Files
fips/src/node
Johnathan Corgan f7085f2ed7 Confirm the peer identity after the handshake, not just the address
An inbound setup message from the address of an established peer is admitted
even when the node is configured to refuse inbound connections. That carve-out
exists so a peer that re-handshakes is not locked out, but it decided purely on
the address, so an off-path party sourcing from that address was admitted too.

The waiver now classifies into three outcomes rather than two: no waiver was
needed, a waiver was used and an owning identity is known, or a waiver was used
and no identity owns the link. The third rejects after the key exchange. An
earlier shape returned nothing for that case, which silently skipped the check
for an ordinary population, which is the defect this change exists to close.

The address lookup deliberately falls through rather than returning when it
finds no owning identity. The reverse lookup can name a link that no longer
exists, because removal clears it only under the key rebuilt from the link's
own address, while the cross-connection path inserts a second key from the
observed source address. Returning there would refuse a peer the address scan
can still attribute, and refuse it permanently: the confirmation returns above
the insert that repairs the map, so nothing downstream would ever fix it.

Six tests, each broken to prove it can fail. The refusing transport is a real
bound socket rather than the loopback handle, which has no refuse override, so
"no response was sent" is an observation on a wire rather than a property of a
transport that was never started.
2026-08-16 16:34:40 +00:00
..