Heal peer-ID rotation: rebind link on verified announce, retire ghost peer (#1401)

* Heal peer-ID rotation: rebind link on verified announce, retire ghost

When a peer relaunches it rotates its ephemeral peer ID, but a
still-open BLE connection kept its stale peripheral/central→peerID
binding for the reachability retention window (~45-60s). Until it aged
out, the other side showed a duplicate ghost peer and dropped the
rotated peer's direct announces as spoofing attempts.

Root cause: the ingress guard rejected a direct announce whose claimed
sender differed from the link binding before signature verification
could ever see it, so the binding could never heal.

- Ingress guard: let a mismatched direct announce through, attributed
  to the claimed sender; REQUEST_SYNC keeps the strict binding check.
- Bind sites: raw (pre-verification) announces may only bind unbound
  links, never rebind bound ones — rebinding now requires the announce
  handler's signature verification to pass.
- On a verified direct announce whose ingress link is bound to a
  different peer, rebind the link to the announced ID and retire the
  rotated-away ID immediately (registry + gossip + UI), mirroring
  handleLeave.
- BLELinkStateStore.bindPeripheral: drop the previous peer's reverse
  mapping on rebind so the retired ID no longer claims the link.

Fixes #1387

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Contain forged-directness rebinds: no identity steal, per-link cooldown

The announce signature does not authenticate directness (TTL is
excluded from signing because relays mutate it), so a bound peer could
replay another peer's fresh signed announce with its TTL restored and
reach the rotation rebind path. Contain what such a replay can do:

- Refuse a rebind when the claimed identity already owns another live
  link — a replayed announce can no longer steal a connected peer's
  binding or route its directed traffic to the replaying link.
- Allow at most one rebind per link per cooldown window (60s) so two
  identities cannot fight over a link in a replay flip-flop, with each
  flip retiring the other peer.

A replay against an identity with no live link remains possible, but
that capability already exists today on unbound links, where any raw
direct announce binds pre-verification.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
jack
2026-07-08 10:08:23 +02:00
committed by GitHub
co-authored by jack Claude Fable 5
parent 78a291ab77
commit 3e9230229d
7 changed files with 358 additions and 25 deletions
+123 -1
View File
@@ -114,7 +114,9 @@ struct BLEServiceCoreTests {
}
@Test
func ingressRejectsDirectAnnounceThatConflictsWithBoundLink() async throws {
func ingressAllowsDirectAnnounceThatConflictsWithBoundLink() async throws {
// Peer-ID rotation heal: the announce must reach signature
// verification, which decides whether the link rebinds.
let ble = makeService()
let boundPeer = PeerID(str: "1122334455667788")
let claimedPeer = PeerID(str: "8899aabbccddeeff")
@@ -128,9 +130,129 @@ struct BLEServiceCoreTests {
ttl: 7
)
#expect(ble._test_acceptsIngress(packet: packet, boundPeerID: boundPeer))
}
@Test
func ingressRejectsRequestSyncThatConflictsWithBoundLink() async throws {
let ble = makeService()
let boundPeer = PeerID(str: "1122334455667788")
let claimedPeer = PeerID(str: "8899aabbccddeeff")
let packet = BitchatPacket(
type: MessageType.requestSync.rawValue,
senderID: Data(hexString: claimedPeer.id) ?? Data(),
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: Data(),
signature: nil,
ttl: 0
)
#expect(!ble._test_acceptsIngress(packet: packet, boundPeerID: boundPeer))
}
@Test
func verifiedDirectAnnounceRebindsRotatedLinkAndRetiresOldPeer() async throws {
let ble = makeService()
let oldPeerID = PeerID(str: "1122334455667788")
let centralUUID = "central-rotation"
// A connected peer whose link binding predates its relaunch.
ble._test_seedConnectedPeer(oldPeerID, nickname: "alice")
ble._test_bindCentral(centralUUID, to: oldPeerID)
// The relaunched device re-announces its rotated identity over the
// still-open link.
let signer = NoiseEncryptionService(keychain: MockKeychain())
let announcement = AnnouncementPacket(
nickname: "alice",
noisePublicKey: signer.getStaticPublicKeyData(),
signingPublicKey: signer.getSigningPublicKeyData(),
directNeighbors: nil
)
let payload = try #require(announcement.encode(), "Failed to encode announcement")
let newPeerID = PeerID(publicKey: announcement.noisePublicKey)
let unsigned = BitchatPacket(
type: MessageType.announce.rawValue,
senderID: Data(hexString: newPeerID.id) ?? Data(),
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload,
signature: nil,
ttl: 7
)
let packet = try #require(signer.signPacket(unsigned), "Failed to sign announce packet")
#expect(ble._test_recordIngressIfNew(packet: packet, linkID: centralUUID))
ble._test_handlePacket(packet, fromPeerID: newPeerID, preseedPeer: false)
let rebound = await TestHelpers.waitUntil(
{ ble._test_centralBinding(centralUUID) == newPeerID },
timeout: TestConstants.defaultTimeout
)
#expect(rebound)
let retired = await TestHelpers.waitUntil(
{
let peerIDs = ble.currentPeerSnapshots().map(\.peerID)
return peerIDs.contains(newPeerID) && !peerIDs.contains(oldPeerID)
},
timeout: TestConstants.defaultTimeout
)
#expect(retired)
}
@Test
func replayedDirectAnnounceCannotStealBoundIdentity() async throws {
let ble = makeService()
let attackerPeerID = PeerID(str: "1122334455667788")
let victimLink = "central-victim"
let attackerLink = "central-attacker"
// The victim's identity, genuinely bound on its own link.
let victimSigner = NoiseEncryptionService(keychain: MockKeychain())
let announcement = AnnouncementPacket(
nickname: "victim",
noisePublicKey: victimSigner.getStaticPublicKeyData(),
signingPublicKey: victimSigner.getSigningPublicKeyData(),
directNeighbors: nil
)
let payload = try #require(announcement.encode(), "Failed to encode announcement")
let victimPeerID = PeerID(publicKey: announcement.noisePublicKey)
ble._test_seedConnectedPeer(victimPeerID, nickname: "victim")
ble._test_bindCentral(victimLink, to: victimPeerID)
ble._test_seedConnectedPeer(attackerPeerID, nickname: "attacker")
ble._test_bindCentral(attackerLink, to: attackerPeerID)
// The victim's fresh signed announce replayed on the attacker's bound
// link with its direct TTL restored (TTL is excluded from signing, so
// the signature still verifies).
let unsigned = BitchatPacket(
type: MessageType.announce.rawValue,
senderID: Data(hexString: victimPeerID.id) ?? Data(),
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload,
signature: nil,
ttl: 7
)
let packet = try #require(victimSigner.signPacket(unsigned), "Failed to sign announce packet")
#expect(ble._test_recordIngressIfNew(packet: packet, linkID: attackerLink))
ble._test_handlePacket(packet, fromPeerID: victimPeerID, preseedPeer: false)
// The rebind must be refused: the identity already owns a live link.
