Skip to content

MQTT 5.0: reject duplicated CONNECT properties with 0x82 (general parse-time validation) #1131

Description

@BenjaminDobler

Follow-up from #1117 review. aedes currently degrades silently when a CONNECT repeats a v5 property that must appear at most once; #1117 closes the one wire-reachable crash (outbound Topic Alias Maximum) defensively, but the general class is worth a deliberate, separate change.

Scope (per the #1117 discussion)

  1. Base-branch behaviour change. receiveMaximum and maximumPacketSize already ship on mqttv5 accepting the array shape and degrading silently; making duplicates strict (0x82 Protocol Error, connection refused) changes CONNECTs that currently succeed. That deserves its own commit / bisect point, not a fold-in.
  2. Per-property spec basis. "It is a Protocol Error to include X more than once" recurs for each property, so the right shape is a general CONNECT-property validation pass, not three special cases.
  3. The array shape is not a reliable duplicate signal. mqtt-packet promotes a repeated property to an array behind a truthiness check (parser.js:772), so a duplicate whose first occurrence is 0 is silently overwritten rather than arrayed. Detecting duplicates properly likely needs an upstream mqtt-packet change.

Notes

Activity

  1. added a commit that references this issue on Jul 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions