You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Reject or gracefully degrade against local wolfSSL builds missing features the extension assumed were present:
Require OPENSSL_ALL and match options.h macro names exactly instead of substring matching (F-13426)
Reject builds with NO_KEEP_PEER_CERT (F-11777)
Reject builds with NO_FILESYSTEM (F-12664)
Make CRL support optional, detecting HAVE_CRL and raising NotImplementedError from enable_crl()/load_crl_file() when absent (F-12663)
Free WOLFSSL_METHOD via a small XFREE helper instead of wolfSSL_Free, which isn't binary-compatible with WOLFSSL_STATIC_MEMORY/WOLFSSL_DEBUG_MEMORY builds (F-12662)
Tie the SSLSocket session lifetime to its Python object via ffi.gc, so close()/shutdown()/unwrap() no longer free the session while another thread is using it (F-11784)
Build bundled wolfSSL with -fPIC (not -fpic) on every Linux platform so linking the static lib into the shared extension works on non-x86 architectures like aarch64; add arm64 Linux to CI (F-10706)
Update expired test certificates (ca-cert.pem, server-cert.pem, client-cert.pem, crl.pem) from wolfSSL
ca-cert.pem, server-cert.pem and client-cert.pem expired on 2026-09-08.
Copy the renewed files from wolfSSL (92e76d46). The keys are unchanged
but the subject email is now facts@wolfssl.com, so crl.pem is replaced
with certs/crl/crl.pem from the same commit, which the new CA signs.
The static library is linked into the shared CFFI extension. Only x86
Linux got a PIC flag, so linking failed on other architectures such as
aarch64. Use -fPIC rather than -fpic, which has GOT size limits on some
architectures.
Run CI on arm64 Linux too. Use the checkout and setup-python versions
wolfcrypt-py already runs; the v3 actions predate the arm64 runners.
wolfSSL_ctrl(), SSL_set_mode() and SSL_OP_NO_TICKET are always bound
but only exist when wolfSSL is built with OPENSSL_ALL. Local builds
without it passed detection and then failed to compile. Detection also
used substring matching, so OPENSSL_EXTRA_X509_SMALL was taken for
OPENSSL_EXTRA. Match options.h macro names exactly and require
--enable-opensslall.
wolfSSL_get_peer_certificate() and wolfSSL_X509_get_subjectCN() are
always bound but only exist with KEEP_PEER_CERT. settings.h defines it
for OPENSSL_EXTRA builds unless NO_KEEP_PEER_CERT is set, so such local
builds passed detection and then failed to import. Reject them unless
KEEP_PEER_CERT is also defined.
The file based cert/key loading APIs (wolfSSL_CTX_use_PrivateKey_file(),
wolfSSL_CTX_load_verify_locations(),
wolfSSL_CTX_use_certificate_chain_file() and their OpenSSL names) are
always bound but only exist without NO_FILESYSTEM. Such local builds
passed detection and then failed to import. The Python API loads
certificates and keys only from files, so reject these builds.
wolfSSL_EnableCRL() and wolfSSL_LoadCRLFile() were always bound but only
exist with HAVE_CRL, which wolfSSL leaves off by default. Local builds
without it passed detection and then failed to import. Detect HAVE_CRL,
bind the CRL functions only when it is set, and make
SSLSocket.enable_crl() and load_crl_file() raise NotImplementedError
otherwise. The bundled build keeps --enable-crl. The client example test
passes -C when CRL support is absent.
wolfSSL_Free() takes extra arguments when wolfSSL is built with
WOLFSSL_STATIC_MEMORY or WOLFSSL_DEBUG_MEMORY, so the extension did not
compile against such a local build. A small C helper now frees the
method with XFREE, which follows the configured allocator. The private
wolfssl._ffi.lib.wolfSSL_Free binding is removed.
close(), shutdown() and unwrap() no longer free the WOLFSSL session
while another thread is inside a native call on it. The session is
wrapped with ffi.gc and freed when its last reference goes. Closing
drops the socket's reference, and each method keeps a local reference
for all its native calls, so a call running in another thread keeps the
session alive.
use_sni(), enable_crl(), load_crl_file() and add_peer() now go through
_check_closed() and raise ValueError instead of passing a NULL session
to wolfSSL. The close-race test now fails on any session call after
close, including ones with a NULL pointer.
Guard native_object access in __del__ after failed initialization
wolfssl/__init__.py:522
__del__() can run after SSLSocket.__init__() raises before native_object is assigned (for example during context setup or getpeername()). This unconditional attribute access then raises AttributeError during finalization, producing an ignored destructor exception instead of safely doing nothing; retain a getattr guard here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
OPENSSL_ALLand match options.h macro names exactly instead of substring matching (F-13426)NO_KEEP_PEER_CERT(F-11777)NO_FILESYSTEM(F-12664)HAVE_CRLand raisingNotImplementedErrorfromenable_crl()/load_crl_file()when absent (F-12663)WOLFSSL_METHODvia a smallXFREEhelper instead ofwolfSSL_Free, which isn't binary-compatible withWOLFSSL_STATIC_MEMORY/WOLFSSL_DEBUG_MEMORYbuilds (F-12662)SSLSocketsession lifetime to its Python object viaffi.gc, soclose()/shutdown()/unwrap()no longer free the session while another thread is using it (F-11784)-fPIC(not-fpic) on every Linux platform so linking the static lib into the shared extension works on non-x86 architectures like aarch64; add arm64 Linux to CI (F-10706)