mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-25 04:05:20 +00:00
Heal peer-ID rotation: rebind link on verified announce, retire ghost peer (#1401)
* Heal peer-ID rotation: rebind link on verified announce, retire ghost When a peer relaunches it rotates its ephemeral peer ID, but a still-open BLE connection kept its stale peripheral/central→peerID binding for the reachability retention window (~45-60s). Until it aged out, the other side showed a duplicate ghost peer and dropped the rotated peer's direct announces as spoofing attempts. Root cause: the ingress guard rejected a direct announce whose claimed sender differed from the link binding before signature verification could ever see it, so the binding could never heal. - Ingress guard: let a mismatched direct announce through, attributed to the claimed sender; REQUEST_SYNC keeps the strict binding check. - Bind sites: raw (pre-verification) announces may only bind unbound links, never rebind bound ones — rebinding now requires the announce handler's signature verification to pass. - On a verified direct announce whose ingress link is bound to a different peer, rebind the link to the announced ID and retire the rotated-away ID immediately (registry + gossip + UI), mirroring handleLeave. - BLELinkStateStore.bindPeripheral: drop the previous peer's reverse mapping on rebind so the retired ID no longer claims the link. Fixes #1387 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Contain forged-directness rebinds: no identity steal, per-link cooldown The announce signature does not authenticate directness (TTL is excluded from signing because relays mutate it), so a bound peer could replay another peer's fresh signed announce with its TTL restored and reach the rotation rebind path. Contain what such a replay can do: - Refuse a rebind when the claimed identity already owns another live link — a replayed announce can no longer steal a connected peer's binding or route its directed traffic to the replaying link. - Allow at most one rebind per link per cooldown window (60s) so two identities cannot fight over a link in a replay flip-flop, with each flip retiring the other peer. A replay against an identity with no live link remains possible, but that capability already exists today on unbound links, where any raw direct announce binds pre-verification. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: jack <jackjackbits@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
jack
Claude Fable 5
parent
78a291ab77
commit
3e9230229d
@@ -114,7 +114,9 @@ struct BLEServiceCoreTests {
|
||||
}
|
||||
|
||||
@Test
|
||||
func ingressRejectsDirectAnnounceThatConflictsWithBoundLink() async throws {
|
||||
func ingressAllowsDirectAnnounceThatConflictsWithBoundLink() async throws {
|
||||
// Peer-ID rotation heal: the announce must reach signature
|
||||
// verification, which decides whether the link rebinds.
|
||||
let ble = makeService()
|
||||
let boundPeer = PeerID(str: "1122334455667788")
|
||||
let claimedPeer = PeerID(str: "8899aabbccddeeff")
|
||||
@@ -128,9 +130,129 @@ struct BLEServiceCoreTests {
|
||||
ttl: 7
|
||||
)
|
||||
|
||||
#expect(ble._test_acceptsIngress(packet: packet, boundPeerID: boundPeer))
|
||||
}
|
||||
|
||||
@Test
|
||||
func ingressRejectsRequestSyncThatConflictsWithBoundLink() async throws {
|
||||
let ble = makeService()
|
||||
let boundPeer = PeerID(str: "1122334455667788")
|
||||
let claimedPeer = PeerID(str: "8899aabbccddeeff")
|
||||
let packet = BitchatPacket(
|
||||
type: MessageType.requestSync.rawValue,
|
||||
senderID: Data(hexString: claimedPeer.id) ?? Data(),
|
||||
recipientID: nil,
|
||||
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
|
||||
payload: Data(),
|
||||
signature: nil,
|
||||
ttl: 0
|
||||
)
|
||||
|
||||
#expect(!ble._test_acceptsIngress(packet: packet, boundPeerID: boundPeer))
|
||||
}
|
||||
|
||||
@Test
|
||||
func verifiedDirectAnnounceRebindsRotatedLinkAndRetiresOldPeer() async throws {
|
||||
let ble = makeService()
|
||||
let oldPeerID = PeerID(str: "1122334455667788")
|
||||
let centralUUID = "central-rotation"
|
||||
|
||||
// A connected peer whose link binding predates its relaunch.
|
||||
ble._test_seedConnectedPeer(oldPeerID, nickname: "alice")
|
||||
ble._test_bindCentral(centralUUID, to: oldPeerID)
|
||||
|
||||
// The relaunched device re-announces its rotated identity over the
|
||||
// still-open link.
|
||||
let signer = NoiseEncryptionService(keychain: MockKeychain())
|
||||
let announcement = AnnouncementPacket(
|
||||
nickname: "alice",
|
||||
noisePublicKey: signer.getStaticPublicKeyData(),
|
||||
signingPublicKey: signer.getSigningPublicKeyData(),
|
||||
directNeighbors: nil
|
||||
)
|
||||
let payload = try #require(announcement.encode(), "Failed to encode announcement")
|
||||
let newPeerID = PeerID(publicKey: announcement.noisePublicKey)
|
||||
let unsigned = BitchatPacket(
|
||||
type: MessageType.announce.rawValue,
|
||||
senderID: Data(hexString: newPeerID.id) ?? Data(),
|
||||
recipientID: nil,
|
||||
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
|
||||
payload: payload,
|
||||
signature: nil,
|
||||
ttl: 7
|
||||
)
|
||||
let packet = try #require(signer.signPacket(unsigned), "Failed to sign announce packet")
|
||||
|
||||
#expect(ble._test_recordIngressIfNew(packet: packet, linkID: centralUUID))
|
||||
ble._test_handlePacket(packet, fromPeerID: newPeerID, preseedPeer: false)
|
||||
|
||||
let rebound = await TestHelpers.waitUntil(
|
||||
{ ble._test_centralBinding(centralUUID) == newPeerID },
|
||||
timeout: TestConstants.defaultTimeout
|
||||
)
|
||||
#expect(rebound)
|
||||
|
||||
let retired = await TestHelpers.waitUntil(
|
||||
{
|
||||
let peerIDs = ble.currentPeerSnapshots().map(\.peerID)
|
||||
return peerIDs.contains(newPeerID) && !peerIDs.contains(oldPeerID)
|
||||
},
|
||||
timeout: TestConstants.defaultTimeout
|
||||
)
|
||||
#expect(retired)
|
||||
}
|
||||
|
||||
@Test
|
||||
func replayedDirectAnnounceCannotStealBoundIdentity() async throws {
|
||||
let ble = makeService()
|
||||
let attackerPeerID = PeerID(str: "1122334455667788")
|
||||
let victimLink = "central-victim"
|
||||
let attackerLink = "central-attacker"
|
||||
|
||||
// The victim's identity, genuinely bound on its own link.
|
||||
let victimSigner = NoiseEncryptionService(keychain: MockKeychain())
|
||||
let announcement = AnnouncementPacket(
|
||||
nickname: "victim",
|
||||
noisePublicKey: victimSigner.getStaticPublicKeyData(),
|
||||
signingPublicKey: victimSigner.getSigningPublicKeyData(),
|
||||
directNeighbors: nil
|
||||
)
|
||||
let payload = try #require(announcement.encode(), "Failed to encode announcement")
|
||||
let victimPeerID = PeerID(publicKey: announcement.noisePublicKey)
|
||||
ble._test_seedConnectedPeer(victimPeerID, nickname: "victim")
|
||||
ble._test_bindCentral(victimLink, to: victimPeerID)
|
||||
ble._test_seedConnectedPeer(attackerPeerID, nickname: "attacker")
|
||||
ble._test_bindCentral(attackerLink, to: attackerPeerID)
|
||||
|
||||
// The victim's fresh signed announce replayed on the attacker's bound
|
||||
// link with its direct TTL restored (TTL is excluded from signing, so
|
||||
// the signature still verifies).
