tls_codec: enforce the mls vector length limit in DeserializeBytes - #2461
Open
yuxi-liu-wired wants to merge 1 commit into
Open
yuxi-liu-wired wants to merge 1 commit into
yuxi-liu-wired wants to merge 1 commit into
Conversation
With the `mls` feature, variable-length vector lengths are limited to 2^30 - 1 (RFC 9420 2.1.2: only 1-, 2- and 4-byte length encodings are valid; the "11" prefix MUST be rejected). The limit was only checked by ContentLength::new, which the Read path (Deserialize) calls, but DeserializeBytes for ContentLength built the value directly. So VLBytes, VLByteVec and Vec<T>::tls_deserialize_bytes accepted an 8-byte length header, decoding a 2^30-byte vector the Read path rejects, and reporting a truncated header as EndOfStream or a DecodingError (or a debug_assert panic) instead of InvalidVectorLength. Route the bytes path through ContentLength::new as well.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
With the
mlsfeature, variable-length vector lengths are limited to 2^30 - 1. RFC 9420 2.1.2 allows only the 1-, 2- and 4-byte length encodings, and says vectors whose length starts with the11prefix (8 bytes) "MUST be rejected".quic_vec.rsenforces this inContentLength::new, but only theReadpath goes through it.DeserializeBytes for ContentLengthbuildsSelf(value)directly, so the two paths disagree:With fewer content bytes than declared, the bytes path reports
DecodingError("16 bytes were read but 1073741824 were expected")forVLBytes(and hits thedebug_assert_eq!that #2414 removes in debug builds), andEndOfStreamforVec<u8>, instead ofInvalidVectorLength.VLByteVecandVec<T>use the sameContentLengthpath.The fix calls
ContentLength::newinDeserializeBytestoo, so both paths reject the length header itself. Withoutmls,newis a no-op, so nothing changes there.Test:
mls_length_above_30_bits_is_rejectedintests/decode_bytes.rs(#[cfg(feature = "mls")]) checksVLBytes,VLByteVecandVec<u8>. It fails on master. Thetls_codec.ymlmatrix passed locally: powerset tests on stable and 1.85, wasm32/thumbv7em builds, derive tests, benches, fuzz build, fmt, clippy. I skipped the i686 job because this machine has no multilib.This PR was produced by AI agents (Claude) and reviewed by me before submission.