Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion lib/net.js
Original file line number Diff line number Diff line change
Expand Up @@ -2826,7 +2826,10 @@ function onconnection(err, clientHandle) {
const remoteInfo = { __proto__: null };
clientHandle.getpeername(remoteInfo);
const addressType = isIP(remoteInfo.address);
if (addressType && self.blockList.check(remoteInfo.address, `ipv${addressType}`)) {
// Fail closed: if a BlockList is configured but the peer address cannot
// be obtained (e.g. the connection was reset before getpeername()),
// refuse the connection instead of silently bypassing the access control.
if (!addressType || self.blockList.check(remoteInfo.address, `ipv${addressType}`)) {
clientHandle.close();
return;
}
Expand Down
33 changes: 33 additions & 0 deletions test/parallel/test-net-server-blocklist-fail-closed.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
'use strict';
const common = require('../common');
const net = require('net');

const blockList = new net.BlockList();
blockList.addCIDR('0.0.0.0/0');
blockList.addCIDR('::/0');

// A connection whose peer address cannot be determined (e.g. it was reset
// before getpeername()) must be rejected when a BlockList is configured,
// rather than being delivered to the application (fail closed).
const server = net.createServer({ blockList }, common.mustNotCall());

server.listen(0, common.mustCall(() => {
const socket = net.connect(server.address().port);
socket.on('error', () => {});
}));

const onconnection = server._handle.onconnection;
server._handle.onconnection = common.mustCall((err, clientHandle) => {
const close = clientHandle.close;
// Simulate the reset-before-getpeername() condition: onconnection() is
// unable to obtain a valid peer address from the accepted connection.
clientHandle.getpeername = function(remoteInfo) {
remoteInfo.address = undefined;
};
clientHandle.close = common.mustCall(() => {
clientHandle.close = close;
close.call(clientHandle);
server.close();
});
onconnection.call(server._handle, err, clientHandle);
});
Loading