Skip to content

internal: refuse userauth before service request - #1292

Draft
ejohnstown wants to merge 1 commit into
wolfSSL:masterfrom
ejohnstown:issue-1287-unrequested-service-accept
Draft

ejohnstown wants to merge 1 commit into
wolfSSL:masterfrom
ejohnstown:issue-1287-unrequested-service-accept

Conversation

@ejohnstown

@ejohnstown ejohnstown commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

The server refuses userauth messages until the ssh-userauth service request is in, RFC 4252 section 1, so a userauth request can no longer draw a SERVICE_ACCEPT for a service the client never asked for.

  • IsMessageAllowedServer() gates ids 50 to 79 on the service request
  • regress: an unrequested userauth disconnects; a pipelined one still works

Issue: #1287

The server refuses user auth messages until the ssh-userauth service
request is in, per RFC 4252 section 1, and disconnects on them as on
any known id at the wrong time. A successful userauth request can no
longer satisfy the accept loop and draw SERVICE_ACCEPT for a service
the client never requested.

- IsMessageAllowedServer() gates ids 50 to 79 on acceptState reaching
  ACCEPT_CLIENT_USERAUTH_REQUEST_DONE
- regress: the filter refuses USERAUTH_REQUEST and INFO_RESPONSE when
  keyed and admits both after the service request
- regress: a userauth request with no service request disconnects
- regress: a userauth request pipelined behind the service request
  still gets SERVICE_ACCEPT, then its answer

Issue: wolfSSL#1287
Copilot AI balanced review requested due to automatic review settings September 30, 2026 23:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The state transition correctly resolves the protocol violation and is covered by focused regression tests.

Review effort: Balanced
Findings: None

What changed in this PR

Fixes issue #1287 by enforcing the SSH user-authentication service-request sequence.

Changes:

  • Rejects user-auth messages before ssh-userauth is requested.
  • Advances server state before processing pipelined authentication.
  • Adds regression coverage for rejected and valid pipelined requests.
File Description
src/​internal.c Gates user-auth messages on service-request state.
src/​ssh.c Advances accept state before further reads.
tests/​regress.c Tests premature and pipelined authentication.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants