Commit Graph
4 Commits
Author SHA1 Message Date
riccardom 3efd4c94a0 UDPv4 is sufficient! we always have 100.x overlay. IPv6 is additive
ipAllowed[0] is the v4
2026-09-11 14:48:54 +02:00
riccardom ecddbf2e55 Addresses CI fixes 2026-09-11 14:48:54 +02:00
riccardom 3b61222b07 [client] pqkem: gate controller re-offer to kick the KEM exactly once
When the controller receives the responder's (KEM-less) offer it replies with
its own KEM offer instead of answering, so the only transaction that brings the
tunnel up is the one that also carries the PSK. Guard that reply with
ShouldSendBootstrapOffer so it fires only when no exchange is in flight: without
it, every responder offer triggered another offer (an offer-per-offer runaway).
The whole behaviour is isolated to the KEM path (config.PQ != nil); non-PQ
connections answer as before.
2026-09-11 14:48:54 +02:00
riccardom 5a6de00f7a Adds PQ connection tests 2026-09-11 14:48:54 +02:00