pqkem: clock data-path PSK rotation from WireGuard handshakes

Source OnDataPathRekeyed from the WGWatcher's per-handshake callback
(onWGCheckSuccess), which fires only on a fresh handshake, and OnDataPathDown
from the handshake-timeout path. A fresh handshake clocks the next chained
KEM exchange pushed over the data-path UDP transport.
This commit is contained in:
riccardom
2026-09-11 14:48:54 +02:00
parent e3ab585c56
commit 1c46b4e9df
2 changed files with 24 additions and 0 deletions
+10
View File
@@ -90,3 +90,13 @@ func (p pqHandshaker) SetRemotePort(remoteKey string, overlayIP netip.Addr, port
}
p.mgr.AddPeer(pqkem.RemoteID(remoteKey), netip.AddrPortFrom(overlayIP, uint16(port)))
}
// OnDataPathRekeyed clocks the next chained PSK rotation on a fresh WG handshake.
func (p pqHandshaker) OnDataPathRekeyed(remoteKey string) {
p.mgr.OnDataPathRekeyed(pqkem.RemoteID(remoteKey))
}
// OnDataPathDown signals the peer's tunnel went down.
func (p pqHandshaker) OnDataPathDown(remoteKey string) {
p.mgr.OnDataPathDown(pqkem.RemoteID(remoteKey))
}