In wado-rs.mode: sequential, a retrieve can receive another study's instances (possibly another patient's). Code refs are at v3.0.2 (f89009d).
- Sequential subscribes by AE only,
(AE, None) (src/backend/dimse/wado.rs:176-179).
- The C-MOVE is never cancelled at the peer when a retrieve ends early. There is no C-CANCEL in
src/backend/dimse/cmove/movescu.rs:27-80.
- The per-AE lock and the subscription are released as soon as the HTTP stream is dropped (
src/backend/dimse/cmove/mediator.rs:134-145).
- After a client disconnect or a read timeout, the peer keeps pushing the old study. The next sequential retrieve for that AE subscribes again and yields every instance it receives, unfiltered (
wado.rs:208-210).
Proposed fix
- Drop, and count in a log, received instances whose StudyInstanceUID does not match the request. Also check SeriesInstanceUID / SOPInstanceUID for series and instance retrieves. Do it in
retrieve_instances, in all modes.
- And/or send a C-CANCEL for the move when the stream is dropped.
This matters for peers that do not send Move Originator Message ID (0000,1031), which forces sequential mode.
Found and drafted with an AI agent (Claude), checked against the source.
In
wado-rs.mode: sequential, a retrieve can receive another study's instances (possibly another patient's). Code refs are at v3.0.2 (f89009d).(AE, None)(src/backend/dimse/wado.rs:176-179).src/backend/dimse/cmove/movescu.rs:27-80.src/backend/dimse/cmove/mediator.rs:134-145).wado.rs:208-210).Proposed fix
retrieve_instances, in all modes.This matters for peers that do not send Move Originator Message ID (0000,1031), which forces sequential mode.
Found and drafted with an AI agent (Claude), checked against the source.