mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-26 21:25:22 +00:00
Heal peer-ID rotation: rebind link on verified announce, retire ghost peer (#1401)
* Heal peer-ID rotation: rebind link on verified announce, retire ghost When a peer relaunches it rotates its ephemeral peer ID, but a still-open BLE connection kept its stale peripheral/central→peerID binding for the reachability retention window (~45-60s). Until it aged out, the other side showed a duplicate ghost peer and dropped the rotated peer's direct announces as spoofing attempts. Root cause: the ingress guard rejected a direct announce whose claimed sender differed from the link binding before signature verification could ever see it, so the binding could never heal. - Ingress guard: let a mismatched direct announce through, attributed to the claimed sender; REQUEST_SYNC keeps the strict binding check. - Bind sites: raw (pre-verification) announces may only bind unbound links, never rebind bound ones — rebinding now requires the announce handler's signature verification to pass. - On a verified direct announce whose ingress link is bound to a different peer, rebind the link to the announced ID and retire the rotated-away ID immediately (registry + gossip + UI), mirroring handleLeave. - BLELinkStateStore.bindPeripheral: drop the previous peer's reverse mapping on rebind so the retired ID no longer claims the link. Fixes #1387 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Contain forged-directness rebinds: no identity steal, per-link cooldown The announce signature does not authenticate directness (TTL is excluded from signing because relays mutate it), so a bound peer could replay another peer's fresh signed announce with its TTL restored and reach the rotation rebind path. Contain what such a replay can do: - Refuse a rebind when the claimed identity already owns another live link — a replayed announce can no longer steal a connected peer's binding or route its directed traffic to the replaying link. - Allow at most one rebind per link per cooldown window (60s) so two identities cannot fight over a link in a replay flip-flop, with each flip retiring the other peer. A replay against an identity with no live link remains possible, but that capability already exists today on unbound links, where any raw direct announce binds pre-verification. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: jack <jackjackbits@users.noreply.github.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
jack
Claude Fable 5
parent
78a291ab77
commit
3e9230229d
@@ -88,21 +88,46 @@ struct BLEIngressLinkRegistryTests {
|
||||
}
|
||||
|
||||
@Test
|
||||
func packetContextRejectsDirectAnnounceMismatchOnBoundLink() {
|
||||
func packetContextAttributesDirectAnnounceMismatchToClaimedSender() throws {
|
||||
// A rotated peer re-announces its new ID on a link still bound to the
|
||||
// old one. The announce must flow through (attributed to the claimed
|
||||
// sender) so signature verification can decide whether to rebind.
|
||||
let localPeer = PeerID(str: "0011223344556677")
|
||||
let boundPeer = PeerID(str: "1122334455667788")
|
||||
let claimedPeer = PeerID(str: "8899aabbccddeeff")
|
||||
let packet = makeAnnouncePacket(sender: claimedPeer, ttl: 7)
|
||||
|
||||
let result = BLEIngressLinkRegistry.packetContext(
|
||||
let context = try #require(trySuccess(BLEIngressLinkRegistry.packetContext(
|
||||
for: packet,
|
||||
claimedSenderID: claimedPeer,
|
||||
boundPeerID: boundPeer,
|
||||
localPeerID: localPeer,
|
||||
directAnnounceTTL: 7
|
||||
)
|
||||
)))
|
||||
|
||||
#expect(result == .failure(.directSenderMismatch(boundPeerID: boundPeer, claimedSenderID: claimedPeer)))
|
||||
#expect(context.receivedFromPeerID == claimedPeer)
|
||||
#expect(context.validationPeerID == claimedPeer)
|
||||
}
|
||||
|
||||
@Test
|
||||
func packetContextAttributesRelayedAnnounceMismatchToBoundPeer() throws {
|
||||
// Relayed announces (ttl below direct) keep relayed attribution: the
|
||||
// link peer forwarded someone else's announce.
|
||||
let localPeer = PeerID(str: "0011223344556677")
|
||||
let boundPeer = PeerID(str: "1122334455667788")
|
||||
let claimedPeer = PeerID(str: "8899aabbccddeeff")
|
||||
let packet = makeAnnouncePacket(sender: claimedPeer, ttl: 6)
|
||||
|
||||
let context = try #require(trySuccess(BLEIngressLinkRegistry.packetContext(
|
||||
for: packet,
|
||||
claimedSenderID: claimedPeer,
|
||||
boundPeerID: boundPeer,
|
||||
localPeerID: localPeer,
|
||||
directAnnounceTTL: 7
|
||||
)))
|
||||
|
||||
#expect(context.receivedFromPeerID == boundPeer)
|
||||
#expect(context.validationPeerID == claimedPeer)
|
||||
}
|
||||
|
||||
@Test
|
||||
|
||||
@@ -26,13 +26,13 @@ struct BLEIngressPacketGuardTests {
|
||||
#expect(context.validationPeerID == sender)
|
||||
}
|
||||
|
||||
@Test("self loopback and direct announce spoofing are rejected before timestamp checks")
|
||||
@Test("self loopback and request-sync spoofing are rejected before timestamp checks")
|
||||
func linkBindingRejectionsWinBeforeTimestampChecks() {
|
||||
let local = PeerID(str: "0011223344556677")
|
||||
let bound = PeerID(str: "1122334455667788")
|
||||
let claimed = PeerID(str: "8899aabbccddeeff")
|
||||
let selfPacket = makePacket(sender: local, timestamp: 0)
|
||||
let spoofedAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 0, ttl: 7)
|
||||
let spoofedRequestSync = makePacket(type: .requestSync, sender: claimed, timestamp: 0, ttl: 0)
|
||||
|
||||
let selfResult = BLEIngressPacketGuard.evaluate(
|
||||
packet: selfPacket,
|
||||
@@ -44,7 +44,7 @@ struct BLEIngressPacketGuardTests {
|
||||
isValidSyncResponse: { _ in false }
|
||||
)
|
||||
let spoofResult = BLEIngressPacketGuard.evaluate(
|
||||
packet: spoofedAnnounce,
|
||||
packet: spoofedRequestSync,
|
||||
claimedSenderID: claimed,
|
||||
boundPeerID: bound,
|
||||
localPeerID: local,
|
||||
@@ -57,6 +57,44 @@ struct BLEIngressPacketGuardTests {
|
||||
#expect(spoofResult == .failure(.directSenderMismatch(boundPeerID: bound, claimedSenderID: claimed)))
|
||||
}
|
||||
|
||||
@Test("direct announce with a mismatched binding flows through to normal validation")
|
||||
func directAnnounceMismatchStillValidatesTimestamp() throws {
|
||||
// Rotation heal path: the announce passes the binding check attributed
|
||||
// to the claimed sender, but stays subject to timestamp validation.
|
||||
let local = PeerID(str: "0011223344556677")
|
||||
let bound = PeerID(str: "1122334455667788")
|
||||
let claimed = PeerID(str: "8899aabbccddeeff")
|
||||
let freshAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 1_000_000, ttl: 7)
|
||||
let staleAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 0, ttl: 7)
|
||||
|
||||
let freshContext = try #require(success(BLEIngressPacketGuard.evaluate(
|
||||
packet: freshAnnounce,
|
||||
claimedSenderID: claimed,
|
||||
boundPeerID: bound,
|
||||
localPeerID: local,
|
||||
directAnnounceTTL: 7,
|
||||
nowMs: 1_000_000,
|
||||
isValidSyncResponse: { _ in false }
|
||||
)))
|
||||
let staleResult = BLEIngressPacketGuard.evaluate(
|
||||
packet: staleAnnounce,
|
||||
claimedSenderID: claimed,
|
||||
boundPeerID: bound,
|
||||
localPeerID: local,
|
||||
directAnnounceTTL: 7,
|
||||
nowMs: 1_000_000,
|
||||
isValidSyncResponse: { _ in false }
|
||||
)
|
||||
|
||||
#expect(freshContext.receivedFromPeerID == claimed)
|
||||
#expect(freshContext.validationPeerID == claimed)
|
||||
#expect(staleResult == .failure(.timestampSkew(
|
||||
peerID: claimed,
|
||||
skewMs: 1_000_000,
|
||||
maxSkewMs: 120_000
|
||||
)))
|
||||
}
|
||||
|
||||
@Test("timestamp skew outside the window is rejected")
|
||||
func timestampSkewIsRejected() {
|
||||
let local = PeerID(str: "0011223344556677")
|
||||
|
||||
Reference in New Issue
Block a user