Heal peer-ID rotation: rebind link on verified announce, retire ghost peer (#1401)

* Heal peer-ID rotation: rebind link on verified announce, retire ghost

When a peer relaunches it rotates its ephemeral peer ID, but a
still-open BLE connection kept its stale peripheral/central→peerID
binding for the reachability retention window (~45-60s). Until it aged
out, the other side showed a duplicate ghost peer and dropped the
rotated peer's direct announces as spoofing attempts.

Root cause: the ingress guard rejected a direct announce whose claimed
sender differed from the link binding before signature verification
could ever see it, so the binding could never heal.

- Ingress guard: let a mismatched direct announce through, attributed
  to the claimed sender; REQUEST_SYNC keeps the strict binding check.
- Bind sites: raw (pre-verification) announces may only bind unbound
  links, never rebind bound ones — rebinding now requires the announce
  handler's signature verification to pass.
- On a verified direct announce whose ingress link is bound to a
  different peer, rebind the link to the announced ID and retire the
  rotated-away ID immediately (registry + gossip + UI), mirroring
  handleLeave.
- BLELinkStateStore.bindPeripheral: drop the previous peer's reverse
  mapping on rebind so the retired ID no longer claims the link.

Fixes #1387

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Contain forged-directness rebinds: no identity steal, per-link cooldown

The announce signature does not authenticate directness (TTL is
excluded from signing because relays mutate it), so a bound peer could
replay another peer's fresh signed announce with its TTL restored and
reach the rotation rebind path. Contain what such a replay can do:

- Refuse a rebind when the claimed identity already owns another live
  link — a replayed announce can no longer steal a connected peer's
  binding or route its directed traffic to the replaying link.
- Allow at most one rebind per link per cooldown window (60s) so two
  identities cannot fight over a link in a replay flip-flop, with each
  flip retiring the other peer.

A replay against an identity with no live link remains possible, but
that capability already exists today on unbound links, where any raw
direct announce binds pre-verification.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
jack
2026-07-08 10:08:23 +02:00
committed by GitHub
co-authored by jack Claude Fable 5
parent 78a291ab77
commit 3e9230229d
7 changed files with 358 additions and 25 deletions
+123 -1
View File
@@ -114,7 +114,9 @@ struct BLEServiceCoreTests {
}
@Test
func ingressRejectsDirectAnnounceThatConflictsWithBoundLink() async throws {
func ingressAllowsDirectAnnounceThatConflictsWithBoundLink() async throws {
// Peer-ID rotation heal: the announce must reach signature
// verification, which decides whether the link rebinds.
let ble = makeService()
let boundPeer = PeerID(str: "1122334455667788")
let claimedPeer = PeerID(str: "8899aabbccddeeff")
@@ -128,9 +130,129 @@ struct BLEServiceCoreTests {
ttl: 7
)
#expect(ble._test_acceptsIngress(packet: packet, boundPeerID: boundPeer))
}
@Test
func ingressRejectsRequestSyncThatConflictsWithBoundLink() async throws {
let ble = makeService()
let boundPeer = PeerID(str: "1122334455667788")
let claimedPeer = PeerID(str: "8899aabbccddeeff")
let packet = BitchatPacket(
type: MessageType.requestSync.rawValue,
senderID: Data(hexString: claimedPeer.id) ?? Data(),
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: Data(),
signature: nil,
ttl: 0
)
#expect(!ble._test_acceptsIngress(packet: packet, boundPeerID: boundPeer))
}
@Test
func verifiedDirectAnnounceRebindsRotatedLinkAndRetiresOldPeer() async throws {
let ble = makeService()
let oldPeerID = PeerID(str: "1122334455667788")
let centralUUID = "central-rotation"
// A connected peer whose link binding predates its relaunch.
ble._test_seedConnectedPeer(oldPeerID, nickname: "alice")
ble._test_bindCentral(centralUUID, to: oldPeerID)
// The relaunched device re-announces its rotated identity over the
// still-open link.
let signer = NoiseEncryptionService(keychain: MockKeychain())
let announcement = AnnouncementPacket(
nickname: "alice",
noisePublicKey: signer.getStaticPublicKeyData(),
signingPublicKey: signer.getSigningPublicKeyData(),
directNeighbors: nil
)
let payload = try #require(announcement.encode(), "Failed to encode announcement")
let newPeerID = PeerID(publicKey: announcement.noisePublicKey)
let unsigned = BitchatPacket(
type: MessageType.announce.rawValue,
senderID: Data(hexString: newPeerID.id) ?? Data(),
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload,
signature: nil,
ttl: 7
)
let packet = try #require(signer.signPacket(unsigned), "Failed to sign announce packet")
#expect(ble._test_recordIngressIfNew(packet: packet, linkID: centralUUID))
ble._test_handlePacket(packet, fromPeerID: newPeerID, preseedPeer: false)
let rebound = await TestHelpers.waitUntil(
{ ble._test_centralBinding(centralUUID) == newPeerID },
timeout: TestConstants.defaultTimeout
)
#expect(rebound)
let retired = await TestHelpers.waitUntil(
{
let peerIDs = ble.currentPeerSnapshots().map(\.peerID)
return peerIDs.contains(newPeerID) && !peerIDs.contains(oldPeerID)
},
timeout: TestConstants.defaultTimeout
)
#expect(retired)
}
@Test
func replayedDirectAnnounceCannotStealBoundIdentity() async throws {
let ble = makeService()
let attackerPeerID = PeerID(str: "1122334455667788")
let victimLink = "central-victim"
let attackerLink = "central-attacker"
// The victim's identity, genuinely bound on its own link.
let victimSigner = NoiseEncryptionService(keychain: MockKeychain())
let announcement = AnnouncementPacket(
nickname: "victim",
noisePublicKey: victimSigner.getStaticPublicKeyData(),
signingPublicKey: victimSigner.getSigningPublicKeyData(),
directNeighbors: nil
)
let payload = try #require(announcement.encode(), "Failed to encode announcement")
let victimPeerID = PeerID(publicKey: announcement.noisePublicKey)
ble._test_seedConnectedPeer(victimPeerID, nickname: "victim")
ble._test_bindCentral(victimLink, to: victimPeerID)
ble._test_seedConnectedPeer(attackerPeerID, nickname: "attacker")
ble._test_bindCentral(attackerLink, to: attackerPeerID)
// The victim's fresh signed announce replayed on the attacker's bound
// link with its direct TTL restored (TTL is excluded from signing, so
// the signature still verifies).
let unsigned = BitchatPacket(
type: MessageType.announce.rawValue,
senderID: Data(hexString: victimPeerID.id) ?? Data(),
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload,
signature: nil,
ttl: 7
)
let packet = try #require(victimSigner.signPacket(unsigned), "Failed to sign announce packet")
#expect(ble._test_recordIngressIfNew(packet: packet, linkID: attackerLink))
ble._test_handlePacket(packet, fromPeerID: victimPeerID, preseedPeer: false)
// The rebind must be refused: the identity already owns a live link.
let stolen = await TestHelpers.waitUntil(
{ ble._test_centralBinding(attackerLink) == victimPeerID },
timeout: 0.3
)
#expect(!stolen)
#expect(ble._test_centralBinding(attackerLink) == attackerPeerID)
#expect(ble._test_centralBinding(victimLink) == victimPeerID)
// And the replay must not retire the link's real bound peer.
#expect(ble.currentPeerSnapshots().map(\.peerID).contains(attackerPeerID))
}
@Test
func ingressRejectsSelfLoopbackBeforeSpoofChecks() async throws {
let ble = makeService()