[Bug 297639] security/py-pyopenssl: upgrade to 26.2.0,1 broke TLS listener

From: <bugzilla-noreply_at_freebsd.org>
Date: Tue, 06 Oct 2026 07:45:04 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297639

Vladimir Bychik <vladimir.bychik.dev@gmail.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |python@FreeBSD.org,
                   |                            |vladimir.bychik.dev@gmail.c
                   |                            |om

--- Comment #1 from Vladimir Bychik <vladimir.bychik.dev@gmail.com> ---
This is not a pyOpenSSL bug. pyOpenSSL 26.2.0 made it an error to call mutating
methods on an SSL.Context after it has been used to create a Connection
(deprecated with a warning since 25.1). Twisted 25.5.0 does exactly that in
twisted/protocols/tls.py (_setAcceptableProtocols() on connection.get_context()
for IProtocolNegotiationFactory wrapped factories), so every TLS handshake on
an ALPN-capable listener (e.g. Synapse's 8448) raises ValueError and the
connection is dropped, hence the "unexpected eof".

Fixed upstream in Twisted 26.4.0
(https://github.com/twisted/twisted/issues/12500), which also fixes
CVE-2026-42304. devel/py-twisted is still at 25.5.0, so the proper fix is
updating devel/py-twisted to >= 26.4.0; I've filed bug 299174 for that.

Until then, either keep security/py-pyopenssl < 26.2.0, or locally patch tls.py
to catch the ValueError around _setAcceptableProtocols() (this disables ALPN,
falling back to HTTP/1.1).

-- 
You are receiving this mail because:
You are on the CC list for the bug.