Skip to content

internal: refuse auth replies before a request - #1290

Draft
ejohnstown wants to merge 1 commit into
wolfSSL:masterfrom
ejohnstown:issue-1285-unsolicited-auth-success
Draft

ejohnstown wants to merge 1 commit into
wolfSSL:masterfrom
ejohnstown:issue-1285-unsolicited-auth-success

Conversation

@ejohnstown

@ejohnstown ejohnstown commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

The client refuses every userauth message, the banner included, until its first USERAUTH_REQUEST is out, so a SUCCESS sent in place of the SERVICE_ACCEPT no longer completes wolfSSH_connect().

  • IsMessageAllowedClient() gates ids 50 to 79 on CONNECT_CLIENT_USERAUTH_SENT
  • regress: early SUCCESS, FAILURE and PK_OK disconnect; a banner bundled behind the service accept still gets through

Issue: #1285

Copilot AI balanced review requested due to automatic review settings September 30, 2026 23:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The state transition fix is focused and comprehensively covered by regression tests.

Review effort: Balanced
Findings: None

What changed in this PR

Prevents clients from accepting user-authentication messages before sending their first authentication request, addressing issue #1285.

Changes:

  • Tightens client message-state validation for user-authentication messages.
  • Adds regression coverage for unsolicited replies and valid banner sequencing.
File Description
src/​internal.c Delays user-auth message acceptance until the request is sent.
tests/​regress.c Tests rejection, disconnect behavior, and banner handling.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

The client filter now refuses every userauth message, the banner
included, until CONNECT_CLIENT_USERAUTH_SENT, so a SUCCESS sent in place
of the SERVICE_ACCEPT no longer completes wolfSSH_connect(). The first
request goes out right after the service accept, RFC 4252 section 5.4.

- regress: test each userauth message in the pre-request states
- regress: drive an early SUCCESS, FAILURE and PK_OK through DoReceive
- regress: a banner bundled behind the service accept still gets
  through wolfSSH_connect()

Issue: wolfSSL#1285
@ejohnstown
ejohnstown force-pushed the issue-1285-unsolicited-auth-success branch from 34ce773 to 9b8d721 Compare October 1, 2026 16:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants