Skip to content

tls: fix OpenSSL compression leak that breaks tests under ASAN - #66600

Open
pimterry wants to merge 1 commit into
nodejs:mainfrom
pimterry:fix-record-compression-asan
Open

pimterry wants to merge 1 commit into
nodejs:mainfrom
pimterry:fix-record-compression-asan

Conversation

@pimterry

@pimterry pimterry commented Oct 8, 2026

Copy link
Copy Markdown
Member

This is not impactful for normal users at all - it's a fixed leak of the openssl record compression descriptors, about 24 bytes leaked total, once per process.

It is very annoying though if you want to run with ASAN & leak detection to check for other issues. It's an unambiguous memory leak we hit effectively every run where crypto is used.

The change here ensures we individually free the descriptors, in addition to emptying the stack that references them. There's an existing test that confirms this doesn't accidentally re-enable record compression somehow.

This is not impactful in any way - it's a fixed leak of the openssl
record compression descriptors, about 24 bytes leaked total, once
per process. Not meaningful.

It is annoying if you want to run with ASAN & leak detection though,
since it's an unambiguous leak we trigger every time crypto is used.

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/crypto

@nodejs-github-bot nodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. crypto Issues and PRs related to the crypto subsystem. needs-ci PRs that need a full CI run. labels Oct 8, 2026
@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.44%. Comparing base (6d5e309) to head (3b42cf7).
⚠️ Report is 4 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #66600      +/-   ##
==========================================
- Coverage   90.44%   90.44%   -0.01%     
==========================================
  Files         791      791              
  Lines      276562   276565       +3     
  Branches    53126    53117       -9     
==========================================
+ Hits       250130   250131       +1     
+ Misses      16846    16842       -4     
- Partials     9586     9592       +6     
Files with missing lines Coverage Δ
src/crypto/crypto_util.cc 51.61% <100.00%> (+0.13%) ⬆️

... and 32 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c++ Issues and PRs that require attention from people who are familiar with C++. crypto Issues and PRs related to the crypto subsystem. needs-ci PRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants