Stop old openssl extensions clashing with OpenSSL 3, add missing 2.7/3.0/3.1/3.2.0 - #14
Merged
Merged
Conversation
Ruby 1.8-2.3's openssl extension defines and exports stand-ins for functions its OpenSSL lacks (X509_STORE_set_ex_data, SSL_SESSION_cmp), and 1.8's digest/sha2 exports SHA256_Transform. With the pg gem required before openssl, the system libcrypto.so.3 is already loaded and those calls bind to OpenSSL 3's functions, which segfault on 1.x structs (seen on 1.8.7, 1.9.3, 2.0.0, 2.1.10). Link these extensions with a version script that exports only Init_*, and have check_openssl_hidden! fail if they export anything else.
Hatchbox's S3 bucket carries these, so the fork needs them before it replaces S3. 3.2.0 was dropped upstream for a header path bug; it now builds and compiles native gems (pg from source) in both variants.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
After #12, Ruby 1.8.7, 1.9.3, 2.0.0 and 2.1.10 still segfault when
pgis required beforeopenssl(Bundler's usual order):Their
ext/openssldefines and exports its ownX509_STORE_get_ex_data/X509_STORE_set_ex_data(andSSL_SESSION_cmp), and 1.8'sdigest/sha2exportsSHA256_Transform. With libpq'slibcrypto.so.3already loaded, calls to them bind to OpenSSL 3's real functions.--exclude-libshides the bundled static OpenSSL, but not symbols the extension itself defines.Fix
init_only_exportssource patch (series 1.8–3.1):opensslanddigest/{md5,sha1,sha2,rmd160}link with a version script exporting onlyInit_*. The flag goes into those extensions' Makefiles only, not rbconfig, so native gems are unaffected.check_openssl_hidden!now fails if those extensions export anything butInit_*(for patched series).Testing
Built locally with
bin/package-linux(arm64): 1.8.7-p374, 2.1.10, 2.3.8, 3.1.7, 2.7.0, 3.0.0, 3.2.0 (both variants). All pass the package's own checks. Then on Ubuntu 24.04, each installed into~/.asdf/installs/ruby/<v>,pgbuilt from source against system libpq 16, in both require orders: pg to a TLS Postgres 17 (TLSv1.3) andNet::HTTPSto rubygems.org with peer verification. All pass (1.8.7 needs an explicitca_file, as 1.8's net/http always has).After merge
New versions release via release-new. Existing old-series versions need a dispatch of Release New Versions with
only:1.8.7-p374 1.9.3-p551 2.0.0-p648 2.1.10 2.2.10 2.3.8 2.4.10 2.5.9 2.6.10 2.7.8 3.0.7 3.1.7