jackc/pgx · error

bad ssl request code

Error message

bad ssl request code

What it means

SSLRequest.Decode guard: the 4-byte request code in the message body does not equal the magic constant 80877103 that identifies an SSLRequest. The peer sent some other startup packet where an SSL request was expected; the mismatched request code is the faulty input.

Solutions

  1. Confirm the client is sending the correct SSLRequest magic number
  2. Check protocol framing — bytes may be misaligned from a prior malformed message
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at pgproto3/ssl_request.go:26 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/2b85e9f0f5e30df9. Report an issue: GitHub.

Appendix: source

Thrown at pgproto3/ssl_request.go:26

	"github.com/jackc/pgx/v5/internal/pgio"
)

const sslRequestNumber = 80877103

type SSLRequest struct{}

// Frontend identifies this message as sendable by a PostgreSQL frontend.
func (*SSLRequest) Frontend() {}

func (dst *SSLRequest) Decode(src []byte) error {
	if len(src) < 4 {
		return errors.New("ssl request too short")
	}

	requestCode := binary.BigEndian.Uint32(src)

	if requestCode != sslRequestNumber {
		return errors.New("bad ssl request code")
	}

	return nil
}

// Encode encodes src into dst. dst will include the 4 byte message length.
func (src *SSLRequest) Encode(dst []byte) ([]byte, error) {
	dst = pgio.AppendInt32(dst, 8)
	dst = pgio.AppendInt32(dst, sslRequestNumber)
	return dst, nil
}

// MarshalJSON implements encoding/json.Marshaler.
func (src SSLRequest) MarshalJSON() ([]byte, error) {
	return json.Marshal(struct {
		Type            string
		ProtocolVersion uint32
		Parameters      map[string]string

View on GitHub (pinned to ec1a0befd2)