From 6e0c150fc97785a229900088a0f58f40f5968eca Mon Sep 17 00:00:00 2001 From: riccardom Date: Fri, 9 Oct 2026 09:49:59 +0200 Subject: [PATCH] [client] pqkem: drop the unused exchangeCtl.pendingPSK field The responder wrote pendingPSK but nothing ever read it: the derived key is consumed via m.psks (set at the same time) and the cached answer via lastSent. Remove the field and its write to avoid a misleading store. Found in cubic review on #7098 (client/internal/pqkem/manager.go:90). --- client/internal/pqkem/convergence.go | 1 - client/internal/pqkem/manager.go | 22 ++++++++++------------ 2 files changed, 10 insertions(+), 13 deletions(-) diff --git a/client/internal/pqkem/convergence.go b/client/internal/pqkem/convergence.go index 76f21b8af..76a061bee 100644 --- a/client/internal/pqkem/convergence.go +++ b/client/internal/pqkem/convergence.go @@ -159,7 +159,6 @@ func (m *Manager) processOffer(remoteID RemoteID, o *OfferMsg, via string) ([]by } ex.state = stateAwaitingAck ex.lastSent = raw - ex.pendingPSK = psk gen := ex.gen m.psks[remoteID] = psk m.capable[remoteID] = true // a real KEM offer proves the peer runs the exchange diff --git a/client/internal/pqkem/manager.go b/client/internal/pqkem/manager.go index cb92a9b2e..ffaf02ffd 100644 --- a/client/internal/pqkem/manager.go +++ b/client/internal/pqkem/manager.go @@ -76,19 +76,17 @@ const ( // exchangeCtl holds all state for one in-flight exchange with a peer, under the // Manager's single lock. state drives every decision. lastSent is the current // data-path retransmit payload (the offer, for the initiator). initiator is the -// ephemeral handle used at Finish; pendingPSK is the responder's derived key. -// viaSignal records that the offer went to the host for the signalling channel, so -// the loop does not retransmit it on the data path. Only the initiator runs a -// retransmit loop, so only it sets cancel. +// ephemeral handle used at Finish. viaSignal records that the offer went to the host +// for the signalling channel, so the loop does not retransmit it on the data path. +// Only the initiator runs a retransmit loop, so only it sets cancel. type exchangeCtl struct { - id ExchangeID - state exchangeState - gen uint64 // local, per-peer monotonic generation; lets the host reject a stale PSK apply - cancel context.CancelFunc - lastSent []byte - initiator *Initiator - pendingPSK PSK - viaSignal bool + id ExchangeID + state exchangeState + gen uint64 // local, per-peer monotonic generation; lets the host reject a stale PSK apply + cancel context.CancelFunc + lastSent []byte + initiator *Initiator + viaSignal bool } // Manager is the stateful orchestrator — the analogue of go-rosenpass's Server. It