p2p: don't reset timeout timer for handshakes
What changed, and why it matters
This change fixes a peer-to-peer networking timeout behavior. Previously, the handshake timeout timer could be reset by incoming partial data, potentially allowing a remote peer to drag out the handshake indefinitely. Now, the handshake timeout is absolute: if it expires, the connection is dropped regardless of partial progress. This prevents a likely denial-of-service vector where a malicious or slow peer stalls handshakes.
Treat as a security hardening fix with DoS relevance. Users and node operators should upgrade to a release containing this commit, especially for public-facing nodes. Monitor for related advisories from the Monero project.
Security signals we found
Denial-of-service mitigation: prevents handshake timeout reset by partial traffic
Peer-to-peer protocol hardening
Timeout semantics changed from sliding to absolute for handshake
Evidence from the diff
In the async Levin protocol handler, reset_timer() is called when bytes are received. The patch adds an early return when the current command is the handshake command and reset_timer() is not the initial call, so subsequent received bytes no longer restart the timer. This makes the handshake timeout a hard deadline rather than one extended by every partial message.
Changed components
contrib/epee/include/net/levin_protocol_handler_async.hLevin async protocol handlerP2P handshake logicInspect captured patch +2 / −0
diff --git a/contrib/epee/include/net/levin_protocol_handler_async.h b/contrib/epee/include/net/levin_protocol_handler_async.h
index 4a0e565..e094f8c 100644
--- a/contrib/epee/include/net/levin_protocol_handler_async.h
+++ b/contrib/epee/include/net/levin_protocol_handler_async.h
@@ -269,6 +269,8 @@ public:
}
virtual bool reset_timer(bool first) override final
{
+ if (m_command == connection_context::handshake_command() && !first)
+ return true;
std::shared_ptr<anvoke_handler> self;
if (!m_cancel_timer_called && (self = this->weak_from_this().lock()) && (first || m_timer.cancel() > 0))
{
Why this scored 49/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.