From 4e4f7b9fcc9ad0b023b6e698e978882d022b94c4 Mon Sep 17 00:00:00 2001 From: Tom Lane Date: Fri, 30 Sep 2022 10:26:47 -0400 Subject: [PATCH] Adjust PQsslAttributeNames() to match PQsslAttribute(). Currently, PQsslAttributeNames() returns the same list of attribute names regardless of its conn parameter. This patch changes it to have behavior parallel to what 80a05679d installed for PQsslAttribute: you get OpenSSL's attributes if conn is NULL or is an SSL-encrypted connection, or an empty list if conn is a non-encrypted connection. The point of this is to have sensible connection-dependent behavior in case we ever support multiple SSL libraries. The behavior for NULL can be defined as "the attributes for the default SSL library", parallel to what PQsslAttribute(NULL, "library") does. Since this is mostly just future-proofing, no back-patch. Discussion: https://postgr.es/m/17625-fc47c78b7d71b534@postgresql.org --- doc/src/sgml/libpq.sgml | 12 +++++++++++- src/interfaces/libpq/fe-secure-openssl.c | 15 +++++++++++++-- 2 files changed, 24 insertions(+), 3 deletions(-) diff --git a/doc/src/sgml/libpq.sgml b/doc/src/sgml/libpq.sgml index 026b0ec46b..3c9bd3d673 100644 --- a/doc/src/sgml/libpq.sgml +++ b/doc/src/sgml/libpq.sgml @@ -2590,12 +2590,22 @@ const char *PQsslAttribute(const PGconn *conn, const char *attribute_name); PQsslAttributeNamesPQsslAttributeNames - Returns an array of SSL attribute names available. + Returns an array of SSL attribute names that can be used + in PQsslAttribute(). The array is terminated by a NULL pointer. const char * const * PQsslAttributeNames(const PGconn *conn); + + + If conn is NULL, the attributes available for the + default SSL library are returned, or an empty list + if libpq was compiled without any SSL + support. If conn is not NULL, the attributes + available for the SSL library in use for the connection are returned, + or an empty list if the connection is not encrypted. + diff --git a/src/interfaces/libpq/fe-secure-openssl.c b/src/interfaces/libpq/fe-secure-openssl.c index 74b5c5987a..b42a908733 100644 --- a/src/interfaces/libpq/fe-secure-openssl.c +++ b/src/interfaces/libpq/fe-secure-openssl.c @@ -1730,7 +1730,7 @@ PQsslStruct(PGconn *conn, const char *struct_name) const char *const * PQsslAttributeNames(PGconn *conn) { - static const char *const result[] = { + static const char *const openssl_attrs[] = { "library", "key_bits", "cipher", @@ -1738,8 +1738,19 @@ PQsslAttributeNames(PGconn *conn) "protocol", NULL }; + static const char *const empty_attrs[] = {NULL}; - return result; + if (!conn) + { + /* Return attributes of default SSL library */ + return openssl_attrs; + } + + /* No attrs for unencrypted connection */ + if (conn->ssl == NULL) + return empty_attrs; + + return openssl_attrs; } const char *