From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Lars Ingebrigtsen Newsgroups: gmane.emacs.bugs Subject: bug#26835: 26.0.50; url-retrieve no longer raises certificate errors Date: Wed, 10 May 2017 16:24:13 +0200 Message-ID: References: <8337cfcgr2.fsf@gnu.org> <83lgq5c40b.fsf@gnu.org> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1494426458 4768 195.159.176.226 (10 May 2017 14:27:38 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Wed, 10 May 2017 14:27:38 +0000 (UTC) User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.0.50 (gnu/linux) Cc: 26835@debbugs.gnu.org, Aaron Jensen To: Eli Zaretskii Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Wed May 10 16:27:33 2017 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d8SaS-000128-J4 for geb-bug-gnu-emacs@m.gmane.org; Wed, 10 May 2017 16:27:32 +0200 Original-Received: from localhost ([::1]:43049 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1d8SaW-0008CE-NR for geb-bug-gnu-emacs@m.gmane.org; Wed, 10 May 2017 10:27:36 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:53502) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1d8SY7-0006fq-2Q for bug-gnu-emacs@gnu.org; Wed, 10 May 2017 10:25:08 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1d8SY3-00081r-30 for bug-gnu-emacs@gnu.org; Wed, 10 May 2017 10:25:07 -0400 Original-Received: from debbugs.gnu.org ([208.118.235.43]:34172) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1d8SY2-00081n-Us for bug-gnu-emacs@gnu.org; Wed, 10 May 2017 10:25:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1d8SY2-0002z7-PQ for bug-gnu-emacs@gnu.org; Wed, 10 May 2017 10:25:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Lars Ingebrigtsen Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Wed, 10 May 2017 14:25:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 26835 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: security Original-Received: via spool by 26835-submit@debbugs.gnu.org id=B26835.149442626411414 (code B ref 26835); Wed, 10 May 2017 14:25:02 +0000 Original-Received: (at 26835) by debbugs.gnu.org; 10 May 2017 14:24:24 +0000 Original-Received: from localhost ([127.0.0.1]:36848 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d8SXQ-0002y2-8O for submit@debbugs.gnu.org; Wed, 10 May 2017 10:24:24 -0400 Original-Received: from hermes.netfonds.no ([80.91.224.195]:60517) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d8SXN-0002xs-Lc for 26835@debbugs.gnu.org; Wed, 10 May 2017 10:24:22 -0400 Original-Received: from cm-84.209.243.26.getinternet.no ([84.209.243.26] helo=stories) by hermes.netfonds.no with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.84_2) (envelope-from ) id 1d8SXG-0005ad-7k; Wed, 10 May 2017 16:24:16 +0200 Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwBAMAAAClLOS0AAAAD1BMVEXx8e2rqbJyXGbHxMiX lpuFfuCVAAACQklEQVQ4jXVT62HzMAjEnzyAiRigcTWAFDSAkdh/pu+w3bT9UeXhhNPxOID2Pw79 DRhnIkpKqTWBxccXILxRqsBqalkbrik1JU5NObtvbiAKnt64WSXhbsrmXTxTgtXdMpi0NvY43EDp ngEM/GPKYmGfNa77RrSIwG7UFi/ObgkxRRGmOXeXTFVln69xDOTEASQ3LQg+62ufA7mX8Ij864oo kyjXqGrsAyF9jHLQv+enGOpV3p/7KxgFxPJc+z7zCUjZ9xUA3HkpxfKa9r1SVi7nfQc+yu5eScNj uLoixyOe5rW3Ga6er+eZ0TgTC81qByD+iU8Afp8aRuqtO0SFg8hX8IIuq3eSrVvyX2fW7kp2iSvv L5AhFpNtkMyth/L9uuQsniDi7cis3uwzPuGN/gRhyFYudxQnpqDZA5YdmnnuX0C0YJXzJh/d+M0I znpltNDK82bUk2NIK5IBsKVTEzQ6zVaXqwhD07clK9rXE3VbYz7sTrM2zgeAlcR6pbcalTGGAXQa UzaSL2BTVQmgkUxO9BjXkPjUmnAxLUw+G4Di6NJAS7KKMYBMm2XS0GhEB6NZlkFjGKduZ1PH3Y0k NYMRg6qdHj8bi8HOCO5H11O7ixAqJfhHaVtG+f1NOAGkywt+lyPFXppavpRNJBVNJD2EGQVUvYGz H8lf5QNlDHtiBCp9n5Y0YbRlwwb/ArDlqSHEsbpAoG9IsWWsbvMRVYaI97Hm46jYHAz+ME1vIFZ5 kuRa7Tl+xkBmFeuAYHvhG/gPywKsGKvkrtwAAAAASUVORK5CYII= In-Reply-To: <83lgq5c40b.fsf@gnu.org> (Eli Zaretskii's message of "Tue, 09 May 2017 20:51:48 +0300") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:132429 Archived-At: Eli Zaretskii writes: >> It repros in `emacs -Q', just set: >> >> (setq gnutls-verify-error t) >> (url-retrieve-synchronously "https://wrong.host.badssl.com/") >> >> In Emacs 25.2, this causes an error to be thrown when you use >> url-retrieve, in 26, it silently proceeds. > > That's because we now perform GnuTLS negotiation asynchronously, > without blocking. (As an aside, perhaps url-retrieve-synchronously should be opening the socket with :nowait nil?) > status = p->status; > if (CONSP (status)) > status = XCAR (status); > > which loses the error message, leaving just 'failed'. So > url-retrieve-synchronously silently exits, and doesn't even have the > info that could cause it to signal an error. > > IOW, the problem is not that the connection proceeds -- it does not. > The problem is that it fails silently without telling the caller what > caused the failure. > > I'll CC Lars, who introduced the non-blocking connections. Good analysis. I'll try to have a look at this soonish (and make it report the error properly) unless somebody else beats me to it. -- (domestic pets only, the antidote for overdose, milk.) bloggy blog: http://lars.ingebrigtsen.no