mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-09 06:59:08 +02:00
[client] pqkem: document rekey-failure recovery as host-defined
The OnRekeyFailed contract told the host to tear the peer connection down, but the shipped adapter re-bootstraps over signalling and keeps the previous PSK. State that recovery is host-defined so another implementation does not perform an unnecessary teardown. Found in cubic review on #7098 (client/internal/pqkem/callbacks.go:15).
This commit is contained in:
@@ -13,8 +13,10 @@ type CallbackHandler interface {
|
||||
// peer has confirmed it — the next offer is the later acknowledgement.
|
||||
OnNewPSKReady(remoteID RemoteID, psk PSK) error
|
||||
|
||||
// OnRekeyFailed fires when an exchange fails to converge within the allotted
|
||||
// time. The host should tear the peer connection down so it re-establishes, and
|
||||
// log a WARN. The library reports the event; it does not dictate the reaction.
|
||||
// OnRekeyFailed fires when an exchange fails to converge within the allotted time.
|
||||
// Recovery is host-defined: the library reports the event and does not dictate the
|
||||
// reaction. The shipped NetBird host, for instance, re-bootstraps the KEM over
|
||||
// signalling and keeps the tunnel on its previous PSK rather than tearing the
|
||||
// connection down.
|
||||
OnRekeyFailed(remoteID RemoteID) error
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user