Commit bb908b895b for openssl.org
commit bb908b895bef4bf5965ddb483f12eb1fe1ec5b40
Author: Nikolas Gauder <nikolas.gauder@tum.de>
Date: Wed Oct 7 19:35:28 2026 +0200
test/quicapitest.c: fix BIO leak in test_quic_amplification_limit()
The dgram pair BIOs leaked if the test failed before SSL_set_bio().
Free them on exit, and clear the local pointers once the SSL objects
own them, as other tests in this file do.
Fixes: dc13cfb93120 "Add a test to check for quic unvalidated credit"
Assisted-by: Claude:claude-opus-5-5
Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Saša NedvÄ›dický <sashan@openssl.org>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Merge-date: Sat Oct 10 08:16:49 2026
Merged-from: https://github.com/openssl/openssl/pull/33150
diff --git a/test/quicapitest.c b/test/quicapitest.c
index 726bdd7e19..c2a055b633 100644
--- a/test/quicapitest.c
+++ b/test/quicapitest.c
@@ -3596,6 +3596,8 @@ static int test_quic_amplification_limit(void)
SSL_set_bio(listener, s_bio, s_bio);
SSL_set_bio(client, c_bio, c_bio);
+ /* The SSL objects own the BIOs now, they are freed with them. */
+ s_bio = c_bio = NULL;
if (!TEST_true(SSL_set_blocking_mode(listener, 0)))
goto err;
@@ -3639,7 +3641,7 @@ static int test_quic_amplification_limit(void)
/*
* Make sure that the client hello was received at the server
*/
- if (!wait_readable(s_bio, 1000)) {
+ if (!wait_readable(SSL_get_rbio(listener), 1000)) {
TEST_info("timed out waiting for the ClientHello");
goto err;
}
@@ -3669,7 +3671,8 @@ static int test_quic_amplification_limit(void)
(unsigned long long)first_injected_pn);
/* Count but never deliver the server flight to the QUIC client. */
- if (!TEST_true(drain_server_output(c_bio, &server_bytes, &server_datagrams)))
+ if (!TEST_true(drain_server_output(SSL_get_rbio(client), &server_bytes,
+ &server_datagrams)))
goto err;
TEST_info("phase 1 complete: legitimate ClientHello credit exhausted");
@@ -3699,7 +3702,8 @@ static int test_quic_amplification_limit(void)
goto err;
if (!TEST_true(SSL_handle_events(server)))
goto err;
- drain_server_output(c_bio, &server_bytes, &server_datagrams);
+ drain_server_output(SSL_get_rbio(client), &server_bytes,
+ &server_datagrams);
}
TEST_info("client UDP payload: %llu bytes in 2 datagrams",
@@ -3732,6 +3736,8 @@ err:
SSL_free(server);
SSL_free(client);
SSL_free(listener);
+ BIO_free(c_bio);
+ BIO_free(s_bio);
SSL_CTX_free(cctx);
SSL_CTX_free(sctx);
BIO_ADDR_free(client_addr);