diff options
author | Daiki Ueno <dueno@redhat.com> | 2019-01-19 10:31:52 +0100 |
---|---|---|
committer | Daiki Ueno <dueno@redhat.com> | 2019-01-23 17:53:56 +0100 |
commit | d73f8e1e2db3f5302fa08488233e8da0316fe88d (patch) | |
tree | 8652a1922204cd9c9a5420af456a861e19d44fc0 | |
parent | 49c6ab6f97abc1661ab72ee3add157305e72459a (diff) | |
download | gnutls-d73f8e1e2db3f5302fa08488233e8da0316fe88d.tar.gz |
constate: don't restore max_record_recv_size from resumed data
Signed-off-by: Daiki Ueno <dueno@redhat.com>
-rw-r--r-- | lib/constate.c | 11 |
1 files changed, 8 insertions, 3 deletions
diff --git a/lib/constate.c b/lib/constate.c index 11fedab533..fbbff886e9 100644 --- a/lib/constate.c +++ b/lib/constate.c @@ -738,8 +738,6 @@ int _gnutls_epoch_set_keys(gnutls_session_t session, uint16_t epoch, hs_stage_t memcpy(dst->server_random, src->server_random, GNUTLS_RANDOM_SIZE); \ dst->ext_master_secret = src->ext_master_secret; \ dst->etm = src->etm; \ - dst->max_record_recv_size = src->max_record_recv_size; \ - dst->max_record_send_size = src->max_record_send_size; \ dst->prf = src->prf; \ dst->grp = src->grp; \ dst->pversion = src->pversion; \ @@ -757,8 +755,15 @@ void _gnutls_set_resumed_parameters(gnutls_session_t session) security_parameters_st *src = &session->internals.resumed_security_parameters; security_parameters_st *dst = &session->security_parameters; + const version_entry_st *ver = get_version(session); + + CPY_COMMON(ver->tls13_sem); - CPY_COMMON(get_version(session)->tls13_sem); + if (!ver->tls13_sem && + !(session->internals.hsk_flags & HSK_RECORD_SIZE_LIMIT_NEGOTIATED)) { + dst->max_record_recv_size = src->max_record_recv_size; + dst->max_record_send_size = src->max_record_send_size; + } } /* Sets the current connection session to conform with the |