The TLS wrapping code in src/shared/protocol.c:68-115 and src/shared/transport_tls.c:80-100 treats any SSL_write/SSL_read/SSL_accept/SSL_connect return value <= 0 as a fatal error. For non-blocking or partially blocking TLS I/O, OpenSSL may return SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE, which should be retried rather than failing immediately. The current code never calls SSL_get_error(), so benign retry conditions are reported as hard failures.
Location
src/shared/protocol.c:77-84 — SSL_write() errors are treated as fatal.
src/shared/protocol.c:98-109 — SSL_read() errors are treated as fatal.
src/shared/transport_tls.c:88-97 — SSL_accept()/SSL_connect() errors are treated as fatal.
Suggested fix
After each SSL_* call that returns <= 0, call SSL_get_error().
For SSL_ERROR_WANT_READ/SSL_ERROR_WANT_WRITE, retry the operation with the appropriate file descriptor readiness check (select()/poll()).
For SSL_ERROR_SYSCALL/SSL_ERROR_SSL, log the error and abort the connection.
Severity
Medium
Category
security
This issue was automatically generated by the issue-creator agent.
## Description
The TLS wrapping code in `src/shared/protocol.c:68-115` and `src/shared/transport_tls.c:80-100` treats any `SSL_write`/`SSL_read`/`SSL_accept`/`SSL_connect` return value `<= 0` as a fatal error. For non-blocking or partially blocking TLS I/O, OpenSSL may return `SSL_ERROR_WANT_READ` or `SSL_ERROR_WANT_WRITE`, which should be retried rather than failing immediately. The current code never calls `SSL_get_error()`, so benign retry conditions are reported as hard failures.
## Location
- `src/shared/protocol.c:77-84` — `SSL_write()` errors are treated as fatal.
- `src/shared/protocol.c:98-109` — `SSL_read()` errors are treated as fatal.
- `src/shared/transport_tls.c:88-97` — `SSL_accept()`/`SSL_connect()` errors are treated as fatal.
## Suggested fix
1. After each `SSL_*` call that returns `<= 0`, call `SSL_get_error()`.
2. For `SSL_ERROR_WANT_READ`/`SSL_ERROR_WANT_WRITE`, retry the operation with the appropriate file descriptor readiness check (`select()`/`poll()`).
3. For `SSL_ERROR_SYSCALL`/`SSL_ERROR_SSL`, log the error and abort the connection.
## Severity
Medium
## Category
security
---
_This issue was automatically generated by the issue-creator agent._
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Description
The TLS wrapping code in
src/shared/protocol.c:68-115andsrc/shared/transport_tls.c:80-100treats anySSL_write/SSL_read/SSL_accept/SSL_connectreturn value<= 0as a fatal error. For non-blocking or partially blocking TLS I/O, OpenSSL may returnSSL_ERROR_WANT_READorSSL_ERROR_WANT_WRITE, which should be retried rather than failing immediately. The current code never callsSSL_get_error(), so benign retry conditions are reported as hard failures.Location
src/shared/protocol.c:77-84—SSL_write()errors are treated as fatal.src/shared/protocol.c:98-109—SSL_read()errors are treated as fatal.src/shared/transport_tls.c:88-97—SSL_accept()/SSL_connect()errors are treated as fatal.Suggested fix
SSL_*call that returns<= 0, callSSL_get_error().SSL_ERROR_WANT_READ/SSL_ERROR_WANT_WRITE, retry the operation with the appropriate file descriptor readiness check (select()/poll()).SSL_ERROR_SYSCALL/SSL_ERROR_SSL, log the error and abort the connection.Severity
Medium
Category
security
This issue was automatically generated by the issue-creator agent.