mirror of
https://github.com/bitcoin/bitcoin.git
synced 2026-09-11 21:20:39 +02:00
Merge bitcoin/bitcoin#35592: http: check rpcallowip immediately after accepting connection
55d3cd51a4doc: add release note describing change for forbidden clients (Matthew Zipkin)d1ed2a6e25http: check rpcallowip immediately after accepting connection (Matthew Zipkin) Pull request description: This is a follow-up to #35182 addressing a review comment from that PR: https://github.com/bitcoin/bitcoin/pull/35182#pullrequestreview-4322490068 This update to HTTPServer checks the IP subnet allowlist as soon as possible (immediately after receiving a connection from a client) before any data is received. This does not entirely protect the server from the "slow loris" attack or [CWE-400](https://cwe.mitre.org/data/definitions/400.html) but does restrict the attack surface to localhost and clients explicitly allowed by the user. If a client is not allowed by the list, we disconnect as soon as possible. This is a behavior change from master branch (and previous release with libevent) where `403 Forbidden` was returned (after a potentially large amount request data was written to memory by the server). To facilitate existing unit tests, this commit includes a refactor that moves the subnet allow list and relevant methods into the HTTPServer class instead of static file scope. This is needed because otherwise the allow list would be empty when the unit tests run. There is still plenty of refactoring to do in order to modernize `HTTPServer` and de-globalize it, but since this specific issue has a resource allocation guard, I wanted to open it quickly on its own. ACKs for top commit: janb84: ACK55d3cd51a4winterrdog: ACK55d3cd51a4w0xlt: ACK55d3cd51a4fjahr: Code review ACK55d3cd51a4Tree-SHA512: 545911f2e4d2f97ab8bc854e9e57c39eb896428f8c349d34c8e8025a1f6bfb8cfd436f381e36af8b87592c07df3e16210819f3eef7943e23c6626030e615fdf5
This commit is contained in:
@@ -7,6 +7,7 @@
|
||||
Roughly based on https://web.archive.org/web/20190424172231/http://voorloopnul.com/blog/a-python-netstat-in-less-than-100-lines-of-code/ by Ricardo Pascal
|
||||
"""
|
||||
|
||||
import http.client
|
||||
import sys
|
||||
import socket
|
||||
import struct
|
||||
@@ -34,6 +35,15 @@ ADDRMAN_NEW_BUCKET_COUNT = 1 << 10
|
||||
ADDRMAN_TRIED_BUCKET_COUNT = 1 << 8
|
||||
ADDRMAN_BUCKET_SIZE = 1 << 6
|
||||
|
||||
# When a test expects a server disconnection, any of these errors are
|
||||
# acceptable. The specific event is determined by race condition and platform OS.
|
||||
NETWORK_ERRORS = (
|
||||
BrokenPipeError, # write to a closed socket/pipe
|
||||
ConnectionResetError, # connection forcibly closed by peer
|
||||
ConnectionAbortedError, # connection aborted locally or by network stack
|
||||
http.client.ResponseNotReady, # server response not ready or connection out of sync
|
||||
)
|
||||
|
||||
def get_socket_inodes(pid):
|
||||
'''
|
||||
Get list of socket inodes for process pid.
|
||||
|
||||
Reference in New Issue
Block a user