mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
An inbound setup message from the address of an established peer is admitted even when the node is configured to refuse inbound connections. That carve-out exists so a peer that re-handshakes is not locked out, but it decided purely on the address, so an off-path party sourcing from that address was admitted too. The waiver now classifies into three outcomes rather than two: no waiver was needed, a waiver was used and an owning identity is known, or a waiver was used and no identity owns the link. The third rejects after the key exchange. An earlier shape returned nothing for that case, which silently skipped the check for an ordinary population, which is the defect this change exists to close. The address lookup deliberately falls through rather than returning when it finds no owning identity. The reverse lookup can name a link that no longer exists, because removal clears it only under the key rebuilt from the link's own address, while the cross-connection path inserts a second key from the observed source address. Returning there would refuse a peer the address scan can still attribute, and refuse it permanently: the confirmation returns above the insert that repairs the map, so nothing downstream would ever fix it. Six tests, each broken to prove it can fail. The refusing transport is a real bound socket rather than the loopback handle, which has no refuse override, so "no response was sent" is an observation on a wire rather than a property of a transport that was never started.