From 78c2e20ff8d6dbe5bf32c1346b31fc6dd3a53048 Mon Sep 17 00:00:00 2001 From: Guancheng Wang <24189100307@stu.xidian.edu.cn> Date: Sun, 20 Sep 2026 00:29:35 +0800 Subject: [PATCH 1/3] tlshd: fix printf format for the certificate version gnutls_x509_crt_get_version() returns an int, so print it with %d instead of %u. Fixes #166 Signed-off-by: warter666 <271496918+warter666@users.noreply.github.com> --- src/tlshd/tags.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/tlshd/tags.c b/src/tlshd/tags.c index 1a83c7c..0491ca6 100644 --- a/src/tlshd/tags.c +++ b/src/tlshd/tags.c @@ -1433,7 +1433,7 @@ tlshd_tags_filter_type_match_x509_tbs_version(struct tlshd_tags_filter *filter, goto deinit; } - snprintf(version, sizeof(version), "%u", ret); + snprintf(version, sizeof(version), "%d", ret); res = tlshd_tags_filter_type_match_string(filter, version); tlshd_log_debug("Filter '%s' %s version '%s'", filter->fi_name, From 740c0014da52c63caeeaf550608088b1156a931b Mon Sep 17 00:00:00 2001 From: Guancheng Wang <24189100307@stu.xidian.edu.cn> Date: Sun, 20 Sep 2026 00:29:37 +0800 Subject: [PATCH 2/3] tlshd: use strtok_r() instead of strtok() strtok() is not thread-safe; tlshd services connections from multiple threads, so use the reentrant strtok_r(). Fixes #164 Signed-off-by: warter666 <271496918+warter666@users.noreply.github.com> --- src/tlshd/quic.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/src/tlshd/quic.c b/src/tlshd/quic.c index 55c36fa..38e77eb 100644 --- a/src/tlshd/quic.c +++ b/src/tlshd/quic.c @@ -360,7 +360,8 @@ static int quic_session_set_priority(gnutls_session_t session, uint32_t cipher) static int quic_session_set_alpns(gnutls_session_t session, char *alpn_data) { gnutls_datum_t alpns[TLSHD_QUIC_MAX_ALPNS_LEN / 2]; - char *alpn = strtok(alpn_data, ","); + char *saveptr = NULL; + char *alpn = strtok_r(alpn_data, ",", &saveptr); int count = 0, ret; while (alpn) { @@ -369,7 +370,7 @@ static int quic_session_set_alpns(gnutls_session_t session, char *alpn_data) alpns[count].data = (unsigned char *)alpn; alpns[count].size = strlen(alpn); count++; - alpn = strtok(NULL, ","); + alpn = strtok_r(NULL, ",", &saveptr); } ret = gnutls_alpn_set_protocols(session, alpns, count, GNUTLS_ALPN_MANDATORY); From 20ebce77b51e9abf584069c9ed30fc99ed083fd5 Mon Sep 17 00:00:00 2001 From: Guancheng Wang <24189100307@stu.xidian.edu.cn> Date: Sun, 20 Sep 2026 00:29:40 +0800 Subject: [PATCH 3/3] tlshd: bound the ALPN count parsed from the configuration quic_session_set_alpns() writes one entry per comma-separated token into a fixed-size stack array without checking the count. An over-long or comma-heavy alpns setting overflows it. Reject configurations with more entries than the array can hold. Fixes #165 Signed-off-by: warter666 <271496918+warter666@users.noreply.github.com> --- src/tlshd/quic.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/tlshd/quic.c b/src/tlshd/quic.c index 38e77eb..aeeab9f 100644 --- a/src/tlshd/quic.c +++ b/src/tlshd/quic.c @@ -367,6 +367,10 @@ static int quic_session_set_alpns(gnutls_session_t session, char *alpn_data) while (alpn) { while (*alpn == ' ') alpn++; + if (count == TLSHD_QUIC_MAX_ALPNS_LEN / 2) { + tlshd_log_error("Too many ALPNs configured"); + return -1; + } alpns[count].data = (unsigned char *)alpn; alpns[count].size = strlen(alpn); count++;