Skip to content

okhttp: Set socket read timeout during TLS handshake - #13081

Open
ArturoSalazarB16 wants to merge 5 commits into
grpc:masterfrom
ArturoSalazarB16:arturosb
Open

ArturoSalazarB16 wants to merge 5 commits into
grpc:masterfrom
ArturoSalazarB16:arturosb

Conversation

@ArturoSalazarB16

Copy link
Copy Markdown

In OkHttpClientTransport, direct TLS connection setup calls OkHttpTlsUpgrader.upgrade(...) without configuring a socket read timeout (setSoTimeout). When a middlebox or unresponsive server completes the TCP three-way handshake and acknowledges the TLS ClientHello without sending a ServerHello or RST, sslSocket.startHandshake() blocks indefinitely in socket read. Because this.socket and asyncSink are only assigned after OkHttpTlsUpgrader.upgrade(...) returns, channel shutdown cannot close the underlying socket either, leaving the subchannel permanently stuck in CONNECTING. Configure sock.setSoTimeout(proxySocketTimeout) before OkHttpTlsUpgrader.upgrade(...) and reset it to 0 once the TLS upgrade completes, matching the timeout handling in createHttpProxySocket. Also close sock via GrpcUtil.closeQuietly(sock) in catch (Exception e) so the socket is not leaked when handshake setup fails before asyncSink.becomeConnected(...) takes ownership.

In `OkHttpClientTransport`, direct TLS connection setup calls `OkHttpTlsUpgrader.upgrade(...)` without configuring a socket read timeout (`setSoTimeout`). When a middlebox or unresponsive server completes the TCP three-way handshake and acknowledges the TLS `ClientHello` without sending a `ServerHello` or `RST`, `sslSocket.startHandshake()` blocks indefinitely in socket read. Because `this.socket` and `asyncSink` are only assigned after `OkHttpTlsUpgrader.upgrade(...)` returns, channel shutdown cannot close the underlying socket either, leaving the subchannel permanently stuck in `CONNECTING`.
Configure `sock.setSoTimeout(proxySocketTimeout)` before `OkHttpTlsUpgrader.upgrade(...)` and reset it to `0` once the TLS upgrade completes, matching the timeout handling in `createHttpProxySocket`. Also close `sock` via `GrpcUtil.closeQuietly(sock)` in `catch (Exception e)` so the socket is not leaked when handshake setup fails before `asyncSink.becomeConnected(...)` takes ownership.
@linux-foundation-easycla

linux-foundation-easycla Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: ArturoSalazarB16 / name: ArturoSalazarB16 (e643833)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant