Skip to content

mixpool: Reject conflicting key exchanges. - #3801

Open
fedikan wants to merge 1 commit into
decred:masterfrom
machine-of-earn:fix-key-exchange-conflicts
Open

fedikan wants to merge 1 commit into
decred:masterfrom
machine-of-earn:fix-key-exchange-conflicts

Conversation

@fedikan

@fedikan fedikan commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

KE messages bypass the per-identity, per-session conflict check applied to other message types. Apply that check inside acceptKE, where both direct acceptance and orphan reconsideration pass, so a second distinct KE cannot increase the session cache or replace latestKE.

Regression tests fail on the previous code for both arrival orders and pass with this change. They also check that exact duplicates remain harmless and a new session can still accept a new KE. Addresses #3795's missing conflict check; the separate comment about old epochs is not changed, and this does not impose a global cap across distinct sessions.

Validation: mixing module tests pass on Go 1.27.1 and 1.26.8; both new acceptance cases run. Five unrelated mixclient integration tests skip without csppsolver. go vet and formatting/diff checks pass.

Key exchanges bypass the per-identity, per-session uniqueness check that
other mixing messages use.  Reject a different key exchange from the same
identity in the same session before adding another entry or updating the
latest key exchange.  Keep the check inside acceptKE so reconsidered
orphans follow it as well.

Cover direct acceptance and orphan reconsideration, harmless exact
duplicates, and acceptance of a key exchange in a distinct session.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant