Tim Waugh 91b288
diff -up cups-1.4.4/cups/http.c.serialize-gnutls cups-1.4.4/cups/http.c
Tim Waugh 91b288
--- cups-1.4.4/cups/http.c.serialize-gnutls	2010-09-17 13:37:01.858871762 +0100
Tim Waugh 91b288
+++ cups-1.4.4/cups/http.c	2010-09-17 13:55:22.579871934 +0100
Tim Waugh 91b288
@@ -149,7 +149,7 @@ static int		http_write_ssl(http_t *http,
Tim Waugh 91b288
 
Tim Waugh 91b288
 #  ifdef HAVE_GNUTLS
Tim Waugh 91b288
 #    ifdef HAVE_PTHREAD_H
Tim Waugh 91b288
-GCRY_THREAD_OPTION_PTHREAD_IMPL;
Tim Waugh 91b288
+static pthread_mutex_t gnutls_lock;
Tim Waugh 91b288
 #    endif /* HAVE_PTHREAD_H */
Tim Waugh 91b288
 
Tim Waugh 91b288
 #  elif defined(HAVE_LIBSSL) && defined(HAVE_PTHREAD_H)
Tim Waugh 91b288
@@ -1231,7 +1231,7 @@ httpInitialize(void)
Tim Waugh 91b288
   */
Tim Waugh 91b288
 
Tim Waugh 91b288
 #  ifdef HAVE_PTHREAD_H
Tim Waugh 91b288
-  gcry_control(GCRYCTL_SET_THREAD_CBS, &gcry_threads_pthread);
Tim Waugh 91b288
+  pthread_mutex_init(&gnutls_lock, NULL);
Tim Waugh 91b288
 #  endif /* HAVE_PTHREAD_H */
Tim Waugh 91b288
 
Tim Waugh 91b288
  /*
Tim Waugh 91b288
@@ -2228,6 +2228,7 @@ _httpWait(http_t *http,			/* I - Connect
Tim Waugh 91b288
     if (SSL_pending((SSL *)(http->tls)))
Tim Waugh 91b288
       return (1);
Tim Waugh 91b288
 #  elif defined(HAVE_GNUTLS)
Tim Waugh 91b288
+    /* lock already held here... */
Tim Waugh 91b288
     if (gnutls_record_check_pending(((http_tls_t *)(http->tls))->session))
Tim Waugh 91b288
       return (1);
Tim Waugh 91b288
 #  elif defined(HAVE_CDSASSL)
Tim Waugh 91b288
@@ -2294,6 +2295,8 @@ int					/* O - 1 if data is available, 0
Tim Waugh 91b288
 httpWait(http_t *http,			/* I - Connection to server */
Tim Waugh 91b288
          int    msec)			/* I - Milliseconds to wait */
Tim Waugh 91b288
 {
Tim Waugh 91b288
+  int ret;
Tim Waugh 91b288
+
Tim Waugh 91b288
  /*
Tim Waugh 91b288
   * First see if there is data in the buffer...
Tim Waugh 91b288
   */
Tim Waugh 91b288
@@ -2318,7 +2321,17 @@ httpWait(http_t *http,			/* I - Connecti
Tim Waugh 91b288
   * If not, check the SSL/TLS buffers and do a select() on the connection...
Tim Waugh 91b288
   */
Tim Waugh 91b288
 
Tim Waugh 91b288
-  return (_httpWait(http, msec, 1));
Tim Waugh 91b288
+#if defined(HAVE_SSL) && defined(HAVE_GNUTLS) && defined(HAVE_PTHREAD_H)
Tim Waugh 91b288
+  pthread_mutex_lock(&gnutls_lock);
Tim Waugh 91b288
+#endif
Tim Waugh 91b288
+
Tim Waugh 91b288
+  ret = _httpWait(http, msec, 1);
Tim Waugh 91b288
+
Tim Waugh 91b288
+#if defined(HAVE_SSL) && defined(HAVE_GNUTLS) && defined(HAVE_PTHREAD_H)
Tim Waugh 91b288
+  pthread_mutex_unlock(&gnutls_lock);
Tim Waugh 91b288
+#endif
Tim Waugh 91b288
+
Tim Waugh 91b288
+  return (ret);
Tim Waugh 91b288
 }
Tim Waugh 91b288
 
