Harden connect token history and restart handling - #27
Conversation
Co-Authored-By: GPT-5.6 Luna
|
Security seat second eyes at exact head 2404f58 (Alex; this repairs the defect I confirmed in security#39 — the pre-1.4.5 token history, netcode.rs#24). Verified: the three-piece C 1.4.8 contract is present and correct.
The old same-address-forever test contract is properly inverted: the suite now pins consumed-then-refused and history-full-refusal (56 unit + 10 integration, all green at this head on this bench). The legacy This closes netcode.rs#24 / security#39. Consistent shape-for-shape with netcode.go#29 and netcode.cs#9 — the three family fixes of this advisory are now verified identical in contract. |
Read (Fable) at 2404f58Verdict: APPROVE. Cold read against C netcode v1.4.8 (47a156b) Contract, hunk by hunk
Lifetime guard direction: configured max shorter than the backend's longest issued lifetime lowers History bounds: fixed Evidence
LOW (notes, no change required for merge)
|
Read (Opus) at 2404f58Verdict: APPROVE. Cold read against C The contract, line by line
Evidence
Findings (all LOW, none blocking)
|
Problem
The Rust server retained the pre-1.4.5 connect-token behavior: a token could be reused from the original address after disconnect, token history evicted its oldest entry under load, and server restarts accepted tokens whose keys may have been used before the restart.
Fix
ServerConfigandServer::new_with_configfor the backend's maximum token lifetime, and reject pre-start tokens before private-token decryption on every server start.STANDARD.mdwith the current netcode 1.02 normative document, which now requires these restart and history rules.No packet layout or wire bytes changed.
Validation
cargo fmt --checkcargo testcargo test --releasecargo build --all-targetscargo clippy --all-targets -- -D warningsRUSTDOCFLAGS='-D warnings' cargo doc --no-depscargo deny checkrustup run 1.85 cargo checkNETCