Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Avoid rooting X509Certificate2 in SslSessionCache #101120

Conversation

rzikm
Copy link
Member

@rzikm rzikm commented Apr 16, 2024

Fixes #101090.

Copy link
Contributor

Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones
See info in area-owners.md if you want to be subscribed.

…treamPal.Windows.cs

Co-authored-by: campersau <buchholz.bastian@googlemail.com>
@rzikm
Copy link
Member Author

rzikm commented Apr 16, 2024

CI Failures seem unrelated.

Copy link
Member

@wfurt wfurt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@rzikm
Copy link
Member Author

rzikm commented Apr 16, 2024

Test failuers are unrelated

@rzikm rzikm merged commit d30369a into dotnet:main Apr 16, 2024
81 of 87 checks passed
@rzikm
Copy link
Member Author

rzikm commented Apr 16, 2024

/backport to release/8.0-staging

@rzikm
Copy link
Member Author

rzikm commented Apr 16, 2024

/backport to release/6.0-staging

Copy link
Contributor

Started backporting to release/8.0-staging: https://github.com/dotnet/runtime/actions/runs/8712510692

Copy link
Contributor

Started backporting to release/6.0-staging: https://github.com/dotnet/runtime/actions/runs/8712513281

Copy link
Contributor

@rzikm backporting to release/6.0-staging failed, the patch most likely resulted in conflicts:

$ git am --3way --ignore-whitespace --keep-non-patch changes.patch

Applying: Avoid rooting X509Certificate2 in SslSessionCache
Using index info to reconstruct a base tree...
M	src/libraries/Common/src/Interop/Windows/SspiCli/SecuritySafeHandles.cs
M	src/libraries/System.Net.Security/src/System/Net/CertificateValidationPal.Windows.cs
M	src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.cs
Falling back to patching base and 3-way merge...
Auto-merging src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.cs
CONFLICT (content): Merge conflict in src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.cs
Auto-merging src/libraries/System.Net.Security/src/System/Net/CertificateValidationPal.Windows.cs
Auto-merging src/libraries/Common/src/Interop/Windows/SspiCli/SecuritySafeHandles.cs
CONFLICT (content): Merge conflict in src/libraries/Common/src/Interop/Windows/SspiCli/SecuritySafeHandles.cs
error: Failed to merge in the changes.
hint: Use 'git am --show-current-patch=diff' to see the failed patch
Patch failed at 0001 Avoid rooting X509Certificate2 in SslSessionCache
When you have resolved this problem, run "git am --continue".
If you prefer to skip this patch, run "git am --skip" instead.
To restore the original branch and stop patching, run "git am --abort".
Error: The process '/usr/bin/git' failed with exit code 128

Please backport manually!

Copy link
Contributor

@rzikm an error occurred while backporting to release/6.0-staging, please check the run log for details!

Error: git am failed, most likely due to a merge conflict.

rzikm added a commit to rzikm/dotnet-runtime that referenced this pull request Apr 17, 2024
…et#101120)

* Avoid rooting X509Certificate2 in SslSessionCache

* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.cs

Co-authored-by: campersau <buchholz.bastian@googlemail.com>

---------

Co-authored-by: campersau <buchholz.bastian@googlemail.com>
rzikm added a commit that referenced this pull request Apr 23, 2024
) (#101167)

* Avoid rooting X509Certificate2 in SslSessionCache

* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.cs



---------

Co-authored-by: campersau <buchholz.bastian@googlemail.com>
matouskozak pushed a commit to matouskozak/runtime that referenced this pull request Apr 30, 2024
* Avoid rooting X509Certificate2 in SslSessionCache

* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.cs

Co-authored-by: campersau <buchholz.bastian@googlemail.com>

---------

Co-authored-by: campersau <buchholz.bastian@googlemail.com>
@karelz karelz added this to the 9.0.0 milestone May 14, 2024
Ruihan-Yin pushed a commit to Ruihan-Yin/runtime that referenced this pull request May 30, 2024
* Avoid rooting X509Certificate2 in SslSessionCache

* Update src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.cs

Co-authored-by: campersau <buchholz.bastian@googlemail.com>

---------

Co-authored-by: campersau <buchholz.bastian@googlemail.com>
@github-actions github-actions bot locked and limited conversation to collaborators Jun 14, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Client certs with HttpClient on Windows prevents X509Certificate2 cleanup
4 participants