mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-25 16:05:19 +00:00
Prekeys: authenticate bundle packets, fix consume-republish, deflake CI
Fixes the prekey-bundle PR review + CI failure: - CI root cause: the receive queue (mesh.message) is concurrent, so a gossiped prekey bundle can be processed before the announce that binds its owner's signing key. The old handler dropped such bundles outright, so under CI parallel load the bundle was permanently lost and the cache/gossip tests flaked (verifiedBundleEntersGossipStore, prekeySealedMailTravelsViaCourierAndOpens). Bundles that arrive before their binding are now retained per-owner (bounded) and re-attempted when the verified announce lands, atomically to avoid a check-then-act race. - Authenticate the OUTER prekey-bundle packet (Codex P2 / review MEDIUM): require senderID == PeerID(bundle.noiseStaticPublicKey) and verify the packet's Ed25519 signature (covers senderID + timestamp) against the owner's bound signing key, in addition to the inner bundle signature. Stops replay under a fresh timestamp / fake senderID. - Key the gossip prekey-bundle store/dedup by the bundle's authenticated identity (noiseStaticPublicKey), not the unauthenticated packet senderID, so one valid bundle sprayed under many fabricated sender IDs can't multiply entries and exhaust the 200-owner cap. - Bump published-bundle generatedAt strictly on consume (Codex P1): consuming a prekey shrinks the published bundle, so it now republishes with a strictly newer generatedAt and re-gossips, so peers replace the cached copy and stop assigning the consumed ID before its 48h grace. - Guard the panic/clear detached Application Support tree-deletes behind TestEnvironment.isRunningTests: the SPM test process shares that tree, so the wipe could land mid-test and flake file-dependent tests. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -329,4 +329,71 @@ struct PrekeyEndToEndTests {
|
||||
// The verified bundle now participates in Alice's sync rounds.
|
||||
#expect(alice._test_hasGossipPrekeyBundle(for: bob.myPeerID))
|
||||
}
|
||||
|
||||
@Test func spoofedSenderPrekeyBundleIsRejected() async throws {
|
||||
let alice = makeService()
|
||||
let bob = makeService()
|
||||
|
||||
let bobOut = PacketTap()
|
||||
bob._test_onOutboundPacket = bobOut.record
|
||||
|
||||
let (announce, bundlePacket) = try await captureAnnounceAndBundle(from: bob, tap: bobOut)
|
||||
alice._test_handlePacket(announce, fromPeerID: bob.myPeerID, preseedPeer: false)
|
||||
|
||||
// A relay re-broadcasts Bob's genuine bundle under a fabricated sender
|
||||
// ID (the DoS that would multiply cache/gossip entries and exhaust the
|
||||
// per-owner cap). Attribution is by the bundle's own key and the outer
|
||||
// signature is bound to Bob's sender ID, so the spoof is dropped — no
|
||||
// cache entry, and no gossip entry under either the fake or real ID.
|
||||
let fakeSender = Data((0..<8).map { _ in UInt8.random(in: 0...255) })
|
||||
let spoofed = BitchatPacket(
|
||||
type: MessageType.prekeyBundle.rawValue,
|
||||
senderID: fakeSender,
|
||||
recipientID: nil,
|
||||
timestamp: bundlePacket.timestamp + 5_000,
|
||||
payload: bundlePacket.payload,
|
||||
signature: bundlePacket.signature,
|
||||
ttl: bundlePacket.ttl
|
||||
)
|
||||
alice._test_handlePacket(spoofed, fromPeerID: PeerID(hexData: fakeSender), preseedPeer: false)
|
||||
|
||||
let cached = await TestHelpers.waitUntil(
|
||||
{ alice.prekeyBundleStore.hasUsableBundle(for: bob.noiseStaticPublicKeyData()) },
|
||||
timeout: TestConstants.shortTimeout
|
||||
)
|
||||
#expect(!cached)
|
||||
#expect(!alice._test_hasGossipPrekeyBundle(for: bob.myPeerID))
|
||||
#expect(!alice._test_hasGossipPrekeyBundle(for: PeerID(hexData: fakeSender)))
|
||||
}
|
||||
|
||||
@Test func replayedPrekeyBundleWithFreshTimestampIsRejected() async throws {
|
||||
let alice = makeService()
|
||||
let bob = makeService()
|
||||
|
||||
let bobOut = PacketTap()
|
||||
bob._test_onOutboundPacket = bobOut.record
|
||||
|
||||
let (announce, bundlePacket) = try await captureAnnounceAndBundle(from: bob, tap: bobOut)
|
||||
alice._test_handlePacket(announce, fromPeerID: bob.myPeerID, preseedPeer: false)
|
||||
|
||||
// Rewriting the outer timestamp (to defeat the freshness window)
|
||||
// invalidates the packet signature, which covers senderID + timestamp.
|
||||
let replay = BitchatPacket(
|
||||
type: MessageType.prekeyBundle.rawValue,
|
||||
senderID: bundlePacket.senderID,
|
||||
recipientID: nil,
|
||||
timestamp: bundlePacket.timestamp + 5_000,
|
||||
payload: bundlePacket.payload,
|
||||
signature: bundlePacket.signature,
|
||||
ttl: bundlePacket.ttl
|
||||
)
|
||||
alice._test_handlePacket(replay, fromPeerID: bob.myPeerID, preseedPeer: false)
|
||||
|
||||
let cached = await TestHelpers.waitUntil(
|
||||
{ alice.prekeyBundleStore.hasUsableBundle(for: bob.noiseStaticPublicKeyData()) },
|
||||
timeout: TestConstants.shortTimeout
|
||||
)
|
||||
#expect(!cached)
|
||||
#expect(!alice._test_hasGossipPrekeyBundle(for: bob.myPeerID))
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user