pgsql: Clear SSL_hosts when destroying TLS

From: Daniel Gustafsson <dgustafsson(at)postgresql(dot)org>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Clear SSL_hosts when destroying TLS
Date: 2026-10-06 11:52:32
Message-ID: E1xE3ii-00000000Y1Q-1SYY@gemulon.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Clear SSL_hosts when destroying TLS

The loaded SSL_CTX objects were cleared on SSL initialization but not
when destroying the TLS objects via be_tls_destroy(). This would not
leak the contexts, but consume memory for no reason.

Reported-by: Jacob Champion <jacob(dot)champion(at)enterprisedb(dot)com>
Reviewed-by: Zsolt Parragi <zsolt(dot)parragi(at)percona(dot)com>
Reviewed-by: Rui Zhao <zhaorui126(at)gmail(dot)com>
Discussion: https://postgr.es/m/CAOYmi+mAtEn4wN3xx=r4TaY5AHy9_q9XncM8YQLhofE3op0SvA@mail.gmail.com
Backpatch-through: 19

Branch
------
REL_19_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/d45dc682e81b2ff5a9f57129b3fa25fb2de5f195

Modified Files
--------------
src/backend/libpq/be-secure-openssl.c | 7 +++++++
1 file changed, 7 insertions(+)

Browse pgsql-committers by date

  From Date Subject
Next Message Nathan Bossart 2026-10-06 14:05:53 pgsql: Fix COPY FROM ... WHERE for negated operators.
Previous Message Daniel Gustafsson 2026-10-06 11:52:22 pgsql: Delay creation of SSL_CTX structure to allow cleanup