mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-06 13:39:07 +02:00
[client] pqkem: address review findings on convergence, strict parsing and status
Bot review (CodeRabbit, cubic) on PR #7098 surfaced several real defects: - Strict() parsed the raw env value instead of the normalized one, so a mixed-case NB_PQ_MLKEM_STRICT such as "tRuE" silently disabled fail-closed mode. Parse the lower-cased value, matching Enabled(). - OnDataPathMessage labeled a data-path answer as "signal" in logs, mislabeling every rotation answer. Use the data-path label. - A failed sendAnswer aborted the whole connection setup, skipping the relay/ICE listeners; a transient signalling failure now still brings the local transport up (the peer retries the answer). - processOffer left the reserved exchange slot in place when Respond failed, so every retransmission of that offer was dropped forever. Clear the reservation on a pre-commit error so a retry can derive again. - Dropped a no-op time.Since that implied a convergence-latency metric that was never recorded, and the now-unused startedAt field. - The strict-mode status line asserted active blocking even for a peer that is simply offline; reword it to state that no PSK is established yet. - conn_test used t.Fatalf for conditions under test; use assert.
This commit is contained in:
@@ -793,7 +793,7 @@ func peerQuantumResistanceStatus(established, rosenpassEnabled, rosenpassPermiss
|
||||
}
|
||||
switch {
|
||||
case mlkemEnabled && mlkemStrict:
|
||||
return "false (ML-KEM strict: blocking peer traffic until the exchange converges)"
|
||||
return "false (ML-KEM strict: no post-quantum PSK established for this peer yet)"
|
||||
case mlkemEnabled:
|
||||
return "false (ML-KEM: not converged yet, or peer does not run the exchange)"
|
||||
case rosenpassEnabled && rosenpassPermissive:
|
||||
|
||||
Reference in New Issue
Block a user