Fix mbedTLS close_notify mid-response handling

The mbedTLS backend's read() returned -1 with err.code = PeerClosed when
the peer sent close_notify, while OpenSSL and wolfSSL surface it as 0
(clean EOF). The result was that an SSL response without Content-Length
or chunked Transfer-Encoding — terminated by connection close — was
reported as "Failed to read connection" on mbedTLS, even though the
body had been fully delivered.

Translate PeerClosed into a return value of 0 to match the other
backends. This re-enables SSLTest.ResponseBodyTerminatedByConnectionClose
on mbedTLS.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
yhirose
2026-04-29 10:04:10 +09:00
co-authored by Claude Opus 4.7
parent 109e331068
commit 3d56762d5c
2 changed files with 3 additions and 6 deletions
-6
View File
@@ -14626,12 +14626,6 @@ TEST_F(SSLOpenStreamTest, PostChunked) {
// SSL peer sends a close_notify after the body, the client must treat it as a
// clean EOF and return a successful response rather than an error.
TEST(SSLTest, ResponseBodyTerminatedByConnectionClose) {
#ifdef CPPHTTPLIB_MBEDTLS_SUPPORT
// TODO: mbedTLS reports a clean close_notify mid-response as a read error.
// Treat the EOF as a successful body terminator the way the OpenSSL/wolfSSL
// backends already do.
GTEST_SKIP() << "mbedTLS backend treats close_notify mid-response as error";
#endif
SSLServer svr(SERVER_CERT_FILE, SERVER_PRIVATE_KEY_FILE);
ASSERT_TRUE(svr.is_valid());