Commit 767a89d
committed
Expose TLS handshake bytes from
Adds `Incoming::handshake_bytes()`, which decrypts the Initial packet using
the publicly-derivable Initial keys, walks the QUIC frames, and returns the
concatenated `CRYPTO` frame contents in offset order.
Per RFC 9001 §4.1.3, TLS handshake messages travel inside `CRYPTO` frames
with no intervening TLS record layer, so the returned bytes start directly
with the TLS handshake message header (`0x01` for ClientHello, followed by a
3-byte length and the body). Callers can feed this to a TLS parser to
inspect extensions such as SNI or ALPN before deciding whether to
`accept()`, `retry()`, `refuse()`, or `ignore()` the connection.
The motivating use case is port-knocking style authentication: a server
that wants to silently drop probes from any client that doesn't carry a
pre-shared token (e.g. an HMAC in a custom ALPN entry) needs to inspect
the ClientHello before any response goes on the wire. The existing
`Incoming` API already provides `ignore()` for the silent-drop side; this
adds the inspection side so the decision can be informed.
The high-level `quinn::Incoming` wrapper forwards the new method, and a
new `HandshakeBytesError` enum is re-exported from `quinn-proto`.Incoming
1 parent 41dce31 commit 767a89d
3 files changed
Lines changed: 83 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1198 | 1198 | | |
1199 | 1199 | | |
1200 | 1200 | | |
| 1201 | + | |
| 1202 | + | |
| 1203 | + | |
| 1204 | + | |
| 1205 | + | |
| 1206 | + | |
| 1207 | + | |
| 1208 | + | |
| 1209 | + | |
| 1210 | + | |
| 1211 | + | |
| 1212 | + | |
| 1213 | + | |
| 1214 | + | |
| 1215 | + | |
| 1216 | + | |
| 1217 | + | |
| 1218 | + | |
| 1219 | + | |
| 1220 | + | |
| 1221 | + | |
| 1222 | + | |
| 1223 | + | |
| 1224 | + | |
| 1225 | + | |
| 1226 | + | |
| 1227 | + | |
| 1228 | + | |
| 1229 | + | |
| 1230 | + | |
| 1231 | + | |
| 1232 | + | |
| 1233 | + | |
| 1234 | + | |
| 1235 | + | |
| 1236 | + | |
| 1237 | + | |
| 1238 | + | |
| 1239 | + | |
| 1240 | + | |
| 1241 | + | |
| 1242 | + | |
| 1243 | + | |
| 1244 | + | |
| 1245 | + | |
| 1246 | + | |
| 1247 | + | |
| 1248 | + | |
| 1249 | + | |
| 1250 | + | |
| 1251 | + | |
| 1252 | + | |
| 1253 | + | |
| 1254 | + | |
| 1255 | + | |
| 1256 | + | |
| 1257 | + | |
| 1258 | + | |
| 1259 | + | |
| 1260 | + | |
| 1261 | + | |
| 1262 | + | |
| 1263 | + | |
| 1264 | + | |
| 1265 | + | |
| 1266 | + | |
| 1267 | + | |
| 1268 | + | |
| 1269 | + | |
1201 | 1270 | | |
1202 | 1271 | | |
1203 | 1272 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
71 | 71 | | |
72 | 72 | | |
73 | 73 | | |
74 | | - | |
| 74 | + | |
| 75 | + | |
75 | 76 | | |
76 | 77 | | |
77 | 78 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
| 9 | + | |
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| |||
98 | 98 | | |
99 | 99 | | |
100 | 100 | | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
101 | 112 | | |
102 | 113 | | |
103 | 114 | | |
| |||
0 commit comments