Severity: medium Category: security Location:src/server/server.c:65-90, src/shared/protocol.c:92-115
Description:
The TCP server accepts every incoming connection and immediately fork()s a child process in src/shared/transport_tcp.c:81. There is no limit on concurrent connections, no connection timeout, and no rate limiting. An unauthenticated attacker can open many slow or idle connections to exhaust process slots, memory, or file descriptors (fork bomb / slowloris).
This is related to the timeouts feature request but is tracked here as a security hardening item.
Suggested fix:
Set socket-level timeouts (SO_RCVTIMEO, SO_SNDTIMEO) or use poll() with a timeout in all receive_n_data/send_n_data loops.
Limit the number of concurrent child processes (e.g., semaphore or counter) and reject or queue additional connections.
Optionally enable SO_KEEPALIVE and TCP_USER_TIMEOUT.
Log abnormal connection counts.
Labels: security, dos, threading
**Severity:** medium
**Category:** security
**Location:** `src/server/server.c:65-90`, `src/shared/protocol.c:92-115`
**Description:**
The TCP server accepts every incoming connection and immediately `fork()`s a child process in `src/shared/transport_tcp.c:81`. There is no limit on concurrent connections, no connection timeout, and no rate limiting. An unauthenticated attacker can open many slow or idle connections to exhaust process slots, memory, or file descriptors (fork bomb / slowloris).
This is related to the timeouts feature request but is tracked here as a security hardening item.
**Suggested fix:**
1. Set socket-level timeouts (`SO_RCVTIMEO`, `SO_SNDTIMEO`) or use `poll()` with a timeout in all `receive_n_data`/`send_n_data` loops.
2. Limit the number of concurrent child processes (e.g., semaphore or counter) and reject or queue additional connections.
3. Optionally enable `SO_KEEPALIVE` and `TCP_USER_TIMEOUT`.
4. Log abnormal connection counts.
**Labels:** security, dos, threading
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity: medium
Category: security
Location:
src/server/server.c:65-90,src/shared/protocol.c:92-115Description:
The TCP server accepts every incoming connection and immediately
fork()s a child process insrc/shared/transport_tcp.c:81. There is no limit on concurrent connections, no connection timeout, and no rate limiting. An unauthenticated attacker can open many slow or idle connections to exhaust process slots, memory, or file descriptors (fork bomb / slowloris).This is related to the timeouts feature request but is tracked here as a security hardening item.
Suggested fix:
SO_RCVTIMEO,SO_SNDTIMEO) or usepoll()with a timeout in allreceive_n_data/send_n_dataloops.SO_KEEPALIVEandTCP_USER_TIMEOUT.Labels: security, dos, threading