srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/tests/test_quic.cpp
diff options
context:
space:
mode:
Diffstat (limited to 'tests/test_quic.cpp')
-rw-r--r--tests/test_quic.cpp19
1 files changed, 19 insertions, 0 deletions
diff --git a/tests/test_quic.cpp b/tests/test_quic.cpp
index 2366176..4b02be5 100644
--- a/tests/test_quic.cpp
+++ b/tests/test_quic.cpp
@@ -78,6 +78,25 @@ TEST_CASE("parse_quic rejects a long-header packet whose DCID length exceeds the
CHECK_FALSE(parse_quic(bytes).has_value());
}
+TEST_CASE("parse_quic rejects a DCID/SCID length past RFC 9000's 20-byte cap even with room in "
+ "the buffer") {
+ // A real protocol bound, not a buffer-size check: plenty of bytes
+ // are available here, the claimed length is just illegal for this
+ // QUIC version. This is what actually stops a mid-record TLS
+ // ciphertext continuation fragment (effectively random bytes to
+ // this parser, since this project doesn't reassemble TCP by
+ // default) from occasionally passing as a plausible QUIC header --
+ // found via live capture against real cloudflare.com traffic, not
+ // by inspection.
+ std::vector<unsigned char> bytes = {0xC0, 0x00, 0x00, 0x00, 0x01, 21};
+ bytes.resize(bytes.size() + 21, 0xAA); // plenty of room for a 21-byte DCID
+ CHECK_FALSE(parse_quic(bytes).has_value());
+
+ std::vector<unsigned char> scid_bytes = {0xC0, 0x00, 0x00, 0x00, 0x01, 0, 21};
+ scid_bytes.resize(scid_bytes.size() + 21, 0xAA); // plenty of room for a 21-byte SCID
+ CHECK_FALSE(parse_quic(scid_bytes).has_value());
+}
+
TEST_CASE("QuicDissector claims port 443 and formats an Initial packet") {
QuicDissector dissector;
CHECK(dissector.port() == kQuicPort);