Skip to content

fix: panic when spec omits session ticket extension - #418

Open
thesinakamali wants to merge 1 commit into
refraction-networking:masterfrom
thesinakamali:fix/tls12-session-ticket-guards
Open

thesinakamali wants to merge 1 commit into
refraction-networking:masterfrom
thesinakamali:fix/tls12-session-ticket-guards

Conversation

@thesinakamali

Copy link
Copy Markdown
Contributor

Fixes #260.

uLoadSession calls initSessionTicketExt followed by setSessionTicketToUConn for a cached TLS 1.2 session without checking that the spec actually has a session ticket extension. When sessionTicketExt is nil, initSessionTicketExt returns early, and setSessionTicketToUConn then fails its assertion with "tls: setSessionTicketExt failed: invalid state." This is reachable with default NewUConn settings for any spec that omits SessionTicketExtension. Fix by returning early and letting the connection do a full handshake.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

panic: tls: setSessionTicketExt failed: invalid state

1 participant