-
Notifications
You must be signed in to change notification settings - Fork 80
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Ensure all INIT have a verification tag of 0 as per the spec #341
base: master
Are you sure you want to change the base?
Conversation
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## master #341 +/- ##
=======================================
Coverage 81.66% 81.66%
=======================================
Files 51 51
Lines 4384 4384
=======================================
Hits 3580 3580
Misses 661 661
Partials 143 143
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
@jmelancongen Is this Pion on both sides when you see this happen? I would like to create a reproduce (I can help with that!) Thank you so much for sending this PR over! |
I agree a reproducer or test would be nice. In the scenario where we are seeing this it is Pion on both sides so it should be doable. The specific test we are doing is a validation of our TURN provider, and I'm guessing the fact that there is a real network is important, I'm suspecting a specific packet being lost at the wrong moment during the initialization. I was lucky to find the webrtc-rs PR early so I haven't looked too deeply in the entire interaction, but we'll assemble the complete logs from the test and post them here and take a deeper look into it! |
Here is the SCTP handshake part of our test: sctp-handshake-hang.txt From what I was told, the test runs every minute in multiple locations, and it reproduces the issue once every 2-3 weeks globally. I've boiled down the logs to these bits:
I believe the specific problem stems from:
I'm not too sure how to isolate those conditions in a smaller self-contained reproducer though. Since it feels like it needs the relay to be triggered. I'm also not very familiar with the testing framework for pion sadly, but it might be easier to reproduce this way? |
Fantastic! I can write a test for that today, that will be pretty easy to reproduce. |
dbd061d
to
9ee04dd
Compare
Sorry for the ping but did you have time to check on that? I'd would love to have the fix so we can remove a workaround on our side |
9ee04dd
to
5472f31
Compare
@jmelancongen Hello I was able to make a test for your PR #359 once it's confirmed & reviewed, I'll merge yours :) |
RFC 4960 Section 8.5.1 specifies that a packet containing an INIT chunk MUST set the verificate tag of the packet to 0. The current code follows that only if it has not received and handled an INIT packet from the peer yet. In which case the peerVerificationTag will not be zero, and any subsequent INIT will be invalid and refused by the peer. This is a problem if the INIT ACK was lost. If both peers have this behavior, and both INIT ACKs were lost, we fall into a situation where the initialization will never complete. Resolve this scenario by ensuring the packet with the INIT chunk always set the tag to zero, as is required.
5472f31
to
f7e04df
Compare
Awesome that's great news. Thanks a lot for looking at it! |
Description
We've been seeing issues with one of our tests that sometime hangs while opening a DataChannel between two peers. Looking at the detailed logs we've been seeing this pattern:
and the data channel never opens
We've found out that there is a PR from a year ago in webrtc-rs that seems to fit exactly the issue we are hitting:
webrtc-rs/webrtc#405
Where the fix was to ensure the init packet always uses the 0 tag, instead of using the Association state which might be different? We're just bringing that same fix here.