Skip to content

Commit a875f32

Browse files
nibjenPaul Hohensee
authored andcommitted
8367133: DTLS: fragmentation of Finished message results in handshake failure
Backport-of: 80cb0ead502ae439660f2a3bbab42df4da39d9d6
1 parent 368e829 commit a875f32

File tree

2 files changed

+78
-3
lines changed

2 files changed

+78
-3
lines changed

src/java.base/share/classes/sun/security/ssl/DTLSInputRecord.java

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
/*
2-
* Copyright (c) 2015, 2024, Oracle and/or its affiliates. All rights reserved.
2+
* Copyright (c) 2015, 2025, Oracle and/or its affiliates. All rights reserved.
33
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
44
*
55
* This code is free software; you can redistribute it and/or modify it
@@ -801,8 +801,11 @@ void queueUpHandshake(HandshakeFragment hsf) throws SSLProtocolException {
801801

802802
// buffer this fragment
803803
if (hsf.handshakeType == SSLHandshake.FINISHED.id) {
804-
// Need no status update.
805-
bufferedFragments.add(hsf);
804+
// Make sure it's not a retransmitted message
805+
if (hsf.recordEpoch > handshakeEpoch) {
806+
bufferedFragments.add(hsf);
807+
flightIsReady = holes.isEmpty();
808+
}
806809
} else {
807810
bufferFragment(hsf);
808811
}
Lines changed: 72 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,72 @@
1+
/*
2+
* Copyright (c) 2025, Oracle and/or its affiliates. All rights reserved.
3+
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
4+
*
5+
* This code is free software; you can redistribute it and/or modify it
6+
* under the terms of the GNU General Public License version 2 only, as
7+
* published by the Free Software Foundation.
8+
*
9+
* This code is distributed in the hope that it will be useful, but WITHOUT
10+
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11+
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
12+
* version 2 for more details (a copy is included in the LICENSE file that
13+
* accompanied this code).
14+
*
15+
* You should have received a copy of the GNU General Public License version
16+
* 2 along with this work; if not, write to the Free Software Foundation,
17+
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
18+
*
19+
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
20+
* or visit www.oracle.com if you need additional information or have any
21+
* questions.
22+
*/
23+
24+
// SunJSSE does not support dynamic system properties, no way to re-use
25+
// system properties in samevm/agentvm mode.
26+
27+
/*
28+
* @test
29+
* @bug 8367133
30+
* @summary Verify that handshake succeeds when Finished message is fragmented
31+
* @modules java.base/sun.security.util
32+
* @library /test/lib
33+
* @build DTLSOverDatagram
34+
* @run main/othervm FragmentedFinished
35+
*/
36+
37+
import javax.net.ssl.SSLEngine;
38+
import javax.net.ssl.SSLParameters;
39+
import java.net.DatagramPacket;
40+
import java.net.SocketAddress;
41+
import java.util.ArrayList;
42+
import java.util.List;
43+
44+
public class FragmentedFinished extends DTLSOverDatagram {
45+
private SSLEngine serverSSLEngine;
46+
public static void main(String[] args) throws Exception {
47+
FragmentedFinished testCase = new FragmentedFinished();
48+
testCase.runTest(testCase);
49+
}
50+
51+
@Override
52+
SSLEngine createSSLEngine(boolean isClient) throws Exception {
53+
SSLEngine sslEngine = super.createSSLEngine(isClient);
54+
if (!isClient) {
55+
serverSSLEngine = sslEngine;
56+
}
57+
return sslEngine;
58+
}
59+
60+
@Override
61+
DatagramPacket createHandshakePacket(byte[] ba, SocketAddress socketAddr) {
62+
if (ba.length < 30) { // detect ChangeCipherSpec
63+
// Reduce the maximumPacketSize to force fragmentation
64+
// of the Finished message
65+
SSLParameters params = serverSSLEngine.getSSLParameters();
66+
params.setMaximumPacketSize(53);
67+
serverSSLEngine.setSSLParameters(params);
68+
}
69+
70+
return super.createHandshakePacket(ba, socketAddr);
71+
}
72+
}

0 commit comments

Comments
 (0)