fix: continue after a failed packet in a coalesced datagram - #2795
Closed
codeandsolder wants to merge 1 commit into
Closed
codeandsolder wants to merge 1 commit into
codeandsolder wants to merge 1 commit into
Conversation
Member
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #2640.
Summary
When a packet in a coalesced UDP datagram is dropped with
Error::Done, quiche currently consumes the entire remainder of the datagram. That can hide a later valid coalesced packet, contrary to RFC 9000 Section 12.2, which requires coalesced packets to be processed independently and requires the receiver to attempt the remaining packets after a decryption failure.This change teaches the receive loop to recover the boundary of a failed long-header packet and advance only over that packet when the boundary is trustworthy.
packet::long_header_packet_len()to parse the long-header length field without decrypting the packet.Error::Done, use that boundary to continue with a following coalesced packet.corrupt Initial || valid Initialproving the later packet is still processed and the connection stays open. It runs under both cubic and bbr2_gcongestion through the existing rstest parameterization.Validation
Rebased directly onto current upstream
master(3fc9bc1c). On Rust 1.98.1:cargo test -p quiche invalid_coalesced_initial_does_not_hide_valid_initial -- --nocapturepasses before the shared validation run proceeds to its later tests. Formatting with the repository's nightly rustfmt configuration and
git diff --checkare clean.