RFR: 8331682: Slow networks/Impatient clients can potentially send unencrypted TLSv1.3 alerts that won't parse on the server [v9]

Artur Barashev abarashev at openjdk.org
Fri Sep 27 19:53:37 UTC 2024


On Fri, 27 Sep 2024 19:30:52 GMT, Daniel Jeliński <djelinski at openjdk.org> wrote:

>> You mean the `packet` buffer? No, it has 2 bytes remaining as it should.
>
> I was referring to `srcs[srcOffset]`; `packet` is a duplicate, so the position is independent from the original.

No, the position was already advanced in `decodeInputRecord`. The test correctly reports `bytesConsumed = 7` when server unwraps the alerts.

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/21043#discussion_r1779085559


More information about the security-dev mailing list