Files
netbird/client/internal
riccardom d0f7e2ac7a [client] pqkem: route a failed PSK application through convergence recovery
Both sides recorded the exchange as converged and then called OnNewPSKReady,
returning its error but leaving the "converged" state in place. A host failure to
program the PSK therefore left the peers split between the old data-path key and
the new stored value, with no failure raised and no re-bootstrap.

Treat applying the PSK as part of the commit. On the initiator, a failed
OnNewPSKReady now drops the exchange and raises the failure so recovery
re-bootstraps. On the responder, it drops the exchange and withholds the answer,
so the initiator times out and re-bootstraps rather than converging on a key the
responder could not apply.

Found in cubic review on #7098 (client/internal/pqkem/convergence.go:228).
2026-10-07 13:26:57 +02:00
..
2026-09-11 14:48:54 +02:00