From 7f4a581fd048b955a7a62ee30bc172613bf92500 Mon Sep 17 00:00:00 2001 From: Daniel Gustafsson Date: Fri, 2 Oct 2026 09:29:12 +0200 Subject: [PATCH v5 4/5] Copy SSL GUCs into the hosts context When the SSL configuration from postgresql.conf is used, the default host entry stored pointers to the relevant GUC variables. These pointers are not guaranteed to survive a failed configuration reload so copy the values into the hosts memory context. Author: Zsolt Parragi --- src/backend/libpq/be-secure-openssl.c | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/src/backend/libpq/be-secure-openssl.c b/src/backend/libpq/be-secure-openssl.c index b9cac88ba55..8eac0199686 100644 --- a/src/backend/libpq/be-secure-openssl.c +++ b/src/backend/libpq/be-secure-openssl.c @@ -346,10 +346,14 @@ be_tls_init(bool isServerStart) Assert(ssl_sni == false); #endif - pgconf->ssl_cert = ssl_cert_file; - pgconf->ssl_key = ssl_key_file; - pgconf->ssl_ca = ssl_ca_file; - pgconf->ssl_passphrase_cmd = ssl_passphrase_command; + /* + * Copy the configuration from the GUC variables since they aren't + * guaranteed to survive a failed reload. + */ + pgconf->ssl_cert = pstrdup(ssl_cert_file); + pgconf->ssl_key = pstrdup(ssl_key_file); + pgconf->ssl_ca = pstrdup(ssl_ca_file); + pgconf->ssl_passphrase_cmd = pstrdup(ssl_passphrase_command); pgconf->ssl_passphrase_reload = ssl_passphrase_command_supports_reload; if (!init_host_context(pgconf, isServerStart, &hasWarned)) -- 2.39.3 (Apple Git-146)