doWrite()'s retry/buffer state was held in function-local static
variables, shared across every SecureSocket instance in the process
rather than per connection. Move it to instance members, and simplify
secureRead()/secureWrite()'s retry counters (also static, but not
load-bearing across calls) to plain locals.
pollSocket() caches a socket's writability and skips waiting once it's
known writable, relying on writeSocket() to clear the cache on
WSAEWOULDBLOCK. SecureSocket writes via SSL_write(), bypassing
writeSocket() entirely, so the cache never clears and the multiplexer
spins at a zero timeout instead of blocking whenever TLS hits
backpressure.
Add IArchNetwork::resetPollWriteOnSocket() and call it from
checkResult()'s SSL_ERROR_WANT_WRITE case, mirroring writeSocket()'s
existing WSAEWOULDBLOCK handling.
It will fix the following warning:
In member function 'int SecureSocket::secureConnect(int)':
/build/deskflow.work/src/lib/net/SecureSocket.cpp:479:16: warning: 'int SSL_set1_host(SSL*, const char*)' is deprecated: Since OpenSSL 4.0 [
-Wdeprecated-declarations]
479 | SSL_set1_host(m_ssl->m_ssl, name.c_str());
| ~~~~~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~~~~
In file included from /build/deskflow.work/src/lib/net/SslLogger.h:8,
from /build/deskflow.work/src/lib/net/SecureSocket.cpp:20:
/usr/include/openssl/ssl.h:1922:34: note: declared here
1922 | OSSL_DEPRECATEDIN_4_0 __owur int SSL_set1_host(SSL *s, const char *host);
| ^~~~~~~~~~~~~
NOTE: It seems that SSL_set1_host setup params for hostname verification, but
it will not be used correctly afterward (See
SSL_CTX_set_cert_verify_callback
in SecureSocket::initContext). This implicit behavior cause misleading
and harmful.
Signed-off-by: Kentaro Hayashi <kenhys@xdump.org>
This fix addresses a busy-loop and stalled connection issue during the TLS
handshake. Previously, SecureSocket incorrectly managed its readiness flags
during negotiation, often polling for 'writability' when OpenSSL was actually
waiting for more 'read' data (or vice versa).
- Explicitly maps SSL_ERROR_WANT_READ and SSL_ERROR_WANT_WRITE to
socket multiplexer events.
- Resets readiness flags before each handshake attempt to ensure the
multiplexer receives the most accurate requirements from OpenSSL.
- Restores readability/writability flags upon a successful handshake
to allow subsequent application-layer protocol exchange.
- Removes inefficient busy-wait sleeps that were masking the loop
and slowing down handshakes.