Skip to content

Validate the first extension set on a header - #374

Closed
RaphaelFakhri wants to merge 1 commit into
pion:mainfrom
RaphaelFakhri:fix-setextension-first-extension
Closed

RaphaelFakhri wants to merge 1 commit into
pion:mainfrom
RaphaelFakhri:fix-setextension-first-extension

Conversation

@RaphaelFakhri

Copy link
Copy Markdown

Validate the first extension set on a header

Description

Header.SetExtension validates the id and payload size only when the header already has extensions. On a header without extensions it picks a profile from the payload length alone and skips validation. This produces packets that are silently corrupt:

  • A payload of 256 bytes or more leaves the profile at 0. Marshal then writes an RFC 3550 extension and Unmarshal reads the extension back with an empty payload.
  • An id above 14 is written with the one-byte profile, so id<<4 overflows and the id is lost.
  • An empty payload is written with the one-byte profile, where the length field wraps to 0xFF. The parsed header has no extensions.

SetExtension now selects the two-byte profile when the id is above 14 or the payload is empty or longer than 16 bytes, and runs the same check that is used for headers that already have extensions. It returns an error and leaves the header unchanged when the extension cannot be encoded, for example a payload longer than 255 bytes or id 0.

TestSetExtensionFirstExtension marshals and unmarshals a header after setting each kind of first extension, and checks that failed calls do not change the header. It fails on the previous code (6 of 10 subtests) and passes with the change.

Reference issue

None.

@JoTurk JoTurk closed this Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants