https://bz.apache.org/bugzilla/show_bug.cgi?id=70255

--- Comment #1 from Jim Jagielski <[email protected]> ---
Thanks for the report and the patch. The diagnosis is right: the payload was
escaped for every datagram before the MAC check, from a pool that is only
cleared when the watchdog callback returns, and the receive loop had no bound.

Fixed in r1938912, partly based on your patch. It differs in two ways: the
escape now happens after verification, so a rejected datagram allocates
nothing, and the loop handles at most 1024 datagrams per tick. The subpool is
created once per tick and cleared per datagram.

Trunk only, since the module is not in 2.4.x.

-- 
You are receiving this mail because:
You are the assignee for the bug.
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to