|
||||
let unsigned = BitchatPacket(
|
||||
type: MessageType.announce.rawValue,
|
||||
senderID: Data(hexString: victimPeerID.id) ?? Data(),
|
||||
recipientID: nil,
|
||||
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
|
||||
payload: payload,
|
||||
signature: nil,
|
||||
ttl: 7
|
||||
)
|
||||
let packet = try #require(victimSigner.signPacket(unsigned), "Failed to sign announce packet")
|
||||
|
||||
#expect(ble._test_recordIngressIfNew(packet: packet, linkID: attackerLink))
|
||||
ble._test_handlePacket(packet, fromPeerID: victimPeerID, preseedPeer: false)
|
||||
|
||||
// The rebind must be refused: the identity already owns a live link.
|
||||
let stolen = await TestHelpers.waitUntil(
|
||||
{ ble._test_centralBinding(attackerLink) == victimPeerID },
|
||||
timeout: 0.3
|
||||
)
|
||||
#expect(!stolen)
|
||||
#expect(ble._test_centralBinding(attackerLink) == attackerPeerID)
|
||||
#expect(ble._test_centralBinding(victimLink) == victimPeerID)
|
||||
// And the replay must not retire the link's real bound peer.
|
||||
#expect(ble.currentPeerSnapshots().map(\.peerID).contains(attackerPeerID))
|
||||
}
|
||||
|
||||
@Test
|
||||
func ingressRejectsSelfLoopbackBeforeSpoofChecks() async throws {
|
||||
let ble = makeService()
|
||||
|
||||
@@ -88,21 +88,46 @@ struct BLEIngressLinkRegistryTests {
|
||||
}
|
||||
|
||||
@Test
|
||||
func packetContextRejectsDirectAnnounceMismatchOnBoundLink() {
|
||||
func packetContextAttributesDirectAnnounceMismatchToClaimedSender() throws {
|
||||
// A rotated peer re-announces its new ID on a link still bound to the
|
||||
// old one. The announce must flow through (attributed to the claimed
|
||||
// sender) so signature verification can decide whether to rebind.
|
||||
let localPeer = PeerID(str: "0011223344556677")
|
||||
let boundPeer = PeerID(str: "1122334455667788")
|
||||
let claimedPeer = PeerID(str: "8899aabbccddeeff")
|
||||
let packet = makeAnnouncePacket(sender: claimedPeer, ttl: 7)
|
||||
|
||||
let result = BLEIngressLinkRegistry.packetContext(
|
||||
let context = try #require(trySuccess(BLEIngressLinkRegistry.packetContext(
|
||||
for: packet,
|
||||
claimedSenderID: claimedPeer,
|
||||
boundPeerID: boundPeer,
|
||||
localPeerID: localPeer,
|
||||
directAnnounceTTL: 7
|
||||
)
|
||||
)))
|
||||
|
||||
#expect(result == .failure(.directSenderMismatch(boundPeerID: boundPeer, claimedSenderID: claimedPeer)))
|
||||
#expect(context.receivedFromPeerID == claimedPeer)
|
||||
#expect(context.validationPeerID == claimedPeer)
|
||||
}
|
||||
|
||||
@Test
|
||||
func packetContextAttributesRelayedAnnounceMismatchToBoundPeer() throws {
|
||||
// Relayed announces (ttl below direct) keep relayed attribution: the
|
||||
// link peer forwarded someone else's announce.
