Skip to content

ssl: Buffer unsent encrypted data on send timeout - #10916

Open
zuiderkwast wants to merge 2 commits into
erlang:masterfrom
zuiderkwast:ssl-socket-backend-timeout-buffering
Open

ssl: Buffer unsent encrypted data on send timeout#10916
zuiderkwast wants to merge 2 commits into
erlang:masterfrom
zuiderkwast:ssl-socket-backend-timeout-buffering

Conversation

@zuiderkwast

@zuiderkwast zuiderkwast commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

When using gen_tcp with {inet_backend, socket} and send_timeout, gen_tcp:send may return {error, {timeout, RestData}} with the unsent encrypted data. Previously this fell through to the generic error handler which killed the connection.

Buffer the RestData in a new #rest{} record in the tls_sender state and retry sending it together with new data on the next ssl:send call. Reply {error, timeout} to the caller to simulate {inet_backend, inet} behavior.

When alerts, post-handshake data or renegotiation need to send while a #rest{} buffer exists, attempt to flush the buffer first. If the flush succeeds, proceed normally. If it times out again, postpone the event and re-buffer the remaining data.

@github-actions

github-actions Bot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

CT Test Results

    2 files     66 suites   25m 41s ⏱️
  827 tests   780 ✅  46 💤 1 ❌
4 303 runs  3 341 ✅ 961 💤 1 ❌

For more details on these failures, see this check.

Results for commit b5242b5.

♻️ This comment has been updated with latest results.

To speed up review, make sure that you have read Contributing to Erlang/OTP and that all checks pass.

See the TESTING and DEVELOPMENT HowTo guides for details about how to run test locally.

Artifacts

// Erlang/OTP Github Action Bot

@IngelaAndin IngelaAndin added team:PS Assigned to OTP team PS stalled waiting for input by the Erlang/OTP team labels Mar 25, 2026
@IngelaAndin

Copy link
Copy Markdown
Contributor

We will consider this after the OTP-29 release.

@bjorng bjorng added this to the 30.0 milestone Mar 26, 2026
When using gen_tcp with {inet_backend, socket} and send_timeout,
gen_tcp:send may return {error, {timeout, RestData}} with the unsent
encrypted data. Previously this fell through to the generic error
handler which killed the connection.

Buffer the RestData in a new #rest{} record in the tls_sender state
and retry sending it together with new data on the next ssl:send call.
Reply {error, timeout} to the caller to simulate {inet_backend, inet}
behavior.

When alerts, post-handshake data or renegotiation need to send while
a #rest{} buffer exists, attempt to flush the buffer first. If the
flush succeeds, proceed normally. If it times out again, postpone the
event and re-buffer the remaining data.

Signed-off-by: Viktor Söderqvist <viktor.soderqvist@est.tech>
@zuiderkwast
zuiderkwast force-pushed the ssl-socket-backend-timeout-buffering branch from 6009ad8 to 5763bb5 Compare July 2, 2026 13:21
Signed-off-by: Viktor Söderqvist <viktor.soderqvist@est.tech>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

stalled waiting for input by the Erlang/OTP team team:PS Assigned to OTP team PS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants