mirror of
https://github.com/meshtastic/firmware.git
synced 2026-09-30 18:25:21 -04:00
Bound remote-initiated key verification sessions (#11101)
* Bound remote-initiated key verification sessions Opening a session raises a 30 second banner and a client notification and occupies the only verification slot, all before the peer has authenticated anything, and nothing limited how often that could happen. Adds an absolute session cap that incoming packets cannot refresh, a cooldown between remote-initiated sessions measured from when the previous one ended, and refreshes the idle deadline only when the protocol actually advances rather than on any arriving packet. The busy path now sets ignoreRequest so it no longer answers with a NAK. Also replaces the getTime() - 60 timeout comparison, which underflowed before the clock passed 60. * Use elapsed-time comparison for the session timeout and condense comments
This commit is contained in:
1 parent
d9f8839241
commit
53e510199a
2 files changed
+38
-5
No files matched your search
@@ -84,6 +84,12 @@ class KeyVerificationModule : public ProtobufModule<meshtastic_KeyVerification>
|
||||
private:
|
||||
uint64_t currentNonce = 0;
|
||||
uint32_t currentNonceTimestamp = 0;
|
||||
// millis() the session opened, never refreshed, so a peer cannot hold the slot open indefinitely.
|
||||
uint32_t sessionStartedMs = 0;
|
||||
// millis() a remote-initiated session last ended. Spacing sessions bounds the slot DoS and the
|
||||
// banner spam; stamped at the end rather than the start so the cooldown is a real gap.
|
||||
uint32_t lastRemoteSessionMs = 0;
|
||||
bool sessionFromRemote = false;
|
||||
NodeNum currentRemoteNode = 0;
|
||||
uint32_t currentSecurityNumber = 0;
|
||||
KeyVerificationState currentState = KEY_VERIFICATION_IDLE;
|
||||
|
||||
Reference in new issue
Block a user