protocol: reject zero channel packet sizes - #1517
Open
sankalpsthakur wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1504. Original report by afldl.
Reject zero maximum packet sizes in CHANNEL_OPEN and CHANNEL_OPEN_CONFIRMATION before constructing a channel. A zero size cannot make progress in the channel write loops; positive sizes retain their behavior.
Regressions cover both message types at sizes 0, 1, 32768 and UINT32_MAX. They failed on untouched upstream and pass with the fix.
npm run lintpasses.Full
npm testis not green on macOS with Node.js 22.23.2: old-OpenSSH RSA integration exits 255, also reproduced upstream with OpenSSH 10.3. A miscellaneous localhost test timed out but passed with--dns-result-order=ipv4first. Optional native crypto is absent; unsupported arcfour is skipped.AI tools assisted with implementation, tests and this description.