From 23b41bd3f350a29632bce953d5eca41fdd627d10 Mon Sep 17 00:00:00 2001 From: Dirk Date: Wed, 30 Sep 2026 18:07:15 +0200 Subject: [PATCH] Fix starttls_io() As noted in #3154 there was an unused variable `waitsleep` in `starttls_io` which was filled with argument passed \#3. The loop search for the pattern in `$2` however was the filled with another variable `nr_waits` which was pre-set to 10 (`STARTTLS_SLEEP`) This PR fixes that by - removing STARTTLS_SLEEP from this function - passing a value of 4 to this function when called *) For ~1200 xmpp tests 2 was the maximum in less than 10% of the cases, so 4 should be really safe. `starttls_postgres_dialog()` uses also `starttls_io` but it should be a safe bet when searching for the pattern `S` --- testssl.sh | 19 ++++++++++--------- 1 file changed, 10 insertions(+), 9 deletions(-) diff --git a/testssl.sh b/testssl.sh index cae9f3a..213612d 100755 --- a/testssl.sh +++ b/testssl.sh @@ -12064,13 +12064,14 @@ run_alpn() { # arg1: send string # arg2: success string: an egrep pattern -# arg3: number of loops we should read from the buffer (optional, otherwise STARTTLS_SLEEP) +# arg3: number of loops we should read from the buffer. As of 2026 we were good with max 2, see #3154 +# To be safe we're using 4 in calling starttls_io() to look for the pattern in $2 +# starttls_io() { - local nr_waits=$STARTTLS_SLEEP + local nr_waits=$3 local buffer="" local -i i - [[ -n "$3" ]] && waitsleep=$3 [[ -z "$2" ]] && echo "FIXME $((LINENO))" # If there's a sending part it's IO. Postgres sends via socket and replies via @@ -12091,7 +12092,7 @@ starttls_io() { for ((i=1; i < nr_waits; i++ )); do [[ "$DEBUG" -ge 2 ]] && echo -en "\nS: " && echo $buffer if [[ "$buffer" =~ $2 ]]; then - debugme echo " ---> reply matched \"$2\"" + debugme echo " ---> reply # $i matched \"$2\"" # the fd sometimes still seem to contain chars which confuses the following TLS handshake, trying to empty: # dd of=/dev/null bs=512 count=1 <&5 2>/dev/null return 0 @@ -12308,9 +12309,9 @@ starttls_xmpp_dialog() { namespace="jabber:client" [[ "$STARTTLS_PROTOCOL" == xmpp-server ]] && namespace="jabber:server" - starttls_io "" 'starttls(.*)features' 1 && - starttls_io "" '" 'JUSTSEND' 2 + starttls_io "" 'starttls(.*)features' 4 && + starttls_io "" '" 'JUSTSEND' 4 ret=$? debugme echo "=== finished xmpp STARTTLS dialog with ${ret} ===" return $ret @@ -12334,8 +12335,8 @@ starttls_postgres_dialog() { local starttls_init=", x00, x00 ,x00 ,x08 ,x04 ,xD2 ,x16 ,x2F" debugme echo "=== starting postgres STARTTLS dialog ===" - socksend_x "${starttls_init}" 0 && debugme echo "${debugpad}initiated STARTTLS" && - starttls_io "" S 1 && debugme echo "${debugpad}received ack (=\"S\") for STARTTLS" + socksend_x "${starttls_init}" 0 && debugme echo "${debugpad}initiated STARTTLS" && + starttls_io "" S 4 && debugme echo "${debugpad}received ack (=\"S\") for STARTTLS" ret=$? debugme echo "=== finished postgres STARTTLS dialog with ${ret} ===" return $ret