Files
fips/src
Johnathan Corgan bde5d797ac Retire an FSP rekey this node started when its setup or ack is lost
A session rekey this node initiated could end only on a SessionAck, a
lost tie-break, cutover or session removal. The only expiry for an armed
rekey handshake covered one the peer armed, timed from the peer's setup
message, and no rekey SessionSetup is ever resent. One lost SessionSetup
or SessionAck therefore left the rekey in flight for good, and a rekey in
flight vetoes the trigger that would start another: the session kept
running on its current keys and stopped rotating them. Where this node
has the smaller address it also drops the peer's own setup on the
tie-break, leaving the peer stuck the same way.

The handshake now carries its own deadline, taken when this node sends
its setup, and expires on the handshake timeout as one the peer armed
does. Only the handshake is dropped, so the next tick starts a fresh
rekey. Putting the handshake back after an unreadable SessionAck does not
restart the deadline, so forged acks cannot hold the rekey open. The
expiry for a handshake the peer armed is unchanged, and neither expiry
reads the other side's clock. The retirement is logged and counted in a
new rekey_unanswered session counter.

The unit test that expected an expired rekey of our own to be left alone
is replaced. Its reasoning, that the msg3 retransmission budget bounds
the cycle, holds only once msg2 has been read. No wire format change.
2026-09-22 21:43:24 +00:00
..