Tim Waugh 91b288
 
Tim Waugh 91b288
@@ -2769,7 +2782,9 @@ http_read_ssl(http_t *http,		/* I - Conn
Tim Waugh 91b288
   ssize_t	result;			/* Return value */
Tim Waugh 91b288
 
Tim Waugh 91b288
 
Tim Waugh 91b288
+  pthread_mutex_lock(&gnutls_lock);
Tim Waugh 91b288
   result = gnutls_record_recv(((http_tls_t *)(http->tls))->session, buf, len);
Tim Waugh 91b288
+  pthread_mutex_unlock(&gnutls_lock);
Tim Waugh 91b288
 
Tim Waugh 91b288
   if (result < 0 && !errno)
Tim Waugh 91b288
   {
Tim Waugh 91b288
@@ -3085,6 +3100,7 @@ http_setup_ssl(http_t *http)		/* I - Con
Tim Waugh 91b288
     return (-1);
Tim Waugh 91b288
   }
Tim Waugh 91b288
 
Tim Waugh 91b288
+  pthread_mutex_lock(&gnutls_lock);
Tim Waugh 91b288
   gnutls_certificate_allocate_credentials(credentials);
Tim Waugh 91b288
 
Tim Waugh 91b288
   gnutls_init(&(conn->session), GNUTLS_CLIENT);
Tim Waugh 91b288
@@ -3104,9 +3120,11 @@ http_setup_ssl(http_t *http)		/* I - Con
Tim Waugh 91b288
     free(credentials);
Tim Waugh 91b288
     free(conn);
Tim Waugh 91b288
 
Tim Waugh 91b288
+    pthread_mutex_unlock(&gnutls_lock);
Tim Waugh 91b288
     return (-1);
Tim Waugh 91b288
   }
Tim Waugh 91b288
 
Tim Waugh 91b288
+  pthread_mutex_unlock(&gnutls_lock);
Tim Waugh 91b288
   conn->credentials = credentials;
Tim Waugh 91b288
 
Tim Waugh 91b288
 #  elif defined(HAVE_CDSASSL)
Tim Waugh 91b288
@@ -3196,9 +3214,11 @@ http_shutdown_ssl(http_t *http)		/* I - 
Tim Waugh 91b288
   conn = (http_tls_t *)(http->tls);
Tim Waugh 91b288
   credentials = (gnutls_certificate_client_credentials *)(conn->credentials);
Tim Waugh 91b288
 
Tim Waugh 91b288
+  pthread_mutex_lock(&gnutls_lock);
Tim Waugh 91b288
   gnutls_bye(conn->session, GNUTLS_SHUT_RDWR);
Tim Waugh 91b288
   gnutls_deinit(conn->session);
Tim Waugh 91b288
   gnutls_certificate_free_credentials(*credentials);
Tim Waugh 91b288
+  pthread_mutex_unlock(&gnutls_lock);
Tim Waugh 91b288
   free(credentials);
Tim Waugh 91b288
   free(conn);
Tim Waugh 91b288
 
Tim Waugh 91b288
@@ -3445,7 +3465,9 @@ http_write_ssl(http_t     *http,	/* I - 
Tim Waugh 91b288
 #  elif defined(HAVE_GNUTLS)
Tim Waugh 91b288
   ssize_t	result;			/* Return value */
Tim Waugh 91b288
 
Tim Waugh 91b288
+  pthread_mutex_lock(&gnutls_lock);
Tim Waugh 91b288
   result = gnutls_record_send(((http_tls_t *)(http->tls))->session, buf, len);
Tim Waugh 91b288
+  pthread_mutex_unlock(&gnutls_lock);
Tim Waugh 91b288
 
Tim Waugh 91b288
   if (result < 0 && !errno)
Tim Waugh 91b288
   {