From 9041e9a3eef64bc278da85d58738b3d7c648a7ba Mon Sep 17 00:00:00 2001 From: riccardom Date: Wed, 7 Oct 2026 13:23:34 +0200 Subject: [PATCH] [client] pqkem: document rekey-failure recovery as host-defined The OnRekeyFailed contract told the host to tear the peer connection down, but the shipped adapter re-bootstraps over signalling and keeps the previous PSK. State that recovery is host-defined so another implementation does not perform an unnecessary teardown. Found in cubic review on #7098 (client/internal/pqkem/callbacks.go:15). --- client/internal/pqkem/callbacks.go | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/client/internal/pqkem/callbacks.go b/client/internal/pqkem/callbacks.go index 3e22a04d4..2b7c3b1c6 100644 --- a/client/internal/pqkem/callbacks.go +++ b/client/internal/pqkem/callbacks.go @@ -13,8 +13,10 @@ type CallbackHandler interface { // peer has confirmed it — the next offer is the later acknowledgement. OnNewPSKReady(remoteID RemoteID, psk PSK) error - // OnRekeyFailed fires when an exchange fails to converge within the allotted - // time. The host should tear the peer connection down so it re-establishes, and - // log a WARN. The library reports the event; it does not dictate the reaction. + // OnRekeyFailed fires when an exchange fails to converge within the allotted time. + // Recovery is host-defined: the library reports the event and does not dictate the + // reaction. The shipped NetBird host, for instance, re-bootstraps the KEM over + // signalling and keeps the tunnel on its previous PSK rather than tearing the + // connection down. OnRekeyFailed(remoteID RemoteID) error }