From 8c65c3819aa6be3e42066847bcd5e42332dbba60 Mon Sep 17 00:00:00 2001 From: Johnathan Corgan Date: Thu, 1 Oct 2026 20:52:59 +0000 Subject: [PATCH] Changelog: second v0.5.3 landing batch Add the batch's user-facing changes to the Unreleased section: the native API descriptor hold and its flow lifetime, release-candidate .ipk versioning, the macOS encrypt worker wedge, the OpenWrt LAN bridge binding, the inbound connection idle deadline, verified coordinates kept against forged PathBroken signals, and the clearing of Noise hash state and key slots. --- CHANGELOG.md | 65 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 65 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 72d9d292..4f251afa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -17,6 +17,18 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 the release. The tarball, artifact and `.deb` file names keep the tag's `-rcN`. +#### Native datagram API + +- An accepted native API flow that its program closes without ever sending on + now stays open, holding its port and a slot against + `node.native_api.max_flows`, until its listener is closed. + +#### OpenWrt + +- Release-candidate OpenWrt `.ipk` packages are now versioned `vX.Y.Z~rcN`, so + opkg sorts them below the final release and the release upgrades a router + that ran the candidate. The package file name keeps the tag's `-rcN`. + #### Windows - `install-service.ps1` stops when `\etc\fips\fips.key` exists on the system @@ -71,6 +83,19 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - TCP connections try the remaining addresses for a hostname after a connection fails, within the existing overall connection timeout. +#### macOS + +- If an encrypt worker thread exits, the daemon no longer stops once that + worker's send queue fills. Packets for that worker are now dropped instead + of blocking forever. This applies to the default sender. + +#### Native datagram API + +- On macOS, a flow accepted through the native API could arrive already + closed, losing the peer's first datagram, when the kernel's descriptor + garbage collector ran before the client read the arrival message. The same + exposure on connect and listen replies is closed too. + #### OpenWrt - dnsmasq forwards `.fips` to fips-gateway only while the gateway is @@ -83,6 +108,13 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 stopped, keeps the gateway's state across an upgrade, and keeps an edited `/etc/fips/fips.yaml`. The SDK's package scan also no longer stops on the `Makefile`'s architecture check, which had kept the package out of the build. +- The shipped config and README now agree that the LAN Ethernet transport + binds the LAN bridge (`br-lan`). A socket on a bridge member port does not + receive FIPS frames, whether or not br_netfilter is loaded. If you followed + the earlier README and changed the `lan` entry in `/etc/fips/fips.yaml` to a + member port (for example `lan1` or `eth1`), change it back to `br-lan`. Your + edited config is kept across upgrades, along with its old "physical port + names, NOT bridge names" comment, so an upgrade alone will not correct it. #### Sessions and rekey @@ -124,6 +156,32 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Security +#### Links and transports + +- An inbound TCP or Tor onion connection is now dropped when it goes longer + than the node's own link-liveness bound without delivering a complete frame. + The bound is about 64 seconds at default settings. A remote that sends one + frame and then goes silent no longer holds an inbound connection slot + indefinitely. The bound follows `node.heartbeat_interval_secs`, + `node.link_dead_timeout_secs`, `node.tick_interval_secs` and the handshake + resend settings. + +#### Routing and discovery + +- A single forged or reflected `PathBroken` signal no longer deletes + coordinates a node verified by lookup. A verified entry is kept while a + fresh lookup re-validates it. It is demoted to an unverified hint only when + `PathBroken` signals naming the destination arrive over two different links + within 15 seconds. The vote is the authenticated link peer the signal + arrived over, not the reporter it names, so a sender on one link cannot + reach the quorum by inventing reporters. Forged reports that arrive over two + different links still demote the entry. The re-lookup now runs on every such + signal, and when the destination's identity is not cached the node first + caches it from the session's key so the answer can be verified. New + error-signal counters `broken_below_quorum`, `broken_demoted`, + `broken_link_mismatch` and `broken_reporter_mismatch` appear in + `show_routing`; the last two only count and never refuse a signal. + #### Sessions and rekey - A copy of a peer's link rekey msg1 can no longer stop link key rotation. A @@ -145,6 +203,13 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 address arrives. A msg1 from a node this one holds no link with, or one that carries a different startup epoch, still starts a new link and is answered at its source, as any new connection is. +- The SHA-256 and HMAC states used by the Noise handshake are now cleared when + dropped. The connection's handshake slot is cleared when a handshake + completes, and its session slot when a rekey session is taken out. The + handshake keypair is erased in place on every early return from starting a + handshake. The security reference now states what clearing key material in + memory does and does not cover in a release build, including copies left + behind by moves and the identity loaded from a secret string. ## [0.5.2] - 2026-09-28