https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=298962

            Bug ID: 298962
           Summary: fetch(1) / libfetch: 100% CPU and no timeout when a
                    TLS server goes silent during the handshake
           Product: Base System
           Version: 15.1-RELEASE
          Hardware: amd64
                OS: Any
            Status: New
          Severity: Affects Many People
          Priority: ---
         Component: bin
          Assignee: [email protected]
          Reporter: [email protected]

Created attachment 275219
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=275219&action=edit
Detailed description of bug and patch recommendation (AI generated)

On 15.1-RELEASE-p3, fetch(1) against an https URL uses 100% of a CPU and
ignores -T if the server accepts the TCP connection and then sends nothing. It
runs until it is killed.

First seen when a network fault stalled a real TLS handshake: a fetch -T 8 ran
for over five minutes at 99% CPU.

Reproduction steps
------------------

1. In one terminal, a listener that accepts and never answers:

       nc -l -k 127.0.0.1 4433 </dev/null >/dev/null

2. In another:

       fetch -T 8 -o /dev/null https://127.0.0.1:4433/x

3. Watch it:

       top            (fetch at about 100% CPU)
       ps -o etime,time,state -p <pid>

   Expected: exits after about 8 seconds with a timeout error.
   Observed: does not exit; CPU time advances one second per second.

4. Control: the same with http:// exits after 8 seconds.


Environment
-----------

  FreeBSD 15.1-RELEASE-p3 GENERIC amd64, packaged base
  /usr/bin/fetch and /usr/lib/libfetch.so.6 from FreeBSD-fetch-15.1
  OpenSSL 3.5.6
  Same result on the host and inside a vnet jail.


Candidate Error Location and Fix
--------------------------------

I used Claude AI to analyze the source code for the likely location of the bug
and generate a possible patch to fix it. It reviewed prior fixes to the
potential location including noting that there were changes from blocking to
non-blocking I/O. In particular, the modifications to support non-blocking read
informed the proposed fix for non-blocking write.

Candidate Location
------------------

 lib/libfetch/common.c on releng/15.1.
 the handshake loop in fetch_ssl(), line 1209

See attachment for details

Candidate Patch
---------------

See attachment for suggested patch to fix the bug (Produced by AI). It was
tested.

Other Attachments
-----------------

Will add three other attachments: patch (AI produced), fetch -vv, kdump
excerpt.

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to