Files
fips/src/node/handlers
Johnathan Corgan cfee2ccde5 Drop frames whose header disagrees with the frame that arrived
The received frame header declares a payload length that nothing read. It now
gets compared against the frame the transport actually delivered, at the one
dispatch point every transport converges on, before that field can be used as
a parsing input.

This changes behaviour on a deployed line, so it is worth being exact about
what it drops. The stream transports read their frame boundary out of this
same field, so the comparison holds by construction and never fires for them.
The datagram transports deliver one whole frame per packet, where the length
is known exactly and nothing checked it before. A short read there is a
truncated frame, which already failed the tag or the exact-size parse; this
changes which reason it is dropped for, not whether it is dropped.

An unrecognised phase carries no fixed relationship, so it is left alone and
reaches the dispatch as before, rather than being rejected on a guess.

The drop gets its own rejection reason and its own counter. Reusing the
admission reason would have mis-attributed it: this is a framing rejection
decided before the phase dispatch, and it applies to data frames as well as
handshakes.

The dispatch function is now visible to the rest of the node module so a test
can drive one packet through it, which is the reach the handshake handlers
beside it already had.
2026-08-16 16:34:40 +00:00
..