Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Fix SSL ZeroReturn
  • Loading branch information
youknowone committed Jan 23, 2026
commit c67451ab067f2a8bdf5e2ed88003afb77891ed85
1 change: 0 additions & 1 deletion Lib/test/test_ssl.py
Original file line number Diff line number Diff line change
Expand Up @@ -3525,7 +3525,6 @@ def test_starttls(self):
else:
s.close()

@unittest.expectedFailureIfWindows("TODO: RUSTPYTHON")
def test_socketserver(self):
"""Using socketserver to create and manage SSL connections."""
server = make_https_server(self, certfile=SIGNED_CERTFILE)
Expand Down
19 changes: 16 additions & 3 deletions crates/stdlib/src/ssl.rs
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@ mod _ssl {
// Import error types used in this module (others are exposed via pymodule(with(...)))
use super::error::{
PySSLError, create_ssl_eof_error, create_ssl_want_read_error, create_ssl_want_write_error,
create_ssl_zero_return_error,
};
use alloc::sync::Arc;
use core::{
Expand Down Expand Up @@ -3593,7 +3594,7 @@ mod _ssl {
let mut conn_guard = self.connection.lock();
let conn = match conn_guard.as_mut() {
Some(conn) => conn,
None => return return_data(vec![], &buffer, vm),
None => return Err(create_ssl_zero_return_error(vm).upcast()),
};
use std::io::BufRead;
let mut reader = conn.reader();
Expand All @@ -3613,8 +3614,20 @@ mod _ssl {
return return_data(buf, &buffer, vm);
}
}
// Clean closure with close_notify - return empty data
return_data(vec![], &buffer, vm)
// Clean closure with close_notify
// CPython behavior depends on whether we've sent our close_notify:
// - If we've already sent close_notify (unwrap was called): raise SSLZeroReturnError
// - If we haven't sent close_notify yet: return empty bytes
let our_shutdown_state = *self.shutdown_state.lock();
if our_shutdown_state == ShutdownState::SentCloseNotify
|| our_shutdown_state == ShutdownState::Completed
{
// We already sent close_notify, now receiving peer's → SSLZeroReturnError
Err(create_ssl_zero_return_error(vm).upcast())
} else {
// We haven't sent close_notify yet → return empty bytes
return_data(vec![], &buffer, vm)
}
}
Err(crate::ssl::compat::SslError::WantRead) => {
// Non-blocking mode: would block
Expand Down
5 changes: 5 additions & 0 deletions crates/stdlib/src/ssl/compat.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1552,6 +1552,11 @@ pub(super) fn ssl_read(

// Try to read plaintext from rustls buffer
if let Some(n) = try_read_plaintext(conn, buf)? {
if n == 0 {
// EOF from TLS - close_notify received
// Return ZeroReturn so Python raises SSLZeroReturnError
return Err(SslError::ZeroReturn);
}
return Ok(n);
}

Expand Down