Reject malformed tunnel packets - #965
Conversation
📝 WalkthroughWalkthroughThe tunnel packet filter now validates payload types and lengths before accessing headers. New tests cover malformed and truncated inputs and verify filtering plus warning logs. ChangesTunnel packet validation
Estimated code review effort: 2 (Simple) | ~10 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
|
|
This looks pretty reasonable to me. If you can sign the CLA and as long as CI doesn't complain about anything, this is probably good to merge. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #965 +/- ##
==========================================
+ Coverage 67.42% 67.51% +0.08%
==========================================
Files 25 25
Lines 4762 4774 +12
==========================================
+ Hits 3211 3223 +12
Misses 1551 1551
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Summary
This PR prevents malformed
IP_TUNNEL_APPpayloads from crashing the IP tunnel packet-filtering path.The tunnel previously assumed every incoming payload was a complete IPv4 packet and indexed packet fields directly. A short, truncated, or non-bytes payload could therefore raise an
IndexErroror formatting/type error while being processed.Root cause
Tunnel._shouldFilterPacket()reads IPv4 and transport-layer fields at fixed offsets:Before this change, there was no validation that:
As a result, an incomplete payload received from the mesh could cause an exception in the tunnel receive path instead of being discarded safely.
Changes
bytes/bytearraypayloads.Security impact
Mesh payloads should be treated as untrusted input. This change prevents malformed tunnel traffic from triggering an uncaught exception in the packet filtering code, improving resilience against accidental corruption and malformed traffic from remote nodes.
This does not alter handling of valid tunnel packets or change the existing protocol/port blacklist behavior.
Validation