Stop skipping stray HelloRequests.
This makes sense to do if we are a client and initiate a renegotiation at the same time as the server requesting one. Since we will never initiate a renegotiation, this should not be necessary. Change-Id: I5835944291fdb8dfcc4fed2ebf1064e91ccdbe6a Reviewed-on: https://boringssl-review.googlesource.com/13825 Reviewed-by: Steven Valdez <svaldez@google.com> Reviewed-by: David Benjamin <davidben@google.com> Commit-Queue: David Benjamin <davidben@google.com> CQ-Verified: CQ bot account: commit-bot@chromium.org <commit-bot@chromium.org>
This commit is contained in:
committed by
CQ bot account: commit-bot@chromium.org
parent
040bc4944b
commit
07ab5d44d9
@@ -678,7 +678,6 @@ static int read_v2_client_hello(SSL *ssl) {
|
||||
}
|
||||
|
||||
int ssl3_get_message(SSL *ssl) {
|
||||
again:
|
||||
/* Re-create the handshake buffer if needed. */
|
||||
if (ssl->init_buf == NULL) {
|
||||
ssl->init_buf = BUF_MEM_new();
|
||||
@@ -733,16 +732,6 @@ again:
|
||||
ssl->s3->tmp.message_type = ((const uint8_t *)ssl->init_buf->data)[0];
|
||||
ssl->init_msg = (uint8_t*)ssl->init_buf->data + SSL3_HM_HEADER_LENGTH;
|
||||
ssl->init_num = ssl->init_buf->length - SSL3_HM_HEADER_LENGTH;
|
||||
|
||||
/* Ignore stray HelloRequest messages in the handshake before TLS 1.3. Per RFC
|
||||
* 5246, section 7.4.1.1, the server may send HelloRequest at any time. */
|
||||
if (!ssl->server && SSL_in_init(ssl) &&
|
||||
(!ssl->s3->have_version || ssl3_protocol_version(ssl) < TLS1_3_VERSION) &&
|
||||
ssl->s3->tmp.message_type == SSL3_MT_HELLO_REQUEST &&
|
||||
ssl->init_num == 0) {
|
||||
goto again;
|
||||
}
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
|
||||
@@ -6395,7 +6395,7 @@ func addRenegotiationTests() {
|
||||
// this case. https://crbug.com/boringssl/130
|
||||
})
|
||||
|
||||
// Stray HelloRequests during the handshake are ignored in TLS 1.2.
|
||||
// We reject stray HelloRequests during the handshake in TLS 1.2.
|
||||
testCases = append(testCases, testCase{
|
||||
name: "StrayHelloRequest",
|
||||
config: Config{
|
||||
@@ -6404,6 +6404,8 @@ func addRenegotiationTests() {
|
||||
SendHelloRequestBeforeEveryHandshakeMessage: true,
|
||||
},
|
||||
},
|
||||
shouldFail: true,
|
||||
expectedError: ":UNEXPECTED_MESSAGE:",
|
||||
})
|
||||
testCases = append(testCases, testCase{
|
||||
name: "StrayHelloRequest-Packed",
|
||||
@@ -6414,6 +6416,8 @@ func addRenegotiationTests() {
|
||||
SendHelloRequestBeforeEveryHandshakeMessage: true,
|
||||
},
|
||||
},
|
||||
shouldFail: true,
|
||||
expectedError: ":UNEXPECTED_MESSAGE:",
|
||||
})
|
||||
|
||||
// Test renegotiation works if HelloRequest and server Finished come in
|
||||
|
||||
Reference in New Issue
Block a user