Repository navigation
Format net_ssl_io_cert_validation in TlsSession reject path - #135351
Merged
Merged
Conversation
TlsSession.SetRemoteCertificateValidationResult built its
AuthenticationException from SR.net_ssl_io_cert_validation without
SR.Format, so the message ended in a literal "{0}". Format it with the
caller's SslPolicyErrors verdict, as SslStream does.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Azure Pipelines: Successfully started running 4 pipeline(s). 12 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
|
Tagging subscribers to this area: @dotnet/ncl, @bartonjs, @vcsjones |
wfurt
approved these changes
Oct 7, 2026
wfurt
left a comment
Member
There was a problem hiding this comment.
LGTM. Thanks for the contribution
MihaZupan
approved these changes
Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TlsSession.SetRemoteCertificateValidationResultcreated itsAuthenticationExceptionfromSR.net_ssl_io_cert_validationwithoutSR.Formatat two sites (the_isHandshakeCompletebranch and the_resumeAfterCertValidationbranch), so a rejection that faulted the session there produced the message "The remote certificate is invalid according to the validation procedure: {0}".This change formats the resource with the caller's
SslPolicyErrorsat both sites, asSslStreamdoes:SslStream.IO.cs:710
ServerSession_ExternalValidation_RejectsClientCert_ServerFaultsPostHoc(TLS 1.2 and TLS 1.3 rows) now keeps the server-sideAuthenticationExceptionand asserts that its message containsRemoteCertificateChainErrorsand does not contain{0}. Both rows fail on the old code withAssert.Contains() Failureand pass with the fix.On Linux with OpenSSL 3.0.13 both rows reach the first site (the
_isHandshakeCompletebranch); the second site (the_resumeAfterCertValidationbranch) is not reached there.On Windows 11 x64 both rows also fail on the old code and pass with the fix; which site they reach there was not checked. Not run on macOS.
The System.Net.Security functional tests passed on Linux x64 with the change (OuterLoop tests not run). On Windows 11 x64 they passed except
SslStreamTlsResumeTests.DifferentEncryptionPolicy_NoResume, which failed once in the full run (Assert.Equal() Failure, expectedTrue, actualFalse) and passed in three separate runs of that test alone.Resolves #135349
Note
AI-generated, written at my direction and reviewed by me before posting.
Source read at dotnet/runtime 6f1d933. Tests ran on Ubuntu 24.04.4 LTS x64 with OpenSSL 3.0.13, against a
./build.sh clr+libs -rc Releasebuild of that commit plus this change, withdotnet build src/libraries/System.Net.Security/tests/FunctionalTests /t:Test. The old-code run put backTlsSession.csfrom that commit and rebuiltsrc/libraries/System.Net.Security/srcbefore running the test.Windows: Windows 11 Pro for Workstations x64 (10.0.26300), against a
build.cmd clr+libs -rc checkedbuild of dotnet/runtime d148189 plus this change (TlsSession.csandTlsSessionTests.csare the same blobs there as at 6f1d933), withdotnet.cmd build /t:Testinsrc/libraries/System.Net.Security/tests/FunctionalTests; the old-code run put backTlsSession.csfrom d148189 and rebuiltsrc/libraries/System.Net.Security/src.