From: Amaury Denoyelle Date: Fri, 29 Aug 2025 12:17:44 +0000 (+0200) Subject: BUG/MINOR: quic: fix room check if padding requested X-Git-Tag: v3.3-dev8~40 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=34d5bfd23c30e08228d7939ba94a839b03716489;p=thirdparty%2Fhaproxy.git BUG/MINOR: quic: fix room check if padding requested qc_prep_pkts() activates padding when building an Initial packet. This ensures that resulting datagram will always be at least 1.200 bytes, which is mandatory to prevent deadlock over anti-amplication. Prior to padding activation, a check is performed to ensure that output buffer is big enough for a padded datagram. However, this did not take into account previously built packets which would be coalesced in the same datagram. Thus this patch fixes this comparison check. In theory, prior to this patch, in some cases Initial packets could not be built despite a datagram of the proper size. Currently, this probably never happens as Initial packet is always the first encoded in a datagram, thus there is no coalesced packet prior to it. However, there is no hard requirement on this, so it's better to reflect this in the code. This should be backported up to 2.6. --- diff --git a/src/quic_tx.c b/src/quic_tx.c index d457bf310..dd6f7f714 100644 --- a/src/quic_tx.c +++ b/src/quic_tx.c @@ -698,7 +698,7 @@ static int qc_prep_pkts(struct quic_conn *qc, struct buffer *buf, */ if (qel == qc->iel && (qc_is_back(qc) || !LIST_ISEMPTY(frms) || probe)) { /* Ensure that no Initial packets are sent into too small datagrams */ - if (end - pos < QUIC_INITIAL_PACKET_MINLEN) { + if (end - pos + dglen < QUIC_INITIAL_PACKET_MINLEN) { TRACE_PROTO("No more enough room to build an Initial packet", QUIC_EV_CONN_PHPKTS, qc); break;