH: .text +320 B (+0.1%, 307,248 B / 1,048,576 B, total: 29% used)

gcc-arm-cortex-m4-rsa-only

  • FLASH: .text +320 B (+0.1%, 337,456 B / 1,048,576 B, total: 32% used)

gcc-arm-cortex-m4-tls12

  • FLASH: .text +64 B (+0.0%, 128,765 B / 262,144 B, total: 49% used)

gcc-arm-cortex-m4-tls13

  • FLASH: .text +256 B (+0.1%, 246,174 B / 262,144 B, total: 94% used)

gcc-arm-cortex-m7

  • FLASH: .text +192 B (+0.1%, 206,828 B / 262,144 B, total: 79% used)

gcc-arm-cortex-m7-pq

  • FLASH: .text +256 B (+0.1%, 308,144 B / 1,048,576 B, total: 29% used)

gcc-arm-cortex-m7-tls13

  • FLASH: .text +320 B (+0.1%, 246,238 B / 262,144 B, total: 94% used)

linuxkm-standard

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The changes introduce an optional-build compilation failure, a callback-backed authentication bypass, and an unversioned persisted-cache layout change.

Review effort: Balanced
Findings: 2 High severity · 1 Medium severity · 1 Low severity

Open (4)
What changed in this PR

Adds client-authentication awareness to resumed sessions and clears stale ticket state during wolfSSL_clear().

Changes:

  • Persists client-auth status in sessions and tickets.
  • Rejects resumptions that cannot satisfy mandatory client authentication.
  • Adds TLS 1.2 resumption and reset tests.
File Description
wolfssl/​internal.h Adds ticket flags and session authentication state.
src/​internal.c Enforces client authentication during TLS 1.2 resumption.
src/​tls13.c Enforces authentication for TLS 1.3 ticket PSKs.
src/​ssl.c Clears stale ticket and alternate-session state.
src/​ssl_sess.c Serializes and populates authentication state.
tests/​api/​test_tls.c Adds TLS 1.2 resumption and reuse tests.
tests/​api/​test_tls.h Registers new TLS tests.
tests/​api.c Tests session serialization compatibility.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/internal.c Outdated
Comment thread src/internal.c Outdated
Comment thread wolfssl/internal.h Outdated
Comment thread src/tls13.c Outdated

@julek-wolfssl julek-wolfssl left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It looks correct but the comments are getting too verbose. Cut them down.

@kareem-wolfssl
kareem-wolfssl force-pushed the zd22516 branch 2 times, most recently from 54a86f2 to 3d38cef Compare September 30, 2026 21:03
Thanks to ByteRay Ltd for the report.
Also clear peerAuthOk in wolfSSL_Clear
Bump up WOLFSSL_CACHE_VERSION
Add TLS 1.3 tests
Add TLS 1.2 test for clearing peerAuthOk
…hecks mutual auth as well.

Reset more fields in wolfSSL_Clear to ensure a full reset.
Add a test to ensure wolfSSL_Clear fully clears after a connection.
Add a test for resuming in TLS 1.2 with mutual auth, and a test for resuming with PHA in TLS 1.3.
Minimize comments.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants