Skip to content

Commit 8e2fd59

Browse files
committed
qir-failures
1 parent be60d6c commit 8e2fd59

6 files changed

Lines changed: 80 additions & 27 deletions

File tree

lib/roles/quic/ops-quic.c

Lines changed: 62 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -1148,28 +1148,6 @@ rops_handle_POLLIN_quic(struct lws_context_per_thread *pt, struct lws *wsi,
11481148
break;
11491149
}
11501150

1151-
/* Check reserved bits AFTER unmasking! */
1152-
if (p[0] & 0x80) {
1153-
/* Long header: Bits 0x0c MUST be zero */
1154-
if (p[0] & 0x0c) {
1155-
lwsl_wsi_notice(wsi, "QUIC RX: Reserved bits non-zero in long header");
1156-
if (nwsi && nwsi != wsi) {
1157-
lws_quic_enter_closing_state(nwsi, LWS_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0);
1158-
goto next_packet;
1159-
}
1160-
return LWS_HPI_RET_PLEASE_CLOSE_ME;
1161-
}
1162-
} else {
1163-
/* Short header: Bits 0x18 MUST be zero */
1164-
if (p[0] & 0x18) {
1165-
lwsl_wsi_notice(wsi, "QUIC RX: Reserved bits non-zero in short header");
1166-
if (nwsi && nwsi != wsi) {
1167-
lws_quic_enter_closing_state(nwsi, LWS_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0);
1168-
goto next_packet;
1169-
}
1170-
return LWS_HPI_RET_PLEASE_CLOSE_ME;
1171-
}
1172-
}
11731151

11741152
/*
11751153
* Reconstruct full 62-bit PN.
@@ -1221,6 +1199,29 @@ rops_handle_POLLIN_quic(struct lws_context_per_thread *pt, struct lws *wsi,
12211199
goto next_packet;
12221200
}
12231201

1202+
/* Check reserved bits AFTER successful AEAD decryption (RFC 9000 5.4.1 & 12.2) */
1203+
if (p[0] & 0x80) {
1204+
/* Long header: Bits 0x0c MUST be zero */
1205+
if (p[0] & 0x0c) {
1206+
lwsl_wsi_notice(wsi, "QUIC RX: Reserved bits non-zero in long header");
1207+
if (nwsi && nwsi != wsi) {
1208+
lws_quic_enter_closing_state(nwsi, LWS_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0);
1209+
goto next_packet;
1210+
}
1211+
return LWS_HPI_RET_PLEASE_CLOSE_ME;
1212+
}
1213+
} else {
1214+
/* Short header: Bits 0x18 MUST be zero */
1215+
if (p[0] & 0x18) {
1216+
lwsl_wsi_notice(wsi, "QUIC RX: Reserved bits non-zero in short header");
1217+
if (nwsi && nwsi != wsi) {
1218+
lws_quic_enter_closing_state(nwsi, LWS_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0);
1219+
goto next_packet;
1220+
}
1221+
return LWS_HPI_RET_PLEASE_CLOSE_ME;
1222+
}
1223+
}
1224+
12241225
/* Decryption succeeded! Commit key update if pending */
12251226
if (is_key_update) {
12261227
lws_quic_keys_release_aead_rx(k);
@@ -1318,7 +1319,7 @@ rops_handle_POLLIN_quic(struct lws_context_per_thread *pt, struct lws *wsi,
13181319
buf_old, (unsigned int)ntohs(port_old),
13191320
buf_new, (unsigned int)ntohs(port_new));
13201321
#endif
1321-
/* F-60: Do NOT commit nwsi->udp->sa46 yet! Wait for PATH_RESPONSE! */
1322+
nwsi->quic.qn->rx_has_non_probing = 0;
13221323
nwsi->quic.qn->probing_sa46 = migration_sa46;
13231324
nwsi->quic.qn->probing_sa46_valid = 1;
13241325

@@ -1400,6 +1401,44 @@ rops_handle_POLLIN_quic(struct lws_context_per_thread *pt, struct lws *wsi,
14001401
nwsi = lws_get_quic_network_wsi(nwsi);
14011402
}
14021403

1404+
/* RFC 9000 Section 9.3: Receiving non-probing frames (STREAM, ACK, etc.) from a new address
1405+
* indicates that the peer has migrated (e.g. due to NAT rebinding or active client migration).
1406+
* The server MUST commit its active path to the new address. */
1407+
if (nwsi && nwsi->quic.qn && nwsi->quic.qn->is_server &&
1408+
nwsi->quic.qn->probing_sa46_valid && nwsi->quic.qn->rx_has_non_probing) {
1409+
char buf_old[64], buf_new[64];
1410+
uint16_t port_old, port_new;
1411+
lws_sa46_write_numeric_address(&nwsi->udp->sa46, buf_old, sizeof(buf_old));
1412+
lws_sa46_write_numeric_address(&nwsi->quic.qn->probing_sa46, buf_new, sizeof(buf_new));
1413+
#if defined(LWS_WITH_IPV6)
1414+
port_old = nwsi->udp->sa46.sa4.sin_family == AF_INET ? nwsi->udp->sa46.sa4.sin_port : nwsi->udp->sa46.sa6.sin6_port;
1415+
port_new = nwsi->quic.qn->probing_sa46.sa4.sin_family == AF_INET ? nwsi->quic.qn->probing_sa46.sa4.sin_port : nwsi->quic.qn->probing_sa46.sa6.sin6_port;
1416+
#else
1417+
port_old = nwsi->udp->sa46.sa4.sin_port;
1418+
port_new = nwsi->quic.qn->probing_sa46.sa4.sin_port;
1419+
#endif
1420+
lwsl_notice("QUIC Server: Connection Migration committed via non-probing packet! Peer address updated from %s:%u to %s:%u\n",
1421+
buf_old, (unsigned int)ntohs(port_old),
1422+
buf_new, (unsigned int)ntohs(port_new));
1423+
1424+
nwsi->udp->sa46 = nwsi->quic.qn->probing_sa46;
1425+
nwsi->quic.qn->probing_sa46_valid = 0;
1426+
1427+
/* Reset Congestion Control State (RFC 9000 9.3.3) */
1428+
if (nwsi->quic.qn->cc_ops && nwsi->quic.qn->cc_ops->init)
1429+
nwsi->quic.qn->cc_ops->init(nwsi);
1430+
1431+
/* Reset RTT estimator */
1432+
nwsi->quic.qn->smoothed_rtt = 0;
1433+
nwsi->quic.qn->rttvar = 0;
1434+
nwsi->quic.qn->latest_rtt = 0;
1435+
1436+
/* Reset PMTUD */
1437+
nwsi->quic.qn->current_mtu = 1280;
1438+
nwsi->quic.qn->probed_mtu = 1380;
1439+
nwsi->quic.qn->pmtud_state = 1;
1440+
}
1441+
14031442
if (nwsi) {
14041443
struct lws *w = nwsi->mux.child_list;
14051444
while (w) {

lib/roles/quic/parse-quic.c

Lines changed: 13 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -543,6 +543,14 @@ lws_quic_parse_frames(struct lws *nwsi, int level, uint8_t *payload, size_t payl
543543
if (!consumed) return -1;
544544
pos += consumed;
545545

546+
/* Track non-probing frames (RFC 9000 Section 9.1) */
547+
if (qn && type != LWS_QUIC_FT_PADDING &&
548+
type != LWS_QUIC_FT_PATH_CHALLENGE &&
549+
type != LWS_QUIC_FT_PATH_RESPONSE &&
550+
type != LWS_QUIC_FT_NEW_CONNECTION_ID) {
551+
qn->rx_has_non_probing = 1;
552+
}
553+
546554
/* Epoch Gating (RFC 9000 12.5) */
547555
int is_allowed = 0;
548556
switch (type) {
@@ -1672,13 +1680,16 @@ lws_quic_parse_transport_parameters(struct lws *wsi, const uint8_t *buf, size_t
16721680
}
16731681

16741682
if (port > 0) {
1683+
const char *host_str = (qn->nwsi && qn->nwsi->stash && qn->nwsi->stash->cis[CIS_HOST]) ?
1684+
qn->nwsi->stash->cis[CIS_HOST] : addr_str;
1685+
16751686
lwsl_wsi_notice(wsi, "QUIC TP: Migrating to preferred_address %s:%d", addr_str, port);
16761687
memset(&i, 0, sizeof(i));
16771688
i.context = wsi->a.context;
16781689
i.vhost = wsi->a.vhost;
16791690
i.address = addr_str;
1680-
i.host = addr_str;
1681-
i.origin = addr_str;
1691+
i.host = host_str;
1692+
i.origin = host_str;
16821693
i.port = port;
16831694
i.ssl_connection = LCCSCF_USE_SSL | LCCSCF_ALLOW_INSECURE;
16841695
i.quic_migrate_from_wsi = qn->nwsi;

lib/roles/quic/private-lib-roles-quic.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -316,6 +316,7 @@ struct lws_quic_netconn {
316316
struct lws *migration_probing_wsi;
317317
lws_sockaddr46 probing_sa46;
318318
uint8_t probing_sa46_valid:1;
319+
uint8_t rx_has_non_probing:1;
319320

320321
/* ECN (Explicit Congestion Notification) */
321322
uint64_t ecn_rx_ect0;

lib/tls/openssl/openssl-client.c

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -708,13 +708,11 @@ lws_tls_client_create_vhost_context(struct lws_vhost *vh,
708708
)
709709
{
710710
struct lws_tls_client_reuse *tcr;
711-
X509_STORE *x509_store;
712711
unsigned long error;
713712
SSL_METHOD *method;
714713
EVP_MD_CTX *mdctx;
715714
unsigned int len;
716715
uint8_t hash[32];
717-
X509 *client_CA;
718716
char c;
719717
int n;
720718

lib/tls/private-lib-tls.h

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -249,12 +249,14 @@ lws_tls_check_all_cert_lifetimes(struct lws_context *context);
249249
LWS_VISIBLE int
250250
lws_tls_cert_get_x509_remaining(struct lws_context *context, const char *filepath, int *days_left, int *total_days);
251251

252+
#if defined(LWS_WITH_NETWORK) && defined(LWS_WITH_CLIENT)
252253
int
253254
lws_tls_client_vhost_extra_cert_mem(struct lws_vhost *vh, const uint8_t *der, size_t len);
254255

255256
int
256257
lws_tls_client_vhost_ca_mem_parse(struct lws_vhost *vh, const void *ca_mem,
257258
unsigned int ca_mem_len);
259+
#endif
258260

259261
int
260262
lws_tls_alloc_pem_to_der_file(struct lws_context *context, const char *filename,

lib/tls/tls.c

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -597,6 +597,7 @@ lws_tls_alloc_pem_to_der_file(struct lws_context *context, const char *filename,
597597
return 4;
598598
}
599599

600+
#if defined(LWS_WITH_NETWORK) && defined(LWS_WITH_CLIENT)
600601
int
601602
lws_tls_client_vhost_ca_mem_parse(struct lws_vhost *vh, const void *ca_mem,
602603
unsigned int ca_mem_len)
@@ -659,6 +660,7 @@ lws_tls_client_vhost_ca_mem_parse(struct lws_vhost *vh, const void *ca_mem,
659660
lwsl_info("%s: loaded %d CA cert(s) from ca_mem\n", __func__, count);
660661
return 0;
661662
}
663+
#endif
662664

663665
#endif
664666

0 commit comments

Comments
 (0)