docs: disclose DiffController OpenFlow candidate findings - #46
Open
Drone-Lab wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
This PR records the OpenDaylight portion of an academic differential-testing
disclosure set. The historical 2023 record classified DC-017 and DC-023 as
previously undocumented on the evaluated Carbon-era target. That historical
label is not maintainer confirmation, a CVE, or a claim that the current
implementation is vulnerable.
The entries are requests for validation. The current replay level
L1meansthat the stated differential signal was reproduced in the local harness. Raw
OpenFlow payloads, relay automation, and the full experiment corpus are not
included.
Tested target
opendaylight/controllerand its OpenFlow plugin componentsMininet/OVS harness
Candidate records
of_hello; BUILDof_flow_stats_reply; ADD; one flow-stat entryFor DC-023, the archived OpenDaylight replay observed the exact sentinel in
11/12 operational snapshots after 12/12 strict same-XID injections and in 0/10
pass-through controls. Channels remained open and REST returned HTTP 200 in the
primary cases. The OpenFlow specification does not explicitly require
controller-side revalidation of every switch statistics reply, so this report
asks maintainers to determine the intended trust and provenance boundary.
Requested action
Please confirm the affected component and versions, whether these behaviors
are expected, and whether an existing Gerrit/GitHub issue, advisory, or fix
tracks either row. We can provide a minimal redacted reproducer, paired-control
logs, and hashes through a maintainer-selected channel. The OpenDaylight
project may prefer Gerrit for development; this PR is the public GitHub record
requested for the disclosure.