mqtt5-protocol 0.15.2 made Packet::decode_from_body_with_version check fixed-header reserved flags for every packet type (MQTT-2.1.3-1). Two decode paths still use the unchecked decode_from_body, so they accept packets with invalid reserved flags:
- the broker QUIC acceptor (
crates/mqtt5/src/broker/quic_acceptor.rs, around lines 502 and 756)
- the wasm broker's decoder path (
crates/mqtt5-wasm)
The TCP, TLS and WebSocket broker paths reject these packets as malformed, so behaviour depends on the transport.
Fix: route both paths through the version-aware checked decode. Add a test per transport sending, for example, PINGREQ with flags 0x1, expecting the connection to close as malformed.
Found in the quorum review of #164.
mqtt5-protocol0.15.2 madePacket::decode_from_body_with_versioncheck fixed-header reserved flags for every packet type (MQTT-2.1.3-1). Two decode paths still use the uncheckeddecode_from_body, so they accept packets with invalid reserved flags:crates/mqtt5/src/broker/quic_acceptor.rs, around lines 502 and 756)crates/mqtt5-wasm)The TCP, TLS and WebSocket broker paths reject these packets as malformed, so behaviour depends on the transport.
Fix: route both paths through the version-aware checked decode. Add a test per transport sending, for example, PINGREQ with flags 0x1, expecting the connection to close as malformed.
Found in the quorum review of #164.