Commit Graph

25 Commits

Author SHA1 Message Date
riccardom
c937df5aea pqkem: apply derived PSK at WG peer-config time (pull) + keep push for rekey 2026-08-04 19:17:44 +02:00
riccardom
d959adfb25 pqkem: dedicated slog logger via NB_PQ_MLKEM_LOG_LEVEL 2026-08-04 19:17:44 +02:00
riccardom
4874f5ae51 Homogeneous logs prefix 2026-08-04 19:17:44 +02:00
riccardom
622be61b11 Bit of renaming
peer -> peerAddrs
have types for remoteID and localID
t.Close log error
Manager SetTransport -> Start
2026-08-04 19:17:44 +02:00
riccardom
1b1ddebd4c Typo 2026-08-04 19:17:44 +02:00
riccardom
56ec125afc Race fix 2026-08-04 19:17:44 +02:00
riccardom
5f81c1e5b8 Makes Transport just a UDP socket.
Manager owns maps for remoteID <-> remote UDP addr
Engine talks to manager only
2026-08-04 19:17:44 +02:00
riccardom
8dcbd4ed8e Added enabled env var 2026-08-04 19:17:44 +02:00
riccardom
2187760567 Invert order of keys as per draft 2026-08-04 19:17:44 +02:00
riccardom
608234e947 Removes confirm. Uses next offer to deliver confirmation/ack of previous round
We clock the next Offer initiation to the OnDataPathRekeyed, so we have 2 minutes
ahead of us to do our attempts and stuff before to give up.
On failure, we will know because we will not receive a new answer.. but more importantly
the wg handshake will fail :D
2026-08-04 19:17:44 +02:00
riccardom
475b3e9790 Leave signal offer/answer as a pull/push operation not as an actual transport 2026-08-04 19:17:44 +02:00
riccardom
baea17efb6 Assume two transports: initial "signal" (control plane) one (no data path established yet) + data path one
Define OnDataPathRekeyed event to transition from control plane path to data plane path over the WG tunnel.

Keep confirm ALWAYS on NEW established WG tunnel (posthandshake with rekeying). We keep an active method
irrelevant of the WG handshake (we might decide that the indirect wg handshake is sufficient in the future).

Optimistic commit on responder(when sending answer), while on initiator we set it on getting the answer
2026-08-04 19:17:44 +02:00
riccardom
6cef0d8bee Epurate wg refs 2026-08-04 19:17:44 +02:00
riccardom
37ce7b4f6f Collapse Driver and Manager in one.
- Have just one manager => one lock
 - Session state is needed in driver to => we have it available now.
 - Isomorphically align to rosenpass components and functionality

File	Role	                                  rosenpass equivalent
kem.go	primitive pure X25519MLKEM768	          crypto.go/handshake
message.go	Offer/Answer/Confirm + Encode/Decode  messages.go
manager.go	Manager stateful, single lock	      server logic
callbacks.go	WGCallbackHandler (seam output)	  Handler
Transport (interfaccia)	seam trasporto pluggable  Conn
2026-08-04 19:17:44 +02:00
riccardom
a20ad0158e [squash] isInitial and answered can be inferred without state variables 2026-08-04 19:17:44 +02:00
riccardom
cdcf58a14c Manages convergence 2026-08-04 19:17:44 +02:00
riccardom
c3667140ea Models reattempts 2026-08-04 19:17:44 +02:00
riccardom
ca356353b1 Reuse answer, don't calculate again 2026-08-04 19:17:44 +02:00
riccardom
3f15ec14c1 Adds driver to glue together manager and outside world 2026-08-04 19:17:44 +02:00
riccardom
4ad3517869 Defines event callbacks 2026-08-04 19:17:44 +02:00
riccardom
f67332f062 Admits possible errors on Encode 2026-08-04 19:17:44 +02:00
riccardom
87c610b44b Bench key material boilerplate time/allocs
CGO_ENABLED=1 go test ./client/internal/pqkem/ -run '^$' -bench . -benchmem 2>&1 | grep -E "Benchmark|ns/op|PASS|ok" | head -20

BenchmarkX25519Keygen-14    	   33795	     34966 ns/op	     224 B/op	       5 allocs/op
BenchmarkX25519ECDH-14      	   33855	     33973 ns/op	      32 B/op	       1 allocs/op
BenchmarkMLKEMKeygen-14     	   21817	     67778 ns/op	    8200 B/op	       2 allocs/op
BenchmarkMLKEMEncaps-14     	   29918	     43235 ns/op	    1216 B/op	       2 allocs/op
BenchmarkMLKEMDecaps-14     	   26048	     56291 ns/op	      64 B/op	       2 allocs/op
PASS
ok  	github.com/netbirdio/netbird/client/internal/pqkem	9.751s
Shell cwd was reset to /home/riccardo/Desktop/Personal/netbirdio/netbird
2026-08-04 19:17:44 +02:00
riccardom
a9946d7ffe Pure mechanics of manager 2026-08-04 19:17:44 +02:00
riccardom
942e3a1924 Messages definition 2026-08-04 19:17:44 +02:00
riccardom
fd08e8aaf7 ML-KEM encapsulate/decapsulate module 2026-08-04 19:17:44 +02:00