Use prepend to fix OpenSSL::PKey::EC.new on OpenSSL 3.x

alias_method doesn't reliably wrap C-extension class methods. Switch to
singleton_class.prepend which correctly intercepts the call chain. Falls
back to OpenSSL::PKey.read when EC.new raises on PKCS#8 format keys.
This commit is contained in:
Adam Moussa 2026-05-18 19:27:26 -04:00
parent e355809b58
commit a0ccf676b8

View file

@ -1,22 +1,17 @@
require 'openssl'
# Workaround: fastlane 2.234.0 uses OpenSSL::PKey::EC.new which fails on
# PKCS#8 keys with OpenSSL 3.x ("invalid curve name"). Fallback to PKey.read.
module OpenSSL
module PKey
class EC
class << self
alias_method :_orig_new, :new
def new(*args)
_orig_new(*args)
rescue OpenSSL::PKey::ECError
raise unless args.length == 1 && args[0].is_a?(String)
OpenSSL::PKey.read(args[0])
end
end
end
# Fastlane 2.234.0 uses OpenSSL::PKey::EC.new which rejects PKCS#8 keys on
# OpenSSL 3.x ("invalid curve name"). Prepend a wrapper that falls back to
# OpenSSL::PKey.read, which handles both PKCS#8 and SEC1 formats.
module OpenSSLECNewFix
def new(arg = nil, *rest)
super
rescue OpenSSL::PKey::ECError
raise if arg.nil? || !arg.is_a?(String)
OpenSSL::PKey.read(arg)
end
end
OpenSSL::PKey::EC.singleton_class.prepend(OpenSSLECNewFix)
default_platform(:ios)