https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=298962
Bug ID: 298962
Summary: fetch(1) / libfetch: 100% CPU and no timeout when a
TLS server goes silent during the handshake
Product: Base System
Version: 15.1-RELEASE
Hardware: amd64
OS: Any
Status: New
Severity: Affects Many People
Priority: ---
Component: bin
Assignee: [email protected]
Reporter: [email protected]
Created attachment 275219
--> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=275219&action=edit
Detailed description of bug and patch recommendation (AI generated)
On 15.1-RELEASE-p3, fetch(1) against an https URL uses 100% of a CPU and
ignores -T if the server accepts the TCP connection and then sends nothing. It
runs until it is killed.
First seen when a network fault stalled a real TLS handshake: a fetch -T 8 ran
for over five minutes at 99% CPU.
Reproduction steps
------------------
1. In one terminal, a listener that accepts and never answers:
nc -l -k 127.0.0.1 4433 </dev/null >/dev/null
2. In another:
fetch -T 8 -o /dev/null https://127.0.0.1:4433/x
3. Watch it:
top (fetch at about 100% CPU)
ps -o etime,time,state -p <pid>
Expected: exits after about 8 seconds with a timeout error.
Observed: does not exit; CPU time advances one second per second.
4. Control: the same with http:// exits after 8 seconds.
Environment
-----------
FreeBSD 15.1-RELEASE-p3 GENERIC amd64, packaged base
/usr/bin/fetch and /usr/lib/libfetch.so.6 from FreeBSD-fetch-15.1
OpenSSL 3.5.6
Same result on the host and inside a vnet jail.
Candidate Error Location and Fix
--------------------------------
I used Claude AI to analyze the source code for the likely location of the bug
and generate a possible patch to fix it. It reviewed prior fixes to the
potential location including noting that there were changes from blocking to
non-blocking I/O. In particular, the modifications to support non-blocking read
informed the proposed fix for non-blocking write.
Candidate Location
------------------
lib/libfetch/common.c on releng/15.1.
the handshake loop in fetch_ssl(), line 1209
See attachment for details
Candidate Patch
---------------
See attachment for suggested patch to fix the bug (Produced by AI). It was
tested.
Other Attachments
-----------------
Will add three other attachments: patch (AI produced), fetch -vv, kdump
excerpt.
--
You are receiving this mail because:
You are the assignee for the bug.