ssh: return window credit for discarded extended data handleData subtracts the length of every data packet from the receive window, but extended data with a type code other than SSH2_EXTENDED_DATA_STDERR is then silently discarded and, since no API exists to read it, its window credit was never returned: adjustWindow only runs as a side effect of reading a stream. A peer sending extended data with an unknown type code could therefore permanently shrink the channel window, down to a complete stall of the channel. Credit the discarded bytes back through adjustWindow. adjustWindow returns io.EOF if the local side has already sent a channel close; ignore it like ReadExtended does, since an error returned here would terminate the mux read loop and tear down the whole connection. For comparison, OpenSSH rejects extended data with unexpected type codes outright and never buffers it, so the dropped bytes are simply never credited back to the misbehaving peer. Fixes golang/go#80333 Change-Id: Ia311ce3ad008e7c89ce9752f1937c91374a4e74f Reviewed-on: https://go-review.googlesource.com/c/crypto/+/802901 Reviewed-by: Mark Freeman <markfreeman@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Filippo Valsorda <filippo@golang.org> Reviewed-by: Cherry Mui <cherryyz@google.com>
This repository holds supplementary Go cryptography packages.
This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see https://go.dev/doc/contribute.
The git repository is https://go.googlesource.com/crypto.
The main issue tracker for the crypto repository is located at https://go.dev/issues. Prefix your issue with “x/crypto:” in the subject line, so it is easy to find.
Note that contributions to the cryptography package receive additional scrutiny due to their sensitive nature. Patches may take longer than normal to receive feedback.