Skip to content
This repository was archived by the owner on Oct 1, 2026. It is now read-only.

tlshd: three small fixes (printf format, strtok_r, ALPN count bound) - #167

Closed
warter666 wants to merge 3 commits into
oracle:mainfrom
warter666:fix/tlshd-three-small-bugs
Closed

warter666 wants to merge 3 commits into
oracle:mainfrom
warter666:fix/tlshd-three-small-bugs

Conversation

@warter666

Copy link
Copy Markdown

Hi, thanks for the quick responses on #164, #165 and #166. This PR carries the three small fixes as three separate, independently revertable commits (each with a Signed-off-by per DCO):

  1. tlshd: fix printf format for the certificate version — gnutls_x509_crt_get_version() returns an int; print with %d instead of %u. (Fixes tlshd/tags.c: printf format mismatch (%u with signed int) #166)

  2. tlshd: use strtok_r() instead of strtok() — strtok() is not thread-safe; use the reentrant variant. (Fixes tlshd/quic.c: strtok() is not thread-safe; consider strtok_r() #164)

  3. tlshd: bound the ALPN count parsed from the configuration — quic_session_set_alpns() wrote one stack-array entry per comma-separated token with no count check; a comma-heavy alpns setting (the buffer holds up to 127 commas) overflows the fixed array. Configurations exceeding TLSHD_QUIC_MAX_ALPNS_LEN / 2 entries are now rejected with a log message. (Fixes tlshd/quic.c: quic_session_set_alpns() has no bound check on the ALPN count #165)

I saw CONTRIBUTING.md prefers patches on kernel-tls-handshake@lists.linux.dev — happy to post these there as well (would need to re-send from a real address); the git format-patch output is ready either way. GitHub PRs are also listed as acceptable, so starting here for review convenience.

Note: I could not run the full build locally (no Linux/gnutls toolchain at hand), but the changes are minimal and self-contained.

gnutls_x509_crt_get_version() returns an int, so print it with %d
instead of %u.

Fixes oracle#166

Signed-off-by: warter666 <271496918+warter666@users.noreply.github.com>
strtok() is not thread-safe; tlshd services connections from
multiple threads, so use the reentrant strtok_r().

Fixes oracle#164

Signed-off-by: warter666 <271496918+warter666@users.noreply.github.com>
quic_session_set_alpns() writes one entry per comma-separated
token into a fixed-size stack array without checking the count.
An over-long or comma-heavy alpns setting overflows it. Reject
configurations with more entries than the array can hold.

Fixes oracle#165

Signed-off-by: warter666 <271496918+warter666@users.noreply.github.com>
@oracle-contributor-agreement

Copy link
Copy Markdown

Thank you for your pull request and welcome to our community! To contribute, please sign the Oracle Contributor Agreement (OCA).
The following contributors of this PR have not signed the OCA:

To sign the OCA, please create an Oracle account and sign the OCA in Oracle's Contributor Agreement Application.

When signing the OCA, please provide your GitHub username. After signing the OCA and getting an OCA approval from Oracle, this PR will be automatically updated.

If you are an Oracle employee, please make sure that you are a member of the main Oracle GitHub organization, and your membership in this organization is public.

@oracle-contributor-agreement oracle-contributor-agreement Bot added the OCA Required At least one contributor does not have an approved Oracle Contributor Agreement. label Sep 19, 2026
@warter666

Copy link
Copy Markdown
Author

I have submitted an OCA application. Could you please approve it?

@chucklever

Copy link
Copy Markdown
Member

The OCA requirement was waived more than a year ago. I'm not sure why the bot is active on this project. I'm working internally to clear that condition. Since I'm not a project administrator I cannot approve your application myself, nor can I remove the bot.

The weekend has delayed matters. I'm hoping to get this cleared up today or tomorrow.

@warter666

Copy link
Copy Markdown
Author

Thanks for sorting that out internally — no rush on my side. The DCO sign-offs are already on all three commits, so once the bot gate is cleared the PR should be good to review.

@chucklever

Copy link
Copy Markdown
Member

I need to cut ktls-utils 1.5.0 for other reasons. The only reason your fixes won't be in that release is this OCA snafu, which doesn't look like it will be resolved quickly. Thanks for your patience while this is sorted.

@warter666

Copy link
Copy Markdown
Author

No worries at all — happy to wait. Good luck with the 1.5.0 release; the branch will still be here whenever the OCA gate gets cleared, and the three commits are independent so they can be picked up one at a time if that's easier.

@chucklever chucklever closed this Sep 25, 2026
@chucklever

Copy link
Copy Markdown
Member

Please open a new pull request in the linux-nfs/ktls-utils repo. Thanks for your patience.

@warter666

Copy link
Copy Markdown
Author

Re-opened as linux-nfs#60 per your request.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

OCA Required At least one contributor does not have an approved Oracle Contributor Agreement.

Projects

None yet

2 participants