Files
fips/src
Johnathan Corgan b8a4449762 Refuse a ceiling frame counter and saturate the gap tracker
An authenticated peer sending a frame counter of u64::MAX pinned its own
replay window's high-water mark at the ceiling, after which every later
counter it sent fell more than a window below `highest` and was dropped,
wedging that peer's receive path until a rekey replaced the session. The
same counter overflowed the MMP gap tracker's expected-counter add, which
wraps to zero in a release build and aborts under a build with overflow
checks on.

Refuse the value in ReplayWindow::check, which covers the FSP session
paths and the off-task FMP decrypt worker in one place, and advance the
gap tracker with a saturating add. Neither send path in this tree can
emit u64::MAX, so no conforming peer notices; u64::MAX - 1, the highest
counter an honest peer can send, is unaffected.
2026-08-23 11:44:45 +01:00
..