fix(protocol): always expect & validate block hash in requests (#10738)
Verify that block requests have a hash and that it's correct. This helps prevent certain races and ensure that only expected data is ever returned in response to a request. (In Syncthing prior to 1.28.1 the block hash was omitted for encrypted requests from trusted devices. This breaks compatibility with that specific config on those versions.) --------- Signed-off-by: Jakob Borg <jakob@kastelo.net>
This commit is contained in:
+13
-19
@@ -93,31 +93,25 @@ func (e encryptedModel) Request(req *Request) (RequestResponse, error) {
|
||||
}
|
||||
realSize := req.Size - blockOverhead
|
||||
realOffset := req.Offset - int64(req.BlockNo*blockOverhead)
|
||||
if realOffset < 0 {
|
||||
panic("bug: realOffset underflow")
|
||||
}
|
||||
|
||||
if req.Size < minPaddedSize {
|
||||
return nil, errors.New("short request")
|
||||
}
|
||||
|
||||
// Attempt to decrypt the block hash; it may be nil depending on what
|
||||
// type of device the request comes from. Trusted devices with
|
||||
// encryption enabled know the hash but don't bother to encrypt & send
|
||||
// it to us. Untrusted devices have the hash from the encrypted index
|
||||
// data and do send it. The model knows to only verify the hash if it
|
||||
// actually gets one.
|
||||
|
||||
var realHash []byte
|
||||
// Decrypt the block hash.
|
||||
fileKey := e.keyGen.FileKey(realName, folderKey)
|
||||
if len(req.Hash) > 0 {
|
||||
var additional [8]byte
|
||||
binary.BigEndian.PutUint64(additional[:], uint64(realOffset))
|
||||
realHash, err = decryptDeterministic(req.Hash, fileKey, additional[:])
|
||||
if err != nil {
|
||||
// "Legacy", no offset additional data?
|
||||
realHash, err = decryptDeterministic(req.Hash, fileKey, nil)
|
||||
}
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("decrypting block hash: %w", err)
|
||||
}
|
||||
var additional [8]byte
|
||||
binary.BigEndian.PutUint64(additional[:], uint64(realOffset))
|
||||
realHash, err := decryptDeterministic(req.Hash, fileKey, additional[:])
|
||||
if err != nil {
|
||||
// "Legacy", no offset additional data?
|
||||
realHash, err = decryptDeterministic(req.Hash, fileKey, nil)
|
||||
}
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("decrypting block hash: %w", err)
|
||||
}
|
||||
|
||||
// Perform that request and grab the data.
|
||||
|
||||
@@ -489,6 +489,12 @@ func (c *rawConnection) dispatcherLoop() (err error) {
|
||||
if msg.Size > MaxRequestSize {
|
||||
return newProtocolError(fmt.Errorf("request size %d exceeds maximum allowed", msg.Size), msgContext)
|
||||
}
|
||||
if len(msg.Hash) == 0 {
|
||||
// Syncthing versions older than v1.28.1 omit the hash in
|
||||
// encrypted requests from trusted devices (a rare config)
|
||||
// and will run into this.
|
||||
return newProtocolError(errors.New("request missing block hash"), msgContext)
|
||||
}
|
||||
go c.handleRequest(requestFromWire(msg))
|
||||
|
||||
case *bep.Response:
|
||||
|
||||
@@ -560,6 +560,7 @@ func TestRequestMaxSize(t *testing.T) {
|
||||
Id: 1,
|
||||
Name: "valid",
|
||||
Size: MaxRequestSize,
|
||||
Hash: []byte{42},
|
||||
}
|
||||
|
||||
res := <-c.outbox
|
||||
@@ -573,6 +574,7 @@ func TestRequestMaxSize(t *testing.T) {
|
||||
Id: 2,
|
||||
Name: "invalid",
|
||||
Size: int32(s),
|
||||
Hash: []byte{42},
|
||||
}
|
||||
|
||||
select {
|
||||
@@ -606,6 +608,7 @@ func TestRequestZeroSize(t *testing.T) {
|
||||
Id: 1,
|
||||
Name: "valid",
|
||||
Size: 0,
|
||||
Hash: []byte{42},
|
||||
}
|
||||
|
||||
select {
|
||||
@@ -632,6 +635,7 @@ func TestRequestInvalidFilename(t *testing.T) {
|
||||
Id: 1,
|
||||
Name: "../escape",
|
||||
Size: 1024,
|
||||
Hash: []byte{42},
|
||||
}
|
||||
|
||||
select {
|
||||
|
||||
Reference in New Issue
Block a user