Conversation
|
Thanks for re-posting these here. Comments per commit below, plus two All three commits
tlshd: fix printf format for the certificate version Looks good. tlshd: use strtok_r() instead of strtok() The change is fine, but the rationale in the commit message is not. tlshd: bound the ALPN count parsed from the configuration This one needs a different fix. The count check guards against a The kernel's With a properly terminated buffer, the new check cannot fire: 127 Please fix the termination instead: make One related thing you may want to handle while in this function: an |
gnutls_x509_crt_get_version() returns an int, so print it with %d instead of %u. Fixes oracle#59 Signed-off-by: Guancheng Wang <271496918+warter666@users.noreply.github.com>
tlshd forks one child process per handshake and does not link pthreads, so strtok()'s static state is never shared between threads. Prefer strtok_r() anyway to avoid hidden global state in a parser. Fixes oracle#57 Signed-off-by: Guancheng Wang <271496918+warter666@users.noreply.github.com>
20ebce7 to
f6256d0
Compare
|
All points addressed — the branch is rewritten as 4 commits (force-pushed):
Thanks for the detailed review — the unterminated-getsockopt analysis makes the failure mode much clearer than what I had. |
The kernel's QUIC_SOCKOPT_ALPN getter returns the comma-joined ALPN string without a NUL terminator, and may return up to QUIC_ALPN_MAX_LEN (128) bytes. conn->alpns was exactly that size, so a full-length value left the buffer unterminated and quic_session_set_alpns()'s strtok_r()/strlen() ran off the end of alpns[] into conn->ticket[]. Make alpns one byte larger than the kernel maximum and write a NUL at the length getsockopt() returns. Fixes oracle#58 Signed-off-by: Guancheng Wang <271496918+warter666@users.noreply.github.com>
An interior empty token such as "h3,,x" survives the kernel's parser and arrives as an empty string, which then goes to GnuTLS as a zero-length ALPN. RFC 7301 requires 1 to 255 octets, so skip empty tokens after the space-strip. Signed-off-by: Guancheng Wang <271496918+warter666@users.noreply.github.com>
f6256d0 to
1028a0f
Compare
Hi @chucklever, re-opening here as requested in oracle#167 — same three fixes, three separate (independently revertable) commits, each with a DCO
Signed-off-by:tlshd: fix printf format for the certificate version —
gnutls_x509_crt_get_version()returns anint; print with%dinstead of%u. (oracle issue: tlshd/tags.c: printf format mismatch (%u with signed int) oracle/ktls-utils#166)tlshd: use strtok_r() instead of strtok() —
strtok()is not thread-safe; use the reentrant variant. (oracle issue: tlshd/quic.c: strtok() is not thread-safe; consider strtok_r() oracle/ktls-utils#164)tlshd: bound the ALPN count parsed from the configuration —
quic_session_set_alpns()wrote one stack-array entry per comma-separated token with no count check; a comma-heavyalpnssetting overflows the fixedTLSHD_QUIC_MAX_ALPNS_LEN / 2array. Configurations exceeding the array capacity are now rejected with a log message. (oracle issue: tlshd/quic.c: quic_session_set_alpns() has no bound check on the ALPN count oracle/ktls-utils#165)