Files
fips/src/control/snapshots/show_status.json
T
Johnathan Corgan 1d589f61e1 Bound the coordinate-cache warm path by the encrypted-header parser
A SessionDatagram carrying a truncated inner FSP payload panicked the
forwarding path. The warm path sliced the inner payload at the full
12-byte header offset while guarding only with the 4-byte common prefix
parser, so an inner payload of 4 to 11 bytes with phase 0x0 and the
Coords Present flag set indexed past the end of the slice. The receive
loop is the process's main future, so the panic terminated the daemon
rather than a task, and under the packaged systemd unit the node
restarted into the same frame.

Apply the same FspEncryptedHeader guard the local-delivery path already
used. That also drops a malformed frame carrying a non-zero protocol
version or the Unencrypted flag alongside Coords Present, rather than
reading its body as coordinates.

Any peer that had completed a link handshake could trigger this, and
admission is default-open.

Count the frames the coordinate-cache warm path abandons

The warm path drops a malformed encrypted frame silently apart from one
debug line, so a node being probed with them looks identical to a quiet
one. Add a counter pair for the abandoned frame and surface it.

The counter is deliberately not a forwarding rejection. The warm helper
returns nothing and runs ahead of both the delivery and TTL decisions, so
the frame goes on to be delivered or forwarded exactly as before; routing
it through the reject path would book a packet as dropped that was not.
The debug line now also carries the version and flags it parsed, which is
what distinguishes a truncated frame from one with an unexpected header.

The counter is tested by driving the drop and asserting it moved, and the
status pane row is tested the same way.
2026-08-13 21:13:10 +00:00

64 lines
1.8 KiB
JSON

{
"data": {
"connection_count": 0,
"control_socket": "<redacted>",
"effective_ipv6_mtu": 1203,
"estimated_mesh_size": null,
"exe_path": "<redacted>",
"forwarding": {
"decode_error_bytes": 0,
"decode_error_packets": 0,
"delivered_bytes": 0,
"delivered_packets": 0,
"drop_mtu_exceeded_bytes": 0,
"drop_mtu_exceeded_packets": 0,
"drop_no_route_bytes": 0,
"drop_no_route_packets": 0,
"drop_send_error_bytes": 0,
"drop_send_error_packets": 0,
"forwarded_bytes": 0,
"forwarded_packets": 0,
"originated_bytes": 0,
"originated_packets": 0,
"received_bytes": 0,
"received_packets": 0,
"route_crosslink_ascend": 0,
"route_crosslink_descend": 0,
"route_direct_peer": 0,
"route_tree_down": 0,
"route_tree_down_cross": 0,
"route_tree_up": 0,
"ttl_exhausted_bytes": 0,
"ttl_exhausted_packets": 0,
"warm_malformed_bytes": 0,
"warm_malformed_packets": 0
},
"ipv6_addr": "fd1b:4788:b7ab:7a43:6a61:1fc5:9fb1:e34c",
"is_leaf_only": false,
"is_root": true,
"link_count": 0,
"node_addr": "1b4788b7ab7a436a611fc59fb1e34c6e",
"npub": "npub1sx42mj99aql52aklsg70y2jmr95u7uz2p40k769aw46ppjv302kqkhmu5r",
"peer_count": 0,
"persistent": false,
"pid": "<redacted>",
"root": "1b4788b7ab7a436a611fc59fb1e34c6e",
"session_count": 0,
"sparklines": {
"bytes_in": [],
"bytes_out": [],
"loss_rate": [],
"mesh_size": [],
"peer_count": [],
"tree_depth": []
},
"state": "created",
"transport_count": 0,
"transport_peer_counts": {},
"tun_name": "<redacted>",
"tun_state": "disabled",
"uptime_secs": "<redacted>",
"version": "<redacted>"
},
"status": "ok"
}