소스 검색

Fix mbedTLS close_notify mid-response handling

The mbedTLS backend's read() returned -1 with err.code = PeerClosed when
the peer sent close_notify, while OpenSSL and wolfSSL surface it as 0
(clean EOF). The result was that an SSL response without Content-Length
or chunked Transfer-Encoding — terminated by connection close — was
reported as "Failed to read connection" on mbedTLS, even though the
body had been fully delivered.

Translate PeerClosed into a return value of 0 to match the other
backends. This re-enables SSLTest.ResponseBodyTerminatedByConnectionClose
on mbedTLS.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
yhirose 5 달 전
부모
커밋
3d56762d5c
2개의 변경된 파일과 3개의 추가작업 그리고 6개의 파일을 삭제
  1. 3 0
      httplib.h
  2. 0 6
      test/test.cc

+ 3 - 0
httplib.h

@@ -17956,6 +17956,9 @@ inline ssize_t read(session_t session, void *buf, size_t len, TlsError &err) {
   err.code = impl::map_mbedtls_error(ret, err.sys_errno);
   err.backend_code = static_cast<uint64_t>(-ret);
   impl::mbedtls_last_error() = ret;
+  // mbedTLS signals a clean close_notify via a negative error code rather
+  // than 0; surface it as a clean EOF the way OpenSSL/wolfSSL do.
+  if (err.code == ErrorCode::PeerClosed) { return 0; }
   return -1;
 }
 

+ 0 - 6
test/test.cc

@@ -14626,12 +14626,6 @@ TEST_F(SSLOpenStreamTest, PostChunked) {
 // SSL peer sends a close_notify after the body, the client must treat it as a
 // clean EOF and return a successful response rather than an error.
 TEST(SSLTest, ResponseBodyTerminatedByConnectionClose) {
-#ifdef CPPHTTPLIB_MBEDTLS_SUPPORT
-  // TODO: mbedTLS reports a clean close_notify mid-response as a read error.
-  // Treat the EOF as a successful body terminator the way the OpenSSL/wolfSSL
-  // backends already do.
-  GTEST_SKIP() << "mbedTLS backend treats close_notify mid-response as error";
-#endif
   SSLServer svr(SERVER_CERT_FILE, SERVER_PRIVATE_KEY_FILE);
   ASSERT_TRUE(svr.is_valid());