summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorLudovic Courtès <ludo@gnu.org>2020-01-10 12:11:45 +0100
committerLudovic Courtès <ludo@gnu.org>2020-01-10 12:11:45 +0100
commitf5dcf067c19a42bcd1644607e10c4603e8a079e1 (patch)
tree726a3d28507efd0ba0e445805402e144dabf61e2
parente097e9839e4f29b9331d32f9798bf9c468075421 (diff)
downloadguile-f5dcf067c19a42bcd1644607e10c4603e8a079e1.tar.gz
web: Continue handshake upon TLS warning alerts.
This is a backport of Guix commit 7b9ac883ea62a816afbfa747c1377dc273c15c20. * module/web/client.scm (tls-wrap): Catch 'gnutls-error' around 'handshake'. Upon ERROR/WARNING-ALERT-RECEIVED, print a message and call 'handshake'.
-rw-r--r--module/web/client.scm17
1 files changed, 16 insertions, 1 deletions
diff --git a/module/web/client.scm b/module/web/client.scm
index 3761eb546..74fc85518 100644
--- a/module/web/client.scm
+++ b/module/web/client.scm
@@ -125,7 +125,22 @@ host name without trailing dot."
;;(set-log-level! 10)
;;(set-log-procedure! log)
- (handshake session)
+ (catch 'gnutls-error
+ (lambda ()
+ (handshake session))
+ (lambda (key err proc . rest)
+ (cond ((eq? err error/warning-alert-received)
+ ;; Like Wget, do no stop upon non-fatal alerts such as
+ ;; 'alert-description/unrecognized-name'.
+ (format (current-error-port)
+ "warning: TLS warning alert received: ~a~%"
+ (alert-description->string (alert-get session)))
+ (handshake session))
+ (else
+ ;; XXX: We'd use 'gnutls_error_is_fatal' but (gnutls) doesn't
+ ;; provide a binding for this.
+ (apply throw key err proc rest)))))
+
;; FIXME: It appears that session-record-port is entirely
;; sufficient; it's already a port. The only value of this code is
;; to keep a reference on "port", to keep it alive! To fix this we