mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-09 15:09:08 +02:00
Both sides recorded the exchange as converged and then called OnNewPSKReady, returning its error but leaving the "converged" state in place. A host failure to program the PSK therefore left the peers split between the old data-path key and the new stored value, with no failure raised and no re-bootstrap. Treat applying the PSK as part of the commit. On the initiator, a failed OnNewPSKReady now drops the exchange and raises the failure so recovery re-bootstraps. On the responder, it drops the exchange and withholds the answer, so the initiator times out and re-bootstraps rather than converging on a key the responder could not apply. Found in cubic review on #7098 (client/internal/pqkem/convergence.go:228).