Skip to content

crypto/x509: work around SecPolicyCreateSSL when executable dir is missing#80471

Open
NorseGaud wants to merge 1 commit into
golang:masterfrom
NorseGaud:crypto-x509-secpolicy-missing-exe-dir
Open

crypto/x509: work around SecPolicyCreateSSL when executable dir is missing#80471
NorseGaud wants to merge 1 commit into
golang:masterfrom
NorseGaud:crypto-x509-secpolicy-missing-exe-dir

Conversation

@NorseGaud

Copy link
Copy Markdown

On macOS, Security.framework returns NULL from SecPolicyCreateSSL when the directory containing the running executable no longer exists. That commonly happens with "go run" after the go command deletes its temporary build directory while a child process is still running.

Fixes #68557

This PR will be imported into Gerrit with the title and first
comment (this text) used to generate the subject and body of
the Gerrit change.

Please ensure you adhere to every item in this list.

More info can be found at https://go.dev/wiki/CommitMessage

  • The PR title is formatted as follows: net/http: frob the quux before blarfing
    • The package name goes before the colon
    • The part after the colon uses the verb tense + phrase that completes the blank in,
      "This change modifies Go to ___________"
    • Lowercase verb after the colon
    • No trailing period
    • Keep the title as short as possible, ideally 72 characters or shorter
  • No Markdown
  • The first PR comment (this one) is wrapped at around 72 characters, unless it's
    really needed (ASCII art, table, or long link)
  • If there is a corresponding issue, add either Fixes #1234 or Updates #1234
    (the latter if this is not a complete fix) to this comment
  • If referring to a repo other than golang/go you can use the
    owner/repo#issue_number syntax: Fixes golang/vscode-go#1234
  • We do not use Signed-off-by lines in Go. Please don't add them.
    Our Gerrit server & GitHub bots enforce CLA compliance instead.
  • Delete these instructions once you have read and applied them

…ssing

On macOS, Security.framework returns NULL from SecPolicyCreateSSL when the
directory containing the running executable no longer exists. That commonly
happens with "go run" after the go command deletes its temporary build
directory while a child process is still running.

Fixes golang#68557

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

crypto/x509: Get "https://google.com": tls: failed to verify certificate: SecPolicyCreateSSL error: 0 when running in child after parent exits

1 participant