|
||||
let localPeer = PeerID(str: "0011223344556677")
|
||||
let boundPeer = PeerID(str: "1122334455667788")
|
||||
let claimedPeer = PeerID(str: "8899aabbccddeeff")
|
||||
let packet = makeAnnouncePacket(sender: claimedPeer, ttl: 6)
|
||||
|
||||
let context = try #require(trySuccess(BLEIngressLinkRegistry.packetContext(
|
||||
for: packet,
|
||||
claimedSenderID: claimedPeer,
|
||||
boundPeerID: boundPeer,
|
||||
localPeerID: localPeer,
|
||||
directAnnounceTTL: 7
|
||||
)))
|
||||
|
||||
#expect(context.receivedFromPeerID == boundPeer)
|
||||
#expect(context.validationPeerID == claimedPeer)
|
||||
}
|
||||
|
||||
@Test
|
||||
|
||||
@@ -26,13 +26,13 @@ struct BLEIngressPacketGuardTests {
|
||||
#expect(context.validationPeerID == sender)
|
||||
}
|
||||
|
||||
@Test("self loopback and direct announce spoofing are rejected before timestamp checks")
|
||||
@Test("self loopback and request-sync spoofing are rejected before timestamp checks")
|
||||
func linkBindingRejectionsWinBeforeTimestampChecks() {
|
||||
let local = PeerID(str: "0011223344556677")
|
||||
let bound = PeerID(str: "1122334455667788")
|
||||
let claimed = PeerID(str: "8899aabbccddeeff")
|
||||
let selfPacket = makePacket(sender: local, timestamp: 0)
|
||||
let spoofedAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 0, ttl: 7)
|
||||
let spoofedRequestSync = makePacket(type: .requestSync, sender: claimed, timestamp: 0, ttl: 0)
|
||||
|
||||
let selfResult = BLEIngressPacketGuard.evaluate(
|
||||
packet: selfPacket,
|
||||
@@ -44,7 +44,7 @@ struct BLEIngressPacketGuardTests {
|
||||
isValidSyncResponse: { _ in false }
|
||||
)
|
||||
let spoofResult = BLEIngressPacketGuard.evaluate(
|
||||
packet: spoofedAnnounce,
|
||||
packet: spoofedRequestSync,
|
||||
claimedSenderID: claimed,
|
||||
boundPeerID: bound,
|
||||
localPeerID: local,
|
||||
@@ -57,6 +57,44 @@ struct BLEIngressPacketGuardTests {
|
||||
#expect(spoofResult == .failure(.directSenderMismatch(boundPeerID: bound, claimedSenderID: claimed)))
|
||||
}
|
||||
|
||||
@Test("direct announce with a mismatched binding flows through to normal validation")
|
||||
func directAnnounceMismatchStillValidatesTimestamp() throws {
|
||||
// Rotation heal path: the announce passes the binding check attributed
|
||||
// to the claimed sender, but stays subject to timestamp validation.
|
||||
let local = PeerID(str: "0011223344556677")
|
||||
let bound = PeerID(str: "1122334455667788")
|
||||
let claimed = PeerID(str: "8899aabbccddeeff")
|
||||
let freshAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 1_000_000, ttl: 7)
|
||||
let staleAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 0, ttl: 7)
|
||||
|
||||
let freshContext = try #require(success(BLEIngressPacketGuard.evaluate(
|
||||
packet: freshAnnounce,
|
||||
claimedSenderID: claimed,
|
||||
boundPeerID: bound,
|
||||
localPeerID: local,
|
||||
directAnnounceTTL: 7,
|
||||
nowMs: 1_000_000,
|
||||
isValidSyncResponse: { _ in false }
|
||||
)))
|
||||
let staleResult = BLEIngressPacketGuard.evaluate(
|
||||
packet: staleAnnounce,
|
||||
claimedSenderID: claimed,
|
||||
boundPeerID: bound,
|
||||
localPeerID: local,
|
||||
directAnnounceTTL: 7,
|
||||
nowMs: 1_000_000,
|
||||
isValidSyncResponse: { _ in false }
|
||||
)
|
||||
|
||||
#expect(freshContext.receivedFromPeerID == claimed)
|
||||
#expect(freshContext.validationPeerID == claimed)
|
||||
#expect(staleResult == .failure(.timestampSkew(
|
||||
peerID: claimed,
|
||||
skewMs: 1_000_000,
|
||||
maxSkewMs: 120_000
|
||||
)))
|
||||
}
|
||||
|
||||
@Test("timestamp skew outside the window is rejected")
|
||||
func timestampSkewIsRejected() {
|
||||
let local = PeerID(str: "0011223344556677")
|
||||
|
||||
Reference in New Issue
Block a user