Reject malformed tunnel packets - #965
Open
avzamelek wants to merge 1 commit into
Open
Conversation
📝 WalkthroughWalkthroughThe tunnel packet filter now validates payload types and lengths before accessing headers. New tests cover malformed and truncated inputs and verify filtering plus warning logs. ChangesTunnel packet validation
Estimated code review effort: 2 (Simple) | ~10 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR prevents malformed
IP_TUNNEL_APPpayloads from crashing the IP tunnel packet-filtering path.The tunnel previously assumed every incoming payload was a complete IPv4 packet and indexed packet fields directly. A short, truncated, or non-bytes payload could therefore raise an
IndexErroror formatting/type error while being processed.Root cause
Tunnel._shouldFilterPacket()reads IPv4 and transport-layer fields at fixed offsets:Before this change, there was no validation that:
As a result, an incomplete payload received from the mesh could cause an exception in the tunnel receive path instead of being discarded safely.
Changes
bytes/bytearraypayloads.Security impact
Mesh payloads should be treated as untrusted input. This change prevents malformed tunnel traffic from triggering an uncaught exception in the packet filtering code, improving resilience against accidental corruption and malformed traffic from remote nodes.
This does not alter handling of valid tunnel packets or change the existing protocol/port blacklist behavior.
Validation