[
https://issues.apache.org/jira/browse/THRIFT-5779?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18120340#comment-18120340
]
Sylwester Lachiewicz commented on THRIFT-5779:
----------------------------------------------
Still reproducible on master, though not through a port scan: on current Linux
and macOS, a connection reset before accept() is still accepted. What stops the
server is accept() failing with EMFILE when the process runs out of
descriptors: acceptImpl() throws UNKNOWN and TServerFramework::serve() returns,
and the server stays down after descriptors free up. [PR
#3977|https://github.com/apache/thrift/pull/3977] waits that out and goes back
to poll() for errors that belong to a single connection; other errors still
stop the server. It replaces [PR
#2964|https://github.com/apache/thrift/pull/2964], which retried every error
immediately.
> Thrift server getting killed for incomplete requests
> -----------------------------------------------------
>
> Key: THRIFT-5779
> URL: https://issues.apache.org/jira/browse/THRIFT-5779
> Project: Thrift
> Issue Type: Bug
> Components: C++ - Library
> Affects Versions: 0.12.0
> Reporter: Anshul Mohan Gupta
> Assignee: Anshul Mohan Gupta
> Priority: Major
> Time Spent: 1h 10m
> Remaining Estimate: 0h
>
> The thrift server is getting killed when using security port scan tools in
> the hosts running the thrift server. These tools try to connect to the open
> ports by sending requests to the ports, and the error can happen when accept
> syscall call, waiting for an incoming connection, or receiving a connection
> that terminates before the accept process completes, hence killing the thrift
> server. This can cause potential DoS (Denial of service) attacks on the
> applications running the thrift server, causing them to become unresponsive.
> Sometimes, even just running the netcat (nc -zvvvw2 <hostname> <thrift server
> port>) on the port remote can kill the entire thrift server, making it
> unresponsive.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)