Skip to content

Commit 0f0892e

Browse files
styfleaduh95
authored andcommitted
tls: initialize session and SNI before connecting
A synchronous custom lookup can abort the socket before tls.connect() applies the session and SNI, leaving the TLS handle unavailable. Initialize both before starting the connection so the original socket error is emitted normally. Assisted-by: Codex Signed-off-by: Steven <steven@ceriously.com> PR-URL: #65624 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com> Reviewed-By: Tim Perry <pimterry@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com>
1 parent 7202aa5 commit 0f0892e

2 files changed

Lines changed: 28 additions & 7 deletions

File tree

‎lib/internal/tls/wrap.js‎

Lines changed: 6 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1912,6 +1912,12 @@ exports.connect = function connect(...args) {
19121912
if (cb)
19131913
tlssock.once('secureConnect', cb);
19141914

1915+
if (options.session)
1916+
tlssock.setSession(options.session);
1917+
1918+
if (options.servername)
1919+
tlssock.setServername(options.servername);
1920+
19151921
if (!options.socket) {
19161922
// If user provided the socket, it's their responsibility to manage its
19171923
// connectivity. If we created one internally, we connect it.
@@ -1924,13 +1930,6 @@ exports.connect = function connect(...args) {
19241930

19251931
tlssock._releaseControl();
19261932

1927-
if (options.session)
1928-
tlssock.setSession(options.session);
1929-
1930-
if (options.servername) {
1931-
tlssock.setServername(options.servername);
1932-
}
1933-
19341933
if (options.socket)
19351934
tlssock._start();
19361935

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
'use strict';
2+
3+
const common = require('../common');
4+
if (!common.hasCrypto)
5+
common.skip('missing crypto');
6+
7+
const tls = require('node:tls');
8+
9+
// Verify that a synchronous lookup cannot interrupt TLS socket initialization.
10+
const controller = new AbortController();
11+
const socket = tls.connect({
12+
host: 'example.com',
13+
servername: 'example.com',
14+
port: 443,
15+
signal: controller.signal,
16+
lookup(_hostname, _options, callback) {
17+
callback(null, [{ address: '2001:db8::1', family: 6 }]);
18+
controller.abort();
19+
},
20+
});
21+
22+
socket.on('error', common.mustCall());

0 commit comments

Comments
 (0)