Files
fips/src/discovery
Johnathan Corgan 957cd94bb0 Accept a punch packet only from an address we planned to probe
The NAT-punch packet's discriminator is a plain digest of the session id, a
value both peers already know, and it travels in the clear in every probe, so
a matching packet proved only that its sender had seen one. The receive loop
broke on the first packet whose digest matched, whatever its source, and
returned that source as the peer address. Anyone who observed a probe could
therefore have an arbitrary address adopted as the peer: the legitimate
traversal was denied, the handshake and its retransmissions went to an address
of the attacker's choosing, and the pair was charged a failure against its
backoff state.

The source address is now ranked against the planned target list before
anything else happens with the packet. An unplanned source is dropped and is
deliberately not acked either, since acking it is a reflection this node
controls. A source matching a planned target exactly is adopted immediately,
as before. A source matching a planned target's IP on a different port is what
a symmetric NAT's fresh mapping toward us looks like, so it is still adopted
rather than dropped, because that is the main class of NAT pairing punching
exists to rescue; it is held as a candidate for a settle window first, so an
exact match arriving inside that window supersedes it. The honest path returns
as fast as it did.

Two consequences to state rather than discover. A sender able to source
packets from a planned target's IP on any port is still accepted, which is the
residue that only an authenticated probe can close. And an attempt under a
flood of spoofed matching packets now runs to its full timeout instead of
ending on the first one, so refused sources are counted and reported once when
the attempt ends rather than logged per packet.
2026-08-23 11:46:02 +01:00
..