fix(protocol): always expect & validate block hash in requests (#10738)

Verify that block requests have a hash and that it's correct. This helps
prevent certain races and ensure that only expected data is ever
returned in response to a request.

(In Syncthing prior to 1.28.1 the block hash was omitted for encrypted
requests from trusted devices. This breaks compatibility with that
specific config on those versions.)

---------

Signed-off-by: Jakob Borg <jakob@kastelo.net>
This commit is contained in:
Jakob Borg
2026-06-11 18:51:25 +02:00
committed by GitHub
parent a5cbeeafea
commit f6428af4c8
6 changed files with 47 additions and 45 deletions
+4
View File
@@ -560,6 +560,7 @@ func TestRequestMaxSize(t *testing.T) {
Id: 1,
Name: "valid",
Size: MaxRequestSize,
Hash: []byte{42},
}
res := <-c.outbox
@@ -573,6 +574,7 @@ func TestRequestMaxSize(t *testing.T) {
Id: 2,
Name: "invalid",
Size: int32(s),
Hash: []byte{42},
}
select {
@@ -606,6 +608,7 @@ func TestRequestZeroSize(t *testing.T) {
Id: 1,
Name: "valid",
Size: 0,
Hash: []byte{42},
}
select {
@@ -632,6 +635,7 @@ func TestRequestInvalidFilename(t *testing.T) {
Id: 1,
Name: "../escape",
Size: 1024,
Hash: []byte{42},
}
select {