Skip to content

Harden panic-prone parsing and QUIC connection error paths - #25

Merged
madeye merged 2 commits into
masterfrom
copilot/fix-security-issues
Aug 19, 2026
Merged

madeye merged 2 commits into
masterfrom
copilot/fix-security-issues

Conversation

Copilot AI commented Aug 19, 2026

Copy link
Copy Markdown
Contributor

This change addresses security-relevant crash vectors caused by unwrap() in externally influenced paths (env/plugin options, cert loading, and connection retry/connect flows). The goal is to convert panic-based failure modes into controlled errors or safe degradation.

  • Input/env parsing hardening

    • parse_env_addr() no longer unwraps resolved socket addresses; it now returns explicit errors when resolution yields no address.
    • parse_plugin_options() now tolerates malformed segments (e.g. missing = / empty key) without panicking, while preserving valid entries and empty values where appropriate.
    • Added test coverage for malformed plugin option input behavior.
  • Client-side TLS/QUIC resilience

    • Replaced panic-prone native cert handling with non-panicking processing:
      • native cert loader errors are logged,
      • invalid certs are skipped instead of aborting.
    • Replaced connect(...).await ... .unwrap() with propagated error handling.
    • Removed panic risk in rebind logging when local socket address lookup fails.
  • Server-side retry path hardening

    • Replaced conn.retry().unwrap() with explicit error handling and logging to prevent process abort on retry failure.
// before
let ss_local_addr = format!("{}:{}", ss_local_host, ss_local_port)
    .to_socket_addrs()?
    .next()
    .unwrap();

// after
let ss_local_addr = format!("{}:{}", ss_local_host, ss_local_port)
    .to_socket_addrs()?
    .next()
    .ok_or_else(|| anyhow!("resolved no local socket address"))?;

Copilot AI and others added 2 commits August 19, 2026 02:29
Co-authored-by: madeye <627917+madeye@users.noreply.github.com>
Co-authored-by: madeye <627917+madeye@users.noreply.github.com>
@madeye
madeye marked this pull request as ready for review August 19, 2026 07:12
@madeye
madeye merged commit 4b242d0 into master Aug 19, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants