Preserve early Noise ciphertext across reconnect promotion (#1464)

Companion to #1463 (they were built as a unit): adds a bounded deferral buffer (4/peer, 32 global, byte-budgeted, responder-timeout lifetime) for ciphertext that arrives before XX message 3 or before BLE installs generation-bound transport state, retried exactly once after the serialized authentication/restore callback. Reclassifies malformed/forged/replayed/oversized/rate-limited ciphertext as drop-only, so attacker bytes can no longer evict an established session (on main, a 1-byte forgery evicts the session via the old clearSession + re-handshake path). Serializes Noise packet reception as messageQueue barriers.

Honors #1463's timeout-restore deferral through the same-generation ready path (verified by negative test: without the gate, parked DMs drain under discarded keys). Full local suite 1789 tests green.
This commit is contained in:
jack
2026-07-26 13:30:06 +02:00
committed by GitHub
parent 78a81e5b57
commit e3e97d51ec
7 changed files with 1458 additions and 40 deletions
@@ -1352,6 +1352,89 @@ struct NoiseEncryptionServiceTests {
}
}
@Test("Responder completion state spans ordinary XX message three")
func responderCompletionStateTracksOrdinaryHandshake() throws {
let alice = NoiseEncryptionService(keychain: MockKeychain())
let bob = NoiseEncryptionService(keychain: MockKeychain())
let alicePeerID = PeerID(
publicKey: alice.getStaticPublicKeyData()
)
let bobPeerID = PeerID(publicKey: bob.getStaticPublicKeyData())
let message1 = try alice.initiateHandshake(with: bobPeerID)
#expect(
!bob.isAwaitingResponderHandshakeCompletion(with: alicePeerID)
)
let message2 = try #require(
try bob.processHandshakeMessage(
from: alicePeerID,
message: message1
)
)
#expect(
bob.isAwaitingResponderHandshakeCompletion(with: alicePeerID)
)
let message3 = try #require(
try alice.processHandshakeMessage(
from: bobPeerID,
message: message2
)
)
#expect(
bob.isAwaitingResponderHandshakeCompletion(with: alicePeerID)
)
_ = try bob.processHandshakeMessage(
from: alicePeerID,
message: message3
)
#expect(
!bob.isAwaitingResponderHandshakeCompletion(with: alicePeerID)
)
}
@Test("Transport readiness rejection spends no message budget")
func transportReadinessRejectionSpendsNoMessageBudget() throws {
let alice = NoiseEncryptionService(keychain: MockKeychain())
let bob = NoiseEncryptionService(keychain: MockKeychain())
let alicePeerID = PeerID(
publicKey: alice.getStaticPublicKeyData()
)
let bobPeerID = PeerID(publicKey: bob.getStaticPublicKeyData())
try establishSessions(alice: alice, bob: bob)
let plaintext = Data([
NoisePayloadType.privateMessage.rawValue,
0xAB, 0xCD
])
let ciphertext = try alice.encrypt(plaintext, for: bobPeerID)
for _ in 0...NoiseSecurityConstants.maxMessagesPerSecond {
do {
_ = try bob.decryptWithSessionGeneration(
ciphertext,
from: alicePeerID,
establishedGenerationIsReady: { _ in false }
)
Issue.record(
"Expected transport generation readiness rejection"
)
} catch NoiseEncryptionError.transportGenerationNotReady {
// Expected: authorization and nonce mutation are both later.
} catch {
Issue.record("Unexpected readiness error: \(error)")
}
}
let decrypted = try bob.decryptWithSessionGeneration(
ciphertext,
from: alicePeerID,
establishedGenerationIsReady: { _ in true }
)
#expect(decrypted.plaintext == plaintext)
}
@Test("NoiseMessage JSON and binary encoding round-trip")
func noiseMessageRoundTrips() throws {
let message = NoiseMessage(