When the underlying BIO_write() fails to send a datagram, we leave the
authorLutz Jänicke <jaenicke@openssl.org>
Fri, 10 Oct 2008 10:41:35 +0000 (10:41 +0000)
committerLutz Jänicke <jaenicke@openssl.org>
Fri, 10 Oct 2008 10:41:35 +0000 (10:41 +0000)
offending record queued as 'pending'. The DTLS code doesn't expect this,
and we end up hitting an OPENSSL_assert() in do_dtls1_write().

The simple fix is just _not_ to leave it queued. In DTLS, dropping
packets is perfectly acceptable -- and even preferable. If we wanted a
service with retries and guaranteed delivery, we'd be using TCP.
PR: #1703
Submitted by: David Woodhouse <dwmw2@infradead.org>

ssl/s3_pkt.c

index 7593ad91959b6be919d964c256e44f43d5eebfcf..1d6760e5154870a9acdb6f0bcfbbbd4523287442 100644 (file)
@@ -828,8 +828,16 @@ int ssl3_write_pending(SSL *s, int type, const unsigned char *buf,
                        s->rwstate=SSL_NOTHING;
                        return(s->s3->wpend_ret);
                        }
-               else if (i <= 0)
+               else if (i <= 0) {
+                       if (s->version == DTLS1_VERSION ||
+                           s->version == DTLS1_BAD_VER) {
+                               /* For DTLS, just drop it. That's kind of the wh
+ole
+                                  point in using a datagram service */
+                               wb->left = 0;
+                       }
                        return(i);
+               }
                wb->offset+=i;
                wb->left-=i;
                }