提交 ba709049 编写于 作者: M Matt Caswell

Return SSL_ERROR_WANT_READ if SSL_shutdown() encounters handshake data

In the case where we are shutdown for writing and awaiting a close_notify
back from a subsequent SSL_shutdown() call we skip over handshake data
that is received. This should not be treated as an error - instead it
should be signalled with SSL_ERROR_WANT_READ.
Reviewed-by: NBernd Edlinger <bernd.edlinger@hotmail.de>
Reviewed-by: NKurt Roeckx <kurt@roeckx.be>
(Merged from https://github.com/openssl/openssl/pull/6340)
上级 c748834f
...@@ -1553,20 +1553,30 @@ int ssl3_read_bytes(SSL *s, int type, int *recvd_type, unsigned char *buf, ...@@ -1553,20 +1553,30 @@ int ssl3_read_bytes(SSL *s, int type, int *recvd_type, unsigned char *buf,
* If we've sent a close_notify but not yet received one back then ditch * If we've sent a close_notify but not yet received one back then ditch
* anything we read. * anything we read.
*/ */
if ((s->shutdown & SSL_SENT_SHUTDOWN) != 0 ) { if ((s->shutdown & SSL_SENT_SHUTDOWN) != 0) {
/* /*
* In TLSv1.3 this could get problematic if we receive a KeyUpdate * In TLSv1.3 this could get problematic if we receive a KeyUpdate
* message after we sent a close_notify because we're about to ditch it, * message after we sent a close_notify because we're about to ditch it,
* so we won't be able to read a close_notify sent afterwards! We don't * so we won't be able to read a close_notify sent afterwards! We don't
* support that. * support that.
*/ */
s->rwstate = SSL_NOTHING;
SSL3_RECORD_set_length(rr, 0); SSL3_RECORD_set_length(rr, 0);
SSL3_RECORD_set_read(rr); SSL3_RECORD_set_read(rr);
if (SSL3_RECORD_get_type(rr) == SSL3_RT_HANDSHAKE if (SSL3_RECORD_get_type(rr) == SSL3_RT_HANDSHAKE) {
&& (s->mode & SSL_MODE_AUTO_RETRY) != 0) BIO *rbio;
goto start;
if ((s->mode & SSL_MODE_AUTO_RETRY) != 0)
goto start;
s->rwstate = SSL_READING;
rbio = SSL_get_rbio(s);
BIO_clear_retry_flags(rbio);
BIO_set_retry_read(rbio);
return -1;
}
s->rwstate = SSL_NOTHING;
return 0; return 0;
} }
......
...@@ -5051,12 +5051,7 @@ static int test_shutdown(int tst) ...@@ -5051,12 +5051,7 @@ static int test_shutdown(int tst)
} }
/* Writing on the client after sending close_notify shouldn't be possible */ /* Writing on the client after sending close_notify shouldn't be possible */
if (!TEST_false(SSL_write_ex(clientssl, msg, sizeof(msg), &written)) if (!TEST_false(SSL_write_ex(clientssl, msg, sizeof(msg), &written)))
/*
* Writing on the server after sending close_notify shouldn't be
* possible.
*/
|| !TEST_false(SSL_write_ex(clientssl, msg, sizeof(msg), &written)))
goto end; goto end;
if (tst < 4) { if (tst < 4) {
...@@ -5066,6 +5061,11 @@ static int test_shutdown(int tst) ...@@ -5066,6 +5061,11 @@ static int test_shutdown(int tst)
* yet. * yet.
*/ */
if (!TEST_int_eq(SSL_shutdown(serverssl), 0) if (!TEST_int_eq(SSL_shutdown(serverssl), 0)
/*
* Writing on the server after sending close_notify shouldn't
* be possible.
*/
|| !TEST_false(SSL_write_ex(serverssl, msg, sizeof(msg), &written))
|| !TEST_int_eq(SSL_shutdown(clientssl), 1) || !TEST_int_eq(SSL_shutdown(clientssl), 1)
|| !TEST_int_eq(SSL_shutdown(serverssl), 1)) || !TEST_int_eq(SSL_shutdown(serverssl), 1))
goto end; goto end;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册