From 073671890a6b700c695821b4bcc806293748c8a8 Mon Sep 17 00:00:00 2001 From: Daniel Gustafsson Date: Fri, 2 Oct 2026 09:33:08 +0200 Subject: [PATCH v5 5/5] Delay creation of SSL_CTX structure to allow cleanup Avoid initializing the OpenSSL SSL_CTX structure for a new host until it has been checked for errors. The cleanup can only see hosts which were successfully added so the previous coding would leak the SSL_CTX on failed reloads. Author: Zsolt Parragi --- src/backend/libpq/be-secure-openssl.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/src/backend/libpq/be-secure-openssl.c b/src/backend/libpq/be-secure-openssl.c index 8eac0199686..c7c8a9d5d1d 100644 --- a/src/backend/libpq/be-secure-openssl.c +++ b/src/backend/libpq/be-secure-openssl.c @@ -257,9 +257,6 @@ be_tls_init(bool isServerStart) { HostsLine *host = lfirst(line); - if (!init_host_context(host, isServerStart, &hasWarned)) - goto error; - /* * The hostname in the config will be set to NULL for the default * host as well as in configs used for non-SNI connections. Lists @@ -329,6 +326,14 @@ be_tls_init(bool isServerStart) */ new_hosts->sni = lappend(new_hosts->sni, host); } + + /* + * Create the SSL context only once the entry has been accepted + * and added to new_hosts, as the cleanup callback can only free + * contexts of entries it can reach from there. + */ + if (!init_host_context(host, isServerStart, &hasWarned)) + goto error; } } -- 2.39.3 (Apple Git-146)