[client] pqkem: carry a generation on PSK callbacks to drop stale applies

OnNewPSKReady could be applied out of order: two exchanges for a peer can derive
concurrently (one over signal, one over the data path), and the callbacks run
outside the manager lock, so an older exchange's apply could land after a newer
one and restore a stale WireGuard PSK, splitting the tunnel.

Give each exchange a per-peer monotonic generation, assigned under the lock at
creation so a later exchange always carries a higher one, and pass it to
OnNewPSKReady. The host adapter records the newest generation applied per peer
and drops any callback that is not newer, with the check-and-record atomic so the
slow SetPresharedKey call stays off that lock.

Found in cubic review on #7098 (client/internal/pqkem/callbacks.go:12).
This commit is contained in:
riccardom
2026-10-07 13:30:52 +02:00
parent d0f7e2ac7a
commit 1182239faa
7 changed files with 90 additions and 40 deletions
+2 -1
View File
@@ -589,7 +589,8 @@ func (e *Engine) startPQKEMManager(publicKey wgtypes.Key) error {
return nil
}
cbHandler := pqCallbackHandler{
wg: e.wgInterface,
wg: e.wgInterface,
applied: newAppliedGenerations(),
// On a persistent rekey failure, re-bootstrap the KEM over Signal: a fresh
// signalling offer starts a new exchange that overwrites the stalled PSK on both
// sides, recovering from a data-path desync.