GnuTLS | Doesn't handle short returns from recvmsg() on FreeBSD using KTLS (#1909)
Read-only notification of GnuTLS library development activities <[email protected]> Fri, 19 Jun 2026 15:05:19 +0000
| Newsgroups | gmane.comp.encryption.gpg.gnutls.devel |
|---|---|
| Message-ID | <[email protected]> |
--===============9200433077307751077==
Content-Type: multipart/alternative;
boundary="--==_mimepart_6a355aaf7796c_37196f68931f8";
charset=UTF-8
Content-Transfer-Encoding: 7bit
----==_mimepart_6a355aaf7796c_37196f68931f8
Content-Type: text/plain;
charset=UTF-8
Content-Transfer-Encoding: 7bit
Issue created by -bat_: https://gitlab.com/gnutls/gnutls/-/work_items/1909
[ Should say upfront I used Claude to find this, but the bug appears genuine, and there is a file attached which demonstrates it. This PR was written by a human :-) ]
When using KTLS the library appears to expect that recvmsg() will either return the whole record, or EMSGSIZE if the buffer is too short. But on FreeBSD if you pass in a small buffer then it will quite happily pass you back out a partial record, and you get the rest on subsequent calls. But those calls are just returning the rest of the original message, and dont have control headers.
I found this by trying to read 5 bytes, to look for 'HTTP/' in the response from a web server. Works fine normally, but when I enable KTLS, it breaks.
--
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1909
You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/5-2li04lgmlzgy8u98jmmixu8vc-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help
----==_mimepart_6a355aaf7796c_37196f68931f8
Content-Type: text/html;
charset=UTF-8
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www=
.w3.org/TR/REC-html40/loose.dtd">
<html lang=3D"en" style=3D'--code-editor-font: var(--default-mono-font, "=
GitLab Mono"), JetBrains Mono, Menlo, DejaVu Sans Mono, Liberation Mono, =
Consolas, Ubuntu Mono, Courier New, andale mono, lucida console, monospac=
e;'>
<head>
<meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-Type">=
<title>
GitLab
</title>
<style data-premailer=3D"ignore" type=3D"text/css">
a { color: #1068bf; }
</style>
<style>img {
max-width: 100%; height: auto;
}
body {
font-size: .875rem;
}
body {
-webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px;
}
body {
font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Ro=
boto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Colo=
r Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"; font-size=
: inherit;
}
</style>
</head>
<body style=3D'font-size: inherit; -webkit-text-shadow: hsla(0,0%,100%,.0=
1) 0 0 1px; font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"=
Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif=
,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji=
";'>
<div class=3D"content">
<p class=3D"details" style=3D"font-style: italic; color: #626168;">
Issue created by <a href=3D"https://gitlab.com/minusbat">-bat.</a>: <a hr=
ef=3D"https://gitlab.com/gnutls/gnutls/-/work_items/1909">#1909</a>
</p>
<div class=3D"md" style=3D"position: relative; z-index: 1; color: #3a383f=
; word-wrap: break-word;">
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">[ Should say upfront I used Claude to find this, but the bug app=
ears genuine, and there is a file attached which demonstrates it. This PR=
was written by a human :-) ]</p>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">When using KTLS the library appears to expect that recvmsg() wil=
l either return the whole record, or EMSGSIZE if the buffer is too short.=
But on FreeBSD if you pass in a small buffer then it will quite happily =
pass you back out a partial record, and you get the rest on subsequent ca=
lls. But those calls are just returning the rest of the original message,=
and dont have control headers.</p>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px;" align=3D"initial">=
I found this by trying to read 5 bytes, to look for 'HTTP/' in the respon=
se from a web server. Works fine normally, but when I enable KTLS, it bre=
aks.</p>
</div>
</div>
<div class=3D"footer" style=3D"margin-top: 10px;">
<p style=3D"font-size: small; color: #626168;">
=E2=80=94
<br>
Reply to this email directly or <a href=3D"https://gitlab.com/gnutls/gnut=
ls/-/work_items/1909">view it on GitLab</a>.
<br>
You're receiving this email because of your account on <a target=3D"_blan=
k" rel=3D"noopener noreferrer" href=3D"https://gitlab.com">gitlab.com</a>=
. <a href=3D"https://gitlab.com/-/namespace/17175643/sent_notifications/5=
-2li04lgmlzgy8u98jmmixu8vc-a84t7/unsubscribe" target=3D"_blank" rel=3D"no=
opener noreferrer">Unsubscribe</a> from this thread =C2=B7 <a href=3D"htt=
ps://gitlab.com/-/profile/notifications" target=3D"_blank" rel=3D"noopene=
r noreferrer" class=3D"mng-notif-link">Manage all notifications</a> =C2=B7=
<a href=3D"https://gitlab.com/help" target=3D"_blank" rel=3D"noopener no=
referrer" class=3D"help-link">Help</a>
<span style=3D"color: transparent; font-size: 0; display: none; overflow:=
hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0;">
Notification message regarding https://gitlab.com/gnutls/gnutls/-/work_it=
ems/1909 at 1781881519
</span>
<script type=3D"application/ld+json">{"@context":"http://schema.org","@ty=
pe":"EmailMessage","action":{"@type":"ViewAction","name":"View Work item"=
,"url":"https://gitlab.com/gnutls/gnutls/-/work_items/1909"}}</script>
</p>
</div>
</body>
</html>
----==_mimepart_6a355aaf7796c_37196f68931f8--
--===============9200433077307751077==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Gnutls-devel mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnutls-devel
--===============9200433077307751077==--