Brian Geffon created TS-3031:
--------------------------------

             Summary: Race condition in SSLNextProtocolSet::advertiseProtocols
                 Key: TS-3031
                 URL: https://issues.apache.org/jira/browse/TS-3031
             Project: Traffic Server
          Issue Type: Bug
          Components: Core, SSL
            Reporter: Brian Geffon


We've observed a bug in a production environment where clients would receive 
malformed NPN sets. This is caused by a race condition in 
SSLNextProtocolSet::advertiseProtocols:

{code}
 if (!npn && !this->endpoints.empty()) {    
   create_npn_advertisement(this->endpoints, &npn, &npnsz);
 }
{code}

Obviously this code is attempting to initailize the npn offer string on the 
first SSL request to that port, this is a race condition. I have a fix that 
will be committed today.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Reply via email to