CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]   2026/09/21 17:16:29

Modified files:
        lib/libssl     : d1_lib.c d1_pkt.c dtls_local.h 

Log message:
Remove DTLS application data queue.

This queue exists to buffer application data that has arrived after
a ChangeCipherSpec message, but before the Finished message. This
is most likely to happen if the Finished message is dropped or
delivered out of order. In the case where the application data
arrived prior to the ChangeCipherSpec, it will be discarded and
the application needs to deal with the loss in the same way as it
does any other network induced packet loss.

RFC 6347 section 4.2.4 says that we must either buffer or discard
all application data that arrives in the next epoch, prior to
receipt of the Finished message. Remove the queue and discard
since this is the simpler option. BoringSSL did the same a long
time ago.

ok beck@ joshua@ kenjiro@

Reply via email to