let stolen = await TestHelpers.waitUntil(
{ ble._test_centralBinding(attackerLink) == victimPeerID },
timeout: 0.3
)
#expect(!stolen)
#expect(ble._test_centralBinding(attackerLink) == attackerPeerID)
#expect(ble._test_centralBinding(victimLink) == victimPeerID)
// And the replay must not retire the link's real bound peer.
#expect(ble.currentPeerSnapshots().map(\.peerID).contains(attackerPeerID))
}
@Test
func ingressRejectsSelfLoopbackBeforeSpoofChecks() async throws {
let ble = makeService()
@@ -88,21 +88,46 @@ struct BLEIngressLinkRegistryTests {
}
@Test
func packetContextRejectsDirectAnnounceMismatchOnBoundLink() {
func packetContextAttributesDirectAnnounceMismatchToClaimedSender() throws {
// A rotated peer re-announces its new ID on a link still bound to the
// old one. The announce must flow through (attributed to the claimed
// sender) so signature verification can decide whether to rebind.
let localPeer = PeerID(str: "0011223344556677")
let boundPeer = PeerID(str: "1122334455667788")
let claimedPeer = PeerID(str: "8899aabbccddeeff")
let packet = makeAnnouncePacket(sender: claimedPeer, ttl: 7)
let result = BLEIngressLinkRegistry.packetContext(
let context = try #require(trySuccess(BLEIngressLinkRegistry.packetContext(
for: packet,
claimedSenderID: claimedPeer,
boundPeerID: boundPeer,
localPeerID: localPeer,
directAnnounceTTL: 7
)
)))
#expect(result == .failure(.directSenderMismatch(boundPeerID: boundPeer, claimedSenderID: claimedPeer)))
#expect(context.receivedFromPeerID == claimedPeer)
#expect(context.validationPeerID == claimedPeer)
}
@Test
func packetContextAttributesRelayedAnnounceMismatchToBoundPeer() throws {
// Relayed announces (ttl below direct) keep relayed attribution: the
// link peer forwarded someone else's announce.
let localPeer = PeerID(str: "0011223344556677")
let boundPeer = PeerID(str: "1122334455667788")
let claimedPeer = PeerID(str: "8899aabbccddeeff")
let packet = makeAnnouncePacket(sender: claimedPeer, ttl: 6)
let context = try #require(trySuccess(BLEIngressLinkRegistry.packetContext(
for: packet,
claimedSenderID: claimedPeer,
boundPeerID: boundPeer,
localPeerID: localPeer,
directAnnounceTTL: 7
)))
#expect(context.receivedFromPeerID == boundPeer)
#expect(context.validationPeerID == claimedPeer)
}
@Test
@@ -26,13 +26,13 @@ struct BLEIngressPacketGuardTests {
#expect(context.validationPeerID == sender)
}
@Test("self loopback and direct announce spoofing are rejected before timestamp checks")
@Test("self loopback and request-sync spoofing are rejected before timestamp checks")
func linkBindingRejectionsWinBeforeTimestampChecks() {
let local = PeerID(str: "0011223344556677")
let bound = PeerID(str: "1122334455667788")
let claimed = PeerID(str: "8899aabbccddeeff")
let selfPacket = makePacket(sender: local, timestamp: 0)
let spoofedAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 0, ttl: 7)
let spoofedRequestSync = makePacket(type: .requestSync, sender: claimed, timestamp: 0, ttl: 0)
let selfResult = BLEIngressPacketGuard.evaluate(
packet: selfPacket,
@@ -44,7 +44,7 @@ struct BLEIngressPacketGuardTests {
isValidSyncResponse: { _ in false }
)
let spoofResult = BLEIngressPacketGuard.evaluate(
packet: spoofedAnnounce,
packet: spoofedRequestSync,
claimedSenderID: claimed,
boundPeerID: bound,
localPeerID: local,
@@ -57,6 +57,44 @@ struct BLEIngressPacketGuardTests {
#expect(spoofResult == .failure(.directSenderMismatch(boundPeerID: bound, claimedSenderID: claimed)))
}
@Test("direct announce with a mismatched binding flows through to normal validation")
func directAnnounceMismatchStillValidatesTimestamp() throws {
// Rotation heal path: the announce passes the binding check attributed
// to the claimed sender, but stays subject to timestamp validation.
let local = PeerID(str: "0011223344556677")
let bound = PeerID(str: "1122334455667788")
let claimed = PeerID(str: "8899aabbccddeeff")
let freshAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 1_000_000, ttl: 7)
let staleAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 0, ttl: 7)
let freshContext = try #require(success(BLEIngressPacketGuard.evaluate(
packet: freshAnnounce,
claimedSenderID: claimed,
boundPeerID: bound,
localPeerID: local,
directAnnounceTTL: 7,
nowMs: 1_000_000,
isValidSyncResponse: { _ in false }
)))
let staleResult = BLEIngressPacketGuard.evaluate(
packet: staleAnnounce,
claimedSenderID: claimed,
boundPeerID: bound,
localPeerID: local,
directAnnounceTTL: 7,
nowMs: 1_000_000,
isValidSyncResponse: { _ in false }
)
#expect(freshContext.receivedFromPeerID == claimed)
#expect(freshContext.validationPeerID == claimed)
#expect(staleResult == .failure(.timestampSkew(
peerID: claimed,
skewMs: 1_000_000,
maxSkewMs: 120_000
)))
}
@Test("timestamp skew outside the window is rejected")
func timestampSkewIsRejected() {
let local = PeerID(str: "0011223344556677")