jackc/pgx · error

ssl request too short

Error message

ssl request too short

What it means

SSLRequest.Decode guard: the message body is shorter than the 4 bytes needed to hold the SSL request code. Only reachable on the server side of a startup exchange receiving a truncated SSLRequest packet; the truncated input buffer is the faulty input.

Solutions

  1. Ensure the client sends the complete 8-byte SSLRequest packet
  2. Check the connection for truncation or premature close
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at pgproto3/ssl_request.go:20 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/dba11e99426cb584. Report an issue: GitHub.

Appendix: source

Thrown at pgproto3/ssl_request.go:20

import (
	"encoding/binary"
	"encoding/json"
	"errors"

	"github.com/jackc/pgx/v5/internal/pgio"
)

const sslRequestNumber = 80877103

type SSLRequest struct{}

// Frontend identifies this message as sendable by a PostgreSQL frontend.
func (*SSLRequest) Frontend() {}

func (dst *SSLRequest) Decode(src []byte) error {
	if len(src) < 4 {
		return errors.New("ssl request too short")
	}

	requestCode := binary.BigEndian.Uint32(src)

	if requestCode != sslRequestNumber {
		return errors.New("bad ssl request code")
	}

	return nil
}

// Encode encodes src into dst. dst will include the 4 byte message length.
func (src *SSLRequest) Encode(dst []byte) ([]byte, error) {
	dst = pgio.AppendInt32(dst, 8)
	dst = pgio.AppendInt32(dst, sslRequestNumber)
	return dst, nil
}

View on GitHub (pinned to ec1a0befd2)