mirror of
https://github.com/jmcorgan/fips.git
synced 2026-08-11 17:17:54 +00:00
peer: move the Noise handshake operations onto the control machine
The pending connection drove its own Noise handshake while the control machine held it, so the crypto and the state it produces lived on the carrier that is going away. Move the six operations onto the machine: starting and completing an initiation, processing an inbound initiation, taking the session, testing for one, and dropping the handle on failure. Bodies are unchanged apart from reaching the handles through the attached connection. Each operation now records its results on both carriers. The learned identity, the remote epoch, and the activity stamp are written to the machine's own bookkeeping at the same point and with the same value as they are written to the connection's. The connection's copies still have readers until those reads are repointed, so both have to be written; the machine's copy of the learned identity was previously never populated for an inbound connection, which is why an inbound pending row showed no expected peer. Driving the handshake from the machine means the machine has to exist before the crypto runs. On the inbound path it is built above the message-1 processing and still kept local, so a rejected message leaves no registry entry and allocates no index. On the outbound path it already existed from the dial, so it simply takes the connection before the index allocation, and both failure arms unwind it as they did. Completing message 2 no longer mirrors the activity stamp separately, since the completion itself now writes both carriers at the point the mirror was approximating. Three tests cover what the compiler cannot. A connection whose handshake failed holds neither Noise handle yet must stay visible to the stale-connection sweep, or every failed connection would leak and hold a peering-budget slot forever. A message 1 rejected by the crypto or by the ACL must leave no machine, no index, and the same rejection count as before. A dial whose message-1 preparation fails must unwind the machine registered at dial time; that test drives the index-allocation failure rather than a crypto failure, which is the arm this change actually widens, since the allocation now happens with the connection already attached.
This commit is contained in:
@@ -131,7 +131,8 @@ pub(super) async fn initiate_handshake(nodes: &mut [TestNode], i: usize, j: usiz
|
||||
let startup_epoch = initiator.node.startup_epoch();
|
||||
let noise_msg1 = initiator
|
||||
.node
|
||||
.get_connection_mut(&link_id)
|
||||
.peer_machines
|
||||
.get_mut(&link_id)
|
||||
.unwrap()
|
||||
.start_handshake(our_keypair, startup_epoch, 1000)
|
||||
.unwrap();
|
||||
|
||||
Reference in New Issue
Block a user