Skip to content

Commit 6b87198

Browse files
use cryptographic random for determining skipped packet numbers
1 parent 4867389 commit 6b87198

File tree

2 files changed

+30
-6
lines changed

2 files changed

+30
-6
lines changed

internal/ackhandler/packet_number_generator.go

Lines changed: 25 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,6 @@ package ackhandler
33
import (
44
"crypto/rand"
55
"encoding/binary"
6-
mrand "math/rand"
76

87
"github.com/lucas-clemente/quic-go/internal/protocol"
98
"github.com/lucas-clemente/quic-go/internal/utils"
@@ -34,25 +33,45 @@ func (p *sequentialPacketNumberGenerator) Pop() protocol.PacketNumber {
3433
return next
3534
}
3635

36+
type rng struct {
37+
buf [4]byte
38+
}
39+
40+
func (r *rng) Int31() int32 {
41+
rand.Read(r.buf[:])
42+
return int32(binary.BigEndian.Uint32(r.buf[:]) & ^uint32(1<<31))
43+
}
44+
45+
// copied from the standard library math/rand implementation of Int63n
46+
func (r *rng) Int31n(n int32) int32 {
47+
if n&(n-1) == 0 { // n is power of two, can mask
48+
return r.Int31() & (n - 1)
49+
}
50+
max := int32((1 << 31) - 1 - (1<<31)%uint32(n))
51+
v := r.Int31()
52+
for v > max {
53+
v = r.Int31()
54+
}
55+
return v % n
56+
}
57+
3758
// The skippingPacketNumberGenerator generates the packet number for the next packet
3859
// it randomly skips a packet number every averagePeriod packets (on average).
3960
// It is guaranteed to never skip two consecutive packet numbers.
4061
type skippingPacketNumberGenerator struct {
41-
rand *mrand.Rand
4262
period protocol.PacketNumber
4363
maxPeriod protocol.PacketNumber
4464

4565
next protocol.PacketNumber
4666
nextToSkip protocol.PacketNumber
67+
68+
rng rng
4769
}
4870

4971
var _ packetNumberGenerator = &skippingPacketNumberGenerator{}
5072

5173
func newSkippingPacketNumberGenerator(initial, initialPeriod, maxPeriod protocol.PacketNumber) packetNumberGenerator {
52-
b := make([]byte, 8)
53-
rand.Read(b) // it's not the end of the world if we don't get perfect random here
5474
g := &skippingPacketNumberGenerator{
55-
rand: mrand.New(mrand.NewSource(int64(binary.LittleEndian.Uint64(b)))),
5675
next: initial,
5776
period: initialPeriod,
5877
maxPeriod: maxPeriod,
@@ -77,6 +96,6 @@ func (p *skippingPacketNumberGenerator) Pop() protocol.PacketNumber {
7796

7897
func (p *skippingPacketNumberGenerator) generateNewSkip() {
7998
// make sure that there are never two consecutive packet numbers that are skipped
80-
p.nextToSkip = p.next + 2 + protocol.PacketNumber(p.rand.Int63n(int64(2*p.period)))
99+
p.nextToSkip = p.next + 2 + protocol.PacketNumber(p.rng.Int31n(int32(2*p.period)))
81100
p.period = utils.MinPacketNumber(2*p.period, p.maxPeriod)
82101
}

internal/ackhandler/packet_number_generator_test.go

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@ package ackhandler
22

33
import (
44
"fmt"
5+
"math"
56

67
"github.com/lucas-clemente/quic-go/internal/protocol"
78

@@ -27,6 +28,10 @@ var _ = Describe("Skipping Packet Number Generator", func() {
2728
const initialPeriod protocol.PacketNumber = 25
2829
const maxPeriod protocol.PacketNumber = 300
2930

31+
It("uses a maximum period that is sufficiently small such that using a 32-bit random number is ok", func() {
32+
Expect(2 * protocol.SkipPacketMaxPeriod).To(BeNumerically("<", math.MaxInt32))
33+
})
34+
3035
It("can be initialized to return any first packet number", func() {
3136
png := newSkippingPacketNumberGenerator(12345, initialPeriod, maxPeriod)
3237
Expect(png.Pop()).To(Equal(protocol.PacketNumber(12345)))

0 commit comments

Comments
 (0)