mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
An authenticated peer sending a frame counter of u64::MAX pinned its own replay window's high-water mark at the ceiling, after which every later counter it sent fell more than a window below `highest` and was dropped, wedging that peer's receive path until a rekey replaced the session. The same counter overflowed the MMP gap tracker's expected-counter add, which wraps to zero in a release build and aborts under a build with overflow checks on. Refuse the value in ReplayWindow::check, which covers the FSP session paths and the off-task FMP decrypt worker in one place, and advance the gap tracker with a saturating add. Neither send path in this tree can emit u64::MAX, so no conforming peer notices; u64::MAX - 1, the highest counter an honest peer can send, is unaffected.