| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Can you test Python 3.11 and main branch?
Or if you wanted us to test this you'll have to attach the cert, key and ca files that the demo program references -- I am not going to learn how to set up an SSL web server myself.
Attached is a zip file containing the necessary files.
I'll attempt to test 3.11 and main right now.
@kumaraditya303 3.11 exhibits the same behavior. It's also worth noting I also tried the ssl's library newer method for configuring versions via the ssl_ctx.minimum_version and ssl_ctx.maximum_version fields.
I suspect that only an SSL/Python expert like @tiran can help us with this...
The alert message never reaches the client because asyncio does not flush the outgoing buffer with self._process_outgoing() on SSLError. _do_shutdown has the same bug.
Someone who understands those words would need to come up with a PR. Please?
The alert message never reaches the client because asyncio does not flush the outgoing buffer with self._process_outgoing() on SSLError. _do_shutdown has the same bug.
Bless. We're using Python 3.7.14, which appears to be an older SSL implementation. I added a quick patch to ours to check the outgoing buffer and write it to the transport when handling a SSLError exception in _on_handshake_complete - and we're now successfully sending alerts.
I could do a formal PR here with the newer SSL implementation (v11) since it should be much easier with the _process_outgoing() API. I could try one for versions 7 through 10 as well.
If you could submit a PR, ideally one containing a new test that fails without the patch, that would be fantastic!
Sounds good. I'll leaving on vacation this weekend, so I'll try to get a PR up in 1-2 weeks.
Looks like @stevoleeto isn't coming from that vacation..
I think what @tiran meant is that there's a need to call self._do_flush() somewhere in
cpython/Lib/asyncio/sslproto.py
Lines 718 to 723 in 21ed1e2
| def _process_outgoing(self): | |
| if not self._ssl_writing_paused: | |
| data = self._outgoing.read() | |
| if len(data): | |
| self._transport.write(data) | |
| self._control_app_writing() |
cpython/Lib/asyncio/sslproto.py
Lines 648 to 659 in 21ed1e2
| def _do_shutdown(self): | |
| try: | |
| if not self._eof_received: | |
| self._sslobj.unwrap() | |
| except SSLAgainErrors: | |
| self._process_outgoing() | |
| except ssl.SSLError as exc: | |
| self._on_shutdown_complete(exc) | |
| else: | |
| self._process_outgoing() | |
| self._call_eof_received() | |
| self._on_shutdown_complete(None) |
| Back | FazBrowse Home | New Git URL |
Bug report
We're using the python3-uvicorn package to host a web server, and are running into an issue with TLS RFC compliance in which Fatal alerts are not being sent. The issue we're examining in particular is when the client / server cannot agree on a TLS protocol version.
Inspecting the issue further, we believe the issue is with the SSL protocol implementation in the asyncio module. Using the native Python SSL module itself we see alerts being sent, however when using asyncio we're not seeing any alerts.
As far as I'm concerned, this should be easy to reproduce. Firefox shows a "PR_END_OF_FILE_ERROR" instead of the expected "SSL_ERROR_PROTOCOL_VERSION_ALERT". I have attached the simple asyncio server I'm using to demonstrate this. Using Firefox and configuring a TLS option which is invalid with the simple server will replicate the issue.
asyncio_web.py.txt
Any help or clarity here would be greatly appreciated!
Your environment
Linked PRs