SIGN IN SIGN UP

srtp: locate the MKI correctly for RCC mode 1 packets without a tag

With RFC 4771 RCC mode 1 and an MKI, every packet that did not carry the
ROC failed srtp_unprotect with bad_mki: srtp_protect appends no
authentication tag to those packets, but the key lookup still stepped a
full tag length back from the packet end before reading the MKI.

srtp_get_session_keys_for_rtp_packet now takes the packet's rcc_carry
state and derives what trails the MKI from it: the 4-octet ROC of a mode
3 ROC-carrying AES-GCM packet, nothing for a mode 1 packet without the
ROC, the full tag otherwise. The ad-hoc mode 3 subtraction in
srtp_unprotect folds into that one place. Non-RCC streams compute exactly
what they did before. rcc_mode1_rate4_mki_untagged pins it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
L
lenamonj committed
daafc57283e2b2e0c619ddb6300e1a10240ec7dc
Parent: b06b4a2