From 49cd59877daadead28c62e4bc8a9daf5778fa339 Mon Sep 17 00:00:00 2001 From: Pierre Le Fevre Date: Thu, 12 Mar 2026 20:30:15 +0100 Subject: [PATCH] Fix TLS handshake review issues: random_bytes panic on failure, variable naming, wildcard edge case MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - random_bytes: panic instead of silently using zero-filled buffers when /dev/urandom fails — using all-zero keys is a critical security issue - Rename _ee_body to ee_body since the variable is actually used - Fix wildcard hostname matching to reject empty labels (e.g. ".example.com" should not match "*.example.com") Co-Authored-By: Claude Opus 4.6 --- crates/net/src/tls/handshake.rs | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/crates/net/src/tls/handshake.rs b/crates/net/src/tls/handshake.rs index 697a899..b35d72b 100644 --- a/crates/net/src/tls/handshake.rs +++ b/crates/net/src/tls/handshake.rs @@ -199,9 +199,8 @@ fn read_bytes<'a>(data: &'a [u8], offset: &mut usize, len: usize) -> Result<&'a fn random_bytes(buf: &mut [u8]) { // Read from /dev/urandom for random bytes. // This is available on macOS (which is our only target). - if let Ok(mut f) = std::fs::File::open("/dev/urandom") { - let _ = f.read_exact(buf); - } + let mut f = std::fs::File::open("/dev/urandom").expect("failed to open /dev/urandom"); + f.read_exact(buf).expect("failed to read /dev/urandom"); } // --------------------------------------------------------------------------- @@ -699,11 +698,11 @@ pub fn connect(stream: S, server_name: &str) -> Result bool { // Wildcard matching: *.example.com matches foo.example.com if let Some(suffix) = pattern.strip_prefix("*.") { if let Some(rest) = hostname.strip_suffix(suffix) { - // The wildcard must match exactly one label - if rest.ends_with('.') && !rest[..rest.len() - 1].contains('.') { + // The wildcard must match exactly one non-empty label + if rest.ends_with('.') && rest.len() > 1 && !rest[..rest.len() - 1].contains('.') { return true; } } -- 2.51.2