* lib/net/smtp.rb: Net::SMTP should close the SSL connection if the

connection verification fails.

git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/trunk@30294 b2dd03c8-39d4-4d8f-98ff-823fe69b080e
This commit is contained in:
tenderlove 2010-12-22 21:37:13 +00:00
Родитель 7a033184ae
Коммит 4a7f4d1f48
3 изменённых файлов: 109 добавлений и 2 удалений

Просмотреть файл

@ -1,3 +1,8 @@
Thu Dec 23 06:35:41 2010 Aaron Patterson <aaron@tenderlovemaking.com>
* lib/net/smtp.rb: Net::SMTP should close the SSL connection if the
connection verification fails.
Thu Dec 23 01:47:58 2010 Kazuhiro NISHIYAMA <zn@mbf.nifty.com>
* NEWS: remove #object_id. [ruby-dev:42840]

Просмотреть файл

@ -542,13 +542,17 @@ module Net
private
def tcp_socket(address, port)
TCPSocket.open address, port
end
def do_start(helo_domain, user, secret, authtype)
raise IOError, 'SMTP session already started' if @started
if user or secret
check_auth_method(authtype || DEFAULT_AUTH_TYPE)
check_auth_args user, secret
end
s = timeout(@open_timeout) { TCPSocket.open(@address, @port) }
s = timeout(@open_timeout) { tcp_socket(@address, @port) }
logging "Connection opened: #{@address}:#{@port}"
@socket = new_internet_message_io(tls? ? tlsconnect(s) : s)
check_response critical { recv_response() }
@ -573,15 +577,23 @@ module Net
end
end
def ssl_socket(socket, context)
OpenSSL::SSL::SSLSocket.new socket, context
end
def tlsconnect(s)
s = OpenSSL::SSL::SSLSocket.new(s, @ssl_context)
verified = false
s = ssl_socket(s, @ssl_context)
logging "TLS connection started"
s.sync_close = true
s.connect
if @ssl_context.verify_mode != OpenSSL::SSL::VERIFY_NONE
s.post_connection_check(@address)
end
verified = true
s
ensure
s.close unless verified
end
def new_internet_message_io(s)

Просмотреть файл

@ -0,0 +1,90 @@
require 'net/smtp'
require 'minitest/autorun'
module Net
class TestSSLSocket < MiniTest::Unit::TestCase
class MySMTP < SMTP
attr_accessor :fake_tcp, :fake_ssl
def tcp_socket address, port
fake_tcp
end
def ssl_socket socket, context
fake_ssl
end
end
class SSLSocket < StringIO
attr_accessor :sync_close, :connected, :closed
def initialize(*args)
@connected = false
@closed = true
super
end
def connect
self.connected = true
self.closed = false
end
def close
self.closed = true
end
def post_connection_check omg
end
end
def test_ssl_socket_close_on_post_connection_check_fail
tcp_socket = StringIO.new success_response
ssl_socket = SSLSocket.new.extend Module.new {
def post_connection_check omg
raise OpenSSL::SSL::SSLError, 'hostname was not match with the server certificate'
end
}
connection = MySMTP.new('localhost', 25)
connection.enable_starttls_auto
connection.fake_tcp = tcp_socket
connection.fake_ssl = ssl_socket
assert_raises(OpenSSL::SSL::SSLError) do
connection.start
end
assert_equal true, ssl_socket.closed
end
def test_ssl_socket_open_on_post_connection_check_success
tcp_socket = StringIO.new success_response
ssl_socket = SSLSocket.new success_response
connection = MySMTP.new('localhost', 25)
connection.enable_starttls_auto
connection.fake_tcp = tcp_socket
connection.fake_ssl = ssl_socket
connection.start
assert_equal false, ssl_socket.closed
end
def success_response
[
'220 smtp.example.com ESMTP Postfix',
"250-ubuntu-desktop",
"250-PIPELINING",
"250-SIZE 10240000",
"250-VRFY",
"250-ETRN",
"250-STARTTLS",
"250-ENHANCEDSTATUSCODES",
"250-8BITMIME",
"250 DSN",
"220 2.0.0 Ready to start TLS",
].join("\r\n") + "\r\n"
end
end
end