Skip to content

Fenrir fixes 2026 10 01 - #183

Merged
gasbytes merged 15 commits into
wolfSSL:masterfrom
danielinux:fenrir-fixes-2026-10-01
Oct 1, 2026
Merged

gasbytes merged 15 commits into
wolfSSL:masterfrom
danielinux:fenrir-fixes-2026-10-01

Conversation

@danielinux

@danielinux danielinux commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

fe18fb4 F-14492: compare bind claims, not resolved egress IPs, in the port-conflict check
b8f5ba1 F-14494: resolve the ICMP connect target before the bound-address check
974a47f F-14493: wildcard-bound sockets source from the egress interface
9d9bd9b F-14497: log wc_AesGcmEncrypt, not wc_AesGcmDecrypt, on encrypt failure
ba4f5ce F-14496: drop the dead second closed-socket guard in tcp_process_ts
29ce82f F-14491: stop flush_tcp_tx from walking the stale cursor after a pop
edfcccf F-14490: clear is_listener when the filter vetoes listen()
bd6f4a2 F-14489: skip DAD when a renew/rebind ACK keeps the in-use IP
de9ac85 F-14519: probe and time out window-blocked teardown sockets
a42f149 F-14518: retransmit the FIN and time out in TCP_CLOSING

Copilot AI balanced review requested due to automatic review settings October 1, 2026 06:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

TCP persist handling can stall teardown sockets and mishandle nonzero sub-segment receive windows.

Review effort: Balanced
Findings: 1 High severity · 3 Medium severity

Open (4)
What changed in this PR

Fixes TCP teardown/persist behavior, DHCP renewal handling, listener cleanup, and stale FIFO traversal.

Changes:

  • Improves TCP teardown retransmission, persist probing, and timeout handling.
  • Skips redundant DHCP DAD and clears rejected listener state.
  • Adds regression tests and documents unsupported TCP urgent data.
File Description
src/​wolfip.c Implements TCP, DHCP, listener, and FIFO fixes.
src/​test/​unit/​unit.c Registers new regression tests.
src/​test/​unit/​unit_tests_tcp_flow.c Tests stale FIFO cursor handling.
src/​test/​unit/​unit_tests_proto.c Tests TCP persist behavior.
src/​test/​unit/​unit_tests_dns_dhcp.c Tests listener and CLOSING behavior.
src/​test/​unit/​unit_tests_dhcp_edges.c Tests DHCP renewal/rebinding DAD behavior.
docs/​rfc9293-scope.md Documents unsupported TCP urgent data.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/wolfip.c Outdated
Comment thread src/wolfip.c
Comment thread src/wolfip.c
Comment thread src/wolfip.c

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

TCP wildcard ephemeral allocation can still create port conflicts, and rebinding accepts malformed DHCPNAKs without a server identifier.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
Resolved since last review (4)

Comment thread src/wolfip.c
Comment thread src/wolfip.c Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Nonzero-window persist probes can advance acknowledgments without retiring queued data, leaving TCP transmission permanently blocked.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
Resolved since last review (2)
Previously missed (4)

In code that hasn't changed since last review

Medium severity Stale local IP used when interfaces have no address

src/​wolfip.c:8020

If neither the routed interface nor the primary interface currently has an address, this branch leaves local_ip at its previous value. A wildcard/unbound ICMP socket that previously sent through another interface will then transmit with that stale source address instead of reflecting the current egress state.

Medium severity Persist timer is not reset when entering teardown

src/​wolfip.c:8919

Resetting only the retry count does not create the documented fresh ~183-second teardown budget: an already-active persist timer retains its established-state deadline and backoff (up to 60 seconds), so eight teardown probes can take up to 480 seconds. Reset and re-arm active persist state when entering teardown.

Medium severity LAST_ACK retains inherited persist timer backoff

src/​wolfip.c:8945

The same inherited-backoff problem applies to the LAST_ACK transition: resetting persist_retries leaves an active timer at its old deadline and persist_backoff, extending the nominal three-minute teardown budget to as much as eight minutes.

Low severity Incorrect RFC cited for IPv4 address-conflict detection

src/​test/​unit/​unit_tests_dhcp_edges.c:1440

RFC 4331 concerns WebDAV quota properties; IPv4 address-conflict detection is specified by RFC 5227, which the changed implementation correctly cites.

Comment thread src/test/unit/unit_tests_misc_edges.c Outdated

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #183

Scan targets checked: wolfip-src, wolfip-bugs
Coverage: 1 of 2 in-scope changed file(s) opened by the reviewer; not opened: src/wolfesp.c

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

@gasbytes
gasbytes self-requested a review October 1, 2026 13:57
@gasbytes gasbytes self-assigned this Oct 1, 2026
@danielinux
danielinux force-pushed the fenrir-fixes-2026-10-01 branch from dc645c5 to feeb01b Compare October 1, 2026 14:55
@gasbytes
gasbytes merged commit 4619d31 into wolfSSL:master Oct 1, 2026
47 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants