Sign plaintext packets in licensed mode (#10969)

* feat: sign licensed plaintext packets

Preserve and publish identity keys in licensed mode so existing XEdDSA signatures can authenticate plaintext traffic. Sign licensed broadcasts and direct messages when they fit, while keeping PKI encryption disabled and normal routing behavior unchanged.

* fix(security): persist licensed channel sanitation

* fix(security): close licensed migration lifecycle gaps

* fix(security): address licensed signing review feedback

* test: restore signing globals from Unity teardown

* fix(baseui): allow confirmed ham region selection

* fix(baseui): guard region picker validation

* style: trunk fmt

---------

Co-authored-by: Ben Meadors <benmmeadors@gmail.com>
Co-authored-by: Austin <vidplace7@gmail.com>
This commit is contained in:
authored and GitHub committed 2026-07-27 02:57:15 +00:00
1 parent 45cb8e7500
commit 1e982fa78c
15 files changed
+576 -49

No files matched your search

+2 -8
View File
@@ -169,14 +169,8 @@ meshtastic_MeshPacket *NodeInfoModule::allocReply()
ignoreRequest = true;
return NULL;
} else {
ignoreRequest = false; // Don't ignore requests anymore
meshtastic_User u = owner; // deliberate copy: the licensed strip below must not clobber the global owner state
// Strip the public key if the user is licensed
if (u.is_licensed && u.public_key.size > 0) {
memset(u.public_key.bytes, 0, sizeof(u.public_key.bytes));
u.public_key.size = 0;
}
ignoreRequest = false; // Don't ignore requests anymore
meshtastic_User u = owner;
// FIXME: Clear the user.id field since it should be derived from node number on the receiving end
// u.id[0] = '\0';