FTP: fix TLS session reuse on the data connection

FTP servers using SSL can be configured to check TLS session reuse on
the DATA connection. They hand out a new session on every CONTROL
connect and require to see the client using exactly that one when
up-/downloading on DATA.

This means:

1. We have to configure the SSL filter on the DATA connection with
   exactly the same peers.

2. We have to remember the SSL session on the CONTROL connection -
   separately from the session cache. The SSL filter on the DATA
   connection then looks for a session at the CONTROL filter and, if
   present, uses that.

Tests:

Enable `require_ssl_reuse` in our pytest setup for vsftpd. This
reproduces the problem reported in #22225 and verifies the fix.

Skip ftp+SSL pytests for rustls, as we have no possibility to reuse
sessions in that backend.

Schannel: we do not run these tests with the backend. I expect it has
similar problems but am not able to verify.

Reported-by: Laurent Sabourin
Fixes #22225
Closes #22246
This commit is contained in:
Stefan Eissing 2026-07-02 12:04:18 +02:00 committed by Daniel Stenberg
parent 0a7ec0ea4d
commit 84ecfb3ecc
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
17 changed files with 485 additions and 190 deletions

View file

@ -106,9 +106,7 @@ def httpd(env) -> Generator[Httpd, None, None]:
@pytest.fixture(scope="session")
def nghttpx(env, httpd) -> Generator[Union[Nghttpx, bool], None, None]:
nghttpx = NghttpxQuic(env=env)
if nghttpx.exists():
if not nghttpx.supports_h3() and env.have_h3_curl():
log.warning("nghttpx does not support QUIC, but curl does")
if nghttpx.exists() and nghttpx.supports_h3() and env.have_h3_curl():
nghttpx.clear_logs()
assert nghttpx.initial_start()
yield nghttpx