fix(tls): prevent DoS by removing blocking sleep
This commit is contained in:
parent
70c8c8f668
commit
329783490b
1 changed files with 4 additions and 5 deletions
|
|
@ -423,13 +423,12 @@ int SecureSocket::secureAccept(int socket)
|
||||||
checkResult(r, retry);
|
checkResult(r, retry);
|
||||||
|
|
||||||
if (isFatal()) {
|
if (isFatal()) {
|
||||||
// tell user and sleep so the socket isn't hammered.
|
// Never block here; this thread services every connected socket.
|
||||||
|
// Historically a 1s sleep let any failed handshake DoS all clients.
|
||||||
LOG_ERR("failed to accept secure socket");
|
LOG_ERR("failed to accept secure socket");
|
||||||
LOG_WARN("client connection may not be secure");
|
|
||||||
m_secureReady = false;
|
m_secureReady = false;
|
||||||
Arch::sleep(1);
|
|
||||||
retry = 0;
|
retry = 0;
|
||||||
return -1; // Failed, error out
|
return -1; // Fail
|
||||||
}
|
}
|
||||||
|
|
||||||
// If not fatal and no retry, state is good
|
// If not fatal and no retry, state is good
|
||||||
|
|
@ -455,7 +454,7 @@ int SecureSocket::secureAccept(int socket)
|
||||||
|
|
||||||
// no good state exists here
|
// no good state exists here
|
||||||
LOG_ERR("unexpected state attempting to accept connection");
|
LOG_ERR("unexpected state attempting to accept connection");
|
||||||
return -1;
|
return -1; // Fail
|
||||||
}
|
}
|
||||||
|
|
||||||
int SecureSocket::secureConnect(int socket)
|
int SecureSocket::secureConnect(int socket)
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue