Files
bitchat/bitchatTests/Services/BLEIngressPacketGuardTests.swift
T
3e9230229d Heal peer-ID rotation: rebind link on verified announce, retire ghost peer (#1401)
* Heal peer-ID rotation: rebind link on verified announce, retire ghost

When a peer relaunches it rotates its ephemeral peer ID, but a
still-open BLE connection kept its stale peripheral/central→peerID
binding for the reachability retention window (~45-60s). Until it aged
out, the other side showed a duplicate ghost peer and dropped the
rotated peer's direct announces as spoofing attempts.

Root cause: the ingress guard rejected a direct announce whose claimed
sender differed from the link binding before signature verification
could ever see it, so the binding could never heal.

- Ingress guard: let a mismatched direct announce through, attributed
  to the claimed sender; REQUEST_SYNC keeps the strict binding check.
- Bind sites: raw (pre-verification) announces may only bind unbound
  links, never rebind bound ones — rebinding now requires the announce
  handler's signature verification to pass.
- On a verified direct announce whose ingress link is bound to a
  different peer, rebind the link to the announced ID and retire the
  rotated-away ID immediately (registry + gossip + UI), mirroring
  handleLeave.
- BLELinkStateStore.bindPeripheral: drop the previous peer's reverse
  mapping on rebind so the retired ID no longer claims the link.

Fixes #1387

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Contain forged-directness rebinds: no identity steal, per-link cooldown

The announce signature does not authenticate directness (TTL is
excluded from signing because relays mutate it), so a bound peer could
replay another peer's fresh signed announce with its TTL restored and
reach the rotation rebind path. Contain what such a replay can do:

- Refuse a rebind when the claimed identity already owns another live
  link — a replayed announce can no longer steal a connected peer's
  binding or route its directed traffic to the replaying link.
- Allow at most one rebind per link per cooldown window (60s) so two
  identities cannot fight over a link in a replay flip-flop, with each
  flip retiring the other peer.

A replay against an identity with no live link remains possible, but
that capability already exists today on unbound links, where any raw
direct announce binds pre-verification.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-08 10:08:23 +02:00

187 lines
6.7 KiB
Swift

import BitFoundation
import Foundation
import Testing
@testable import bitchat
@Suite("BLE ingress packet guard tests")
struct BLEIngressPacketGuardTests {
@Test("valid packets return the received and validation peer context")
func validPacketsReturnContext() throws {
let local = PeerID(str: "0011223344556677")
let bound = PeerID(str: "1122334455667788")
let sender = PeerID(str: "8899aabbccddeeff")
let packet = makePacket(sender: sender, timestamp: 1_000)
let context = try #require(success(BLEIngressPacketGuard.evaluate(
packet: packet,
claimedSenderID: sender,
boundPeerID: bound,
localPeerID: local,
directAnnounceTTL: 7,
nowMs: 1_000,
isValidSyncResponse: { _ in false }
)))
#expect(context.receivedFromPeerID == bound)
#expect(context.validationPeerID == sender)
}
@Test("self loopback and request-sync spoofing are rejected before timestamp checks")
func linkBindingRejectionsWinBeforeTimestampChecks() {
let local = PeerID(str: "0011223344556677")
let bound = PeerID(str: "1122334455667788")
let claimed = PeerID(str: "8899aabbccddeeff")
let selfPacket = makePacket(sender: local, timestamp: 0)
let spoofedRequestSync = makePacket(type: .requestSync, sender: claimed, timestamp: 0, ttl: 0)
let selfResult = BLEIngressPacketGuard.evaluate(
packet: selfPacket,
claimedSenderID: local,
boundPeerID: bound,
localPeerID: local,
directAnnounceTTL: 7,
nowMs: 1_000_000,
isValidSyncResponse: { _ in false }
)
let spoofResult = BLEIngressPacketGuard.evaluate(
packet: spoofedRequestSync,
claimedSenderID: claimed,
boundPeerID: bound,
localPeerID: local,
directAnnounceTTL: 7,
nowMs: 1_000_000,
isValidSyncResponse: { _ in false }
)
#expect(selfResult == .failure(.selfLoopback(packetType: MessageType.message.rawValue)))
#expect(spoofResult == .failure(.directSenderMismatch(boundPeerID: bound, claimedSenderID: claimed)))
}
@Test("direct announce with a mismatched binding flows through to normal validation")
func directAnnounceMismatchStillValidatesTimestamp() throws {
// Rotation heal path: the announce passes the binding check attributed
// to the claimed sender, but stays subject to timestamp validation.
let local = PeerID(str: "0011223344556677")
let bound = PeerID(str: "1122334455667788")
let claimed = PeerID(str: "8899aabbccddeeff")
let freshAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 1_000_000, ttl: 7)
let staleAnnounce = makePacket(type: .announce, sender: claimed, timestamp: 0, ttl: 7)
let freshContext = try #require(success(BLEIngressPacketGuard.evaluate(
packet: freshAnnounce,
claimedSenderID: claimed,
boundPeerID: bound,
localPeerID: local,
directAnnounceTTL: 7,
nowMs: 1_000_000,
isValidSyncResponse: { _ in false }
)))
let staleResult = BLEIngressPacketGuard.evaluate(
packet: staleAnnounce,
claimedSenderID: claimed,
boundPeerID: bound,
localPeerID: local,
directAnnounceTTL: 7,
nowMs: 1_000_000,
isValidSyncResponse: { _ in false }
)
#expect(freshContext.receivedFromPeerID == claimed)
#expect(freshContext.validationPeerID == claimed)
#expect(staleResult == .failure(.timestampSkew(
peerID: claimed,
skewMs: 1_000_000,
maxSkewMs: 120_000
)))
}
@Test("timestamp skew outside the window is rejected")
func timestampSkewIsRejected() {
let local = PeerID(str: "0011223344556677")
let sender = PeerID(str: "1122334455667788")
let packet = makePacket(sender: sender, timestamp: 1_000)
let result = BLEIngressPacketGuard.evaluate(
packet: packet,
claimedSenderID: sender,
boundPeerID: nil,
localPeerID: local,
directAnnounceTTL: 7,
nowMs: 200_000,
maxTimestampSkewMs: 120_000,
isValidSyncResponse: { _ in false }
)
#expect(result == .failure(.timestampSkew(
peerID: sender,
skewMs: 199_000,
maxSkewMs: 120_000
)))
}
@Test("valid RSR packets use bound peer validation and bypass timestamp skew")
func validRSRUsesBoundPeerAndBypassesTimestamp() throws {
let local = PeerID(str: "0011223344556677")
let bound = PeerID(str: "1122334455667788")
let sender = PeerID(str: "8899aabbccddeeff")
var packet = makePacket(sender: sender, timestamp: 1)
packet.isRSR = true
let context = try #require(success(BLEIngressPacketGuard.evaluate(
packet: packet,
claimedSenderID: sender,
boundPeerID: bound,
localPeerID: local,
directAnnounceTTL: 7,
nowMs: 1_000_000,
isValidSyncResponse: { $0 == bound }
)))
#expect(context.receivedFromPeerID == bound)
#expect(context.validationPeerID == bound)
}
@Test("invalid RSR packets are rejected")
func invalidRSRIsRejected() {
let local = PeerID(str: "0011223344556677")
let bound = PeerID(str: "1122334455667788")
let sender = PeerID(str: "8899aabbccddeeff")
var packet = makePacket(sender: sender, timestamp: 1)
packet.isRSR = true
let result = BLEIngressPacketGuard.evaluate(
packet: packet,
claimedSenderID: sender,
boundPeerID: bound,
localPeerID: local,
directAnnounceTTL: 7,
nowMs: 1_000_000,
isValidSyncResponse: { _ in false }
)
#expect(result == .failure(.invalidRSR(peerID: bound)))
}
private func makePacket(
type: MessageType = .message,
sender: PeerID,
timestamp: UInt64,
ttl: UInt8 = 3
) -> BitchatPacket {
BitchatPacket(
type: type.rawValue,
senderID: Data(hexString: sender.id) ?? Data(),
recipientID: nil,
timestamp: timestamp,
payload: Data([0x01, 0x02, 0x03]),
signature: nil,
ttl: ttl
)
}
private func success(_ result: Result<BLEIngressPacketContext, BLEIngressPacketGuard.Rejection>) -> BLEIngressPacketContext? {
guard case .success(let context) = result else { return nil }
return context
}
}