Conversation
gnutls_x509_crt_get_version() returns an int, so print it with %d instead of %u. Fixes oracle#166 Signed-off-by: warter666 <271496918+warter666@users.noreply.github.com>
strtok() is not thread-safe; tlshd services connections from multiple threads, so use the reentrant strtok_r(). Fixes oracle#164 Signed-off-by: warter666 <271496918+warter666@users.noreply.github.com>
quic_session_set_alpns() writes one entry per comma-separated token into a fixed-size stack array without checking the count. An over-long or comma-heavy alpns setting overflows it. Reject configurations with more entries than the array can hold. Fixes oracle#165 Signed-off-by: warter666 <271496918+warter666@users.noreply.github.com>
|
Thank you for your pull request and welcome to our community! To contribute, please sign the Oracle Contributor Agreement (OCA).
To sign the OCA, please create an Oracle account and sign the OCA in Oracle's Contributor Agreement Application. When signing the OCA, please provide your GitHub username. After signing the OCA and getting an OCA approval from Oracle, this PR will be automatically updated. If you are an Oracle employee, please make sure that you are a member of the main Oracle GitHub organization, and your membership in this organization is public. |
|
I have submitted an OCA application. Could you please approve it? |
|
The OCA requirement was waived more than a year ago. I'm not sure why the bot is active on this project. I'm working internally to clear that condition. Since I'm not a project administrator I cannot approve your application myself, nor can I remove the bot. The weekend has delayed matters. I'm hoping to get this cleared up today or tomorrow. |
|
Thanks for sorting that out internally — no rush on my side. The DCO sign-offs are already on all three commits, so once the bot gate is cleared the PR should be good to review. |
|
I need to cut ktls-utils 1.5.0 for other reasons. The only reason your fixes won't be in that release is this OCA snafu, which doesn't look like it will be resolved quickly. Thanks for your patience while this is sorted. |
|
No worries at all — happy to wait. Good luck with the 1.5.0 release; the branch will still be here whenever the OCA gate gets cleared, and the three commits are independent so they can be picked up one at a time if that's easier. |
|
Please open a new pull request in the linux-nfs/ktls-utils repo. Thanks for your patience. |
|
Re-opened as linux-nfs#60 per your request. |
Hi, thanks for the quick responses on #164, #165 and #166. This PR carries the three small fixes as three separate, independently revertable commits (each with a
Signed-off-byper DCO):tlshd: fix printf format for the certificate version —
gnutls_x509_crt_get_version()returns anint; print with%dinstead of%u. (Fixes tlshd/tags.c: printf format mismatch (%u with signed int) #166)tlshd: use strtok_r() instead of strtok() —
strtok()is not thread-safe; use the reentrant variant. (Fixes tlshd/quic.c: strtok() is not thread-safe; consider strtok_r() #164)tlshd: bound the ALPN count parsed from the configuration —
quic_session_set_alpns()wrote one stack-array entry per comma-separated token with no count check; a comma-heavyalpnssetting (the buffer holds up to 127 commas) overflows the fixed array. Configurations exceedingTLSHD_QUIC_MAX_ALPNS_LEN / 2entries are now rejected with a log message. (Fixes tlshd/quic.c: quic_session_set_alpns() has no bound check on the ALPN count #165)I saw CONTRIBUTING.md prefers patches on kernel-tls-handshake@lists.linux.dev — happy to post these there as well (would need to re-send from a real address); the
git format-patchoutput is ready either way. GitHub PRs are also listed as acceptable, so starting here for review convenience.Note: I could not run the full build locally (no Linux/gnutls toolchain at hand), but the changes are minimal and self-contained.