LWP::Protocol::https loses Client-SSL-Version response metadata
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 45/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Área
- networking, security
Línea de trabajo
Comienza con t/example.t y sigue get_sslversion desde LWP::Protocol::https, pasando por IO::Socket::SSL, hasta la implementación de _get_sslversion del puente Java. Verifica que el protocolo de sesión de Java SSLSocket llegue a Perl como el valor TLSvN.N o SSLvN esperado y que se utilice el mismo socket actualizado a TLS. Se considera terminado cuando una prueba de regresión local o mock determinista pasa y t/example.t tiene éxito en ambos backends cuando el acceso a la red está disponible.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
LWP::Protocol::https v6.15 can complete an HTTPS request under PerlOnJava but fails to expose the negotiated TLS protocol version through the expected Client-SSL-Version response header.
CPAN evidence
- CPAN run:
20260918-141920-96054 - Distribution:
LWP::Protocol::httpsv6.15 - System Perl: PASS — 4 files, 62 tests
- PerlOnJava: FAIL — 1/4 test programs, 1/6 reported subtests
The failing test is t/example.t. The HTTPS request to https://httpbin.org succeeds, and the other response metadata checks pass, but this assertion fails:
Failed test 'have header Client-SSL-Version'
The PerlOnJava run skips t/https_proxy.t because fork is unsupported; that skip is unrelated to the failure.
Expected behavior
After a successful HTTPS request, LWP::Protocol::https should expose a negotiated TLS version in Client-SSL-Version, normally matching a value such as TLSv1.2 or TLSv1.3.
The same distribution passes completely under system Perl, including the version-header assertion.
Suspected cause
LWP::Protocol::https obtains the metadata from the underlying socket through:
$sock->get_sslversion
PerlOnJava supplies an IO::Socket::SSL compatibility layer backed by Java TLS. The Java bridge has an _get_sslversion implementation that reads the SSLSession protocol, but the CPAN test still receives no usable Client-SSL-Version value. This suggests a mismatch in socket identity, TLS-session access, protocol-string conversion, or metadata propagation between the Java socket and the Perl compatibility layer.
The failure is not an inability to establish HTTPS: the request reaches the server and the test proceeds to inspect the response. It is specifically a missing negotiated-version diagnostic.
Reproduction
Run the LWP::Protocol::https v6.15 test suite under PerlOnJava in an environment where httpbin.org:443 is reachable. t/example.t should fail at the Client-SSL-Version assertion while system Perl passes the complete suite.
A fresh local rerun outside the archived CPAN job could not reach httpbin.org and was skipped by Test::RequiresInternet, so the archived CPAN run is the retained reproduction evidence.
Requested fix
- Trace the negotiated TLS session from Java
SSLSocketthroughIO::Socket::SSL::get_sslversion. - Ensure the returned protocol string is available as a Perl scalar and has the expected
TLSvN.N/SSLvNform. - Verify that the socket object used by
LWP::Protocol::httpsis the same TLS-upgraded socket exposed by the Java bridge. - Add a deterministic project-owned regression test for TLS protocol metadata that does not depend on
httpbin.org, using a local TLS endpoint or a focused mock socket/session. - Rerun
LWP::Protocol::httpst/example.ton both JVM and interpreter backends when network access is available.
- Lenguaje dominante
- Perl
- Estrellas
- 64
- Forks
- 7
- Merge medio
- 5 h 25 min
- PR fusionados (30 d)
- 178
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de fglock/PerlOnJava
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
fglock/PerlOnJava#1651 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
fglock/PerlOnJava#1579 ·
Los mantenedores suelen responder en 1 día
-
area:cpan-port area:unicode bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
fglock/PerlOnJava#1341 ·
Los mantenedores suelen responder en 1 día
-
area:runtime bug
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
fglock/PerlOnJava#1700 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 12/100
fglock/PerlOnJava#1696 ·
Los mantenedores suelen responder en 1 día
Todos los issues de fglock/PerlOnJava
Issues similares
-
bug help wanted
Dificultad 2/5 Menos de una hora Aptitud para principiantes 70/100
bioepic-data/bervo#145 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Ubuntu .deb packages ship all files owned by uid/gid 1001 (CI user runner) instead of root:rootAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
-
Help-Wanted Needs-Triage Package-Update
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
microsoft/winget-pkgs#448814 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
FOODTURE
Dificultad 2/5 1-3 horas Aptitud para principiantes 67/100
openfoodfacts/openfoodfacts-server#14853 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Perl/Fish oddness in new versionAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
gugod/App-perlbrew#879 ·