Skip to content

fix: continue after a failed packet in a coalesced datagram - #2795

Closed
codeandsolder wants to merge 1 commit into
cloudflare:masterfrom
codeandsolder:upstream-pr/coalesced-packet-continue-20261004
Closed

codeandsolder wants to merge 1 commit into
cloudflare:masterfrom
codeandsolder:upstream-pr/coalesced-packet-continue-20261004

Conversation

@codeandsolder

Copy link
Copy Markdown

Fixes #2640.

Summary

When a packet in a coalesced UDP datagram is dropped with Error::Done, quiche currently consumes the entire remainder of the datagram. That can hide a later valid coalesced packet, contrary to RFC 9000 Section 12.2, which requires coalesced packets to be processed independently and requires the receiver to attempt the remaining packets after a decryption failure.

This change teaches the receive loop to recover the boundary of a failed long-header packet and advance only over that packet when the boundary is trustworthy.

  • Add packet::long_header_packet_len() to parse the long-header length field without decrypting the packet.
  • On Error::Done, use that boundary to continue with a following coalesced packet.
  • Keep the existing consume-the-rest behavior for short headers, Retry, Version Negotiation, or malformed/unknown lengths, where there is no safe packet boundary to recover.
  • Add a regression with corrupt Initial || valid Initial proving the later packet is still processed and the connection stays open. It runs under both cubic and bbr2_gcongestion through the existing rstest parameterization.

Validation

Rebased directly onto current upstream master (3fc9bc1c). On Rust 1.98.1:

cargo test -p quiche invalid_coalesced_initial_does_not_hide_valid_initial -- --nocapture

passes before the shared validation run proceeds to its later tests. Formatting with the repository's nightly rustfmt configuration and git diff --check are clean.

@codeandsolder
codeandsolder requested a review from a team as a code owner October 4, 2026 19:30
@ghedo ghedo added type: bugfix Corrects defective behavior. area: packet Changes related to packet. labels Oct 5, 2026
@ghedo

ghedo commented Oct 5, 2026

Copy link
Copy Markdown
Member

Closing as a duplicate of #2769. The packet-boundary recovery and corrupted-Initial regression are equivalent, so the same coalesced-packet fix can be reviewed in one PR. This does not supersede #1922's separate dropped-Initial-key case.

@ghedo ghedo closed this Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: packet Changes related to packet. type: bugfix Corrects defective behavior.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Coalesced datagram processing stops after one failed packet

2 participants