Transport padding (s4) crashed the whole process with "index out of range" in RoutineSequentialSender on the first data packet: InputPacket/InputPackets sized elem.buffer without headroom for the in-buffer right-shift that prepends the random prefix. - send.go: reserve paddings.transport in both injection-path allocLength computations; replace the manual backward byte loop with an overlap-safe copy; defensively grow the buffer (pool-backed) if it still lacks headroom, dropping packets that cannot fit a single WG message instead of overrunning. - receive.go: drop the rxBytes/timers block duplicated by the AWG re-graft (rx accounting was doubled, keepKeyFreshReceiving fired twice per batch). - send.go: swap jmin/jmax when configured inverted (UAPI validates the fields only individually; a swapped pair panicked rand.Int with a non-positive bound on the first handshake). - obf*.go: bound obfuscator length args to [0, MaxMessageSize] (negative panicked slice bounds, huge ones OOMed the handshake). - magic-header.go: widen to int64 before end-start+1 so a full-range header cannot wrap to a zero rand.Int bound. Tests: transport_padding_test.go reproduces the on-device crash byte-for-byte (red on the previous commit, green now) across both injection paths and the tun path; obf_guards_test.go pins the config-value guards.
36 lines
604 B
Go
36 lines
604 B
Go
package device
|
|
|
|
func newDataSizeObf(val string) (obf, error) {
|
|
length, err := parseObfLen(val)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
return &dataSizeObf{
|
|
length: length,
|
|
}, nil
|
|
}
|
|
|
|
type dataSizeObf struct {
|
|
length int
|
|
}
|
|
|
|
func (o *dataSizeObf) Obfuscate(dst, src []byte) {
|
|
srcLen := len(src)
|
|
for i := o.length - 1; i >= 0; i-- {
|
|
dst[i] = byte(srcLen & 0xFF)
|
|
srcLen >>= 8
|
|
}
|
|
}
|
|
|
|
func (o *dataSizeObf) Deobfuscate(dst, src []byte) bool {
|
|
return true
|
|
}
|
|
|
|
func (o *dataSizeObf) ObfuscatedLen(srcLen int) int {
|
|
return o.length
|
|
}
|
|
|
|
func (o *dataSizeObf) DeobfuscatedLen(srcLen int) int {
|
|
return 0
|
|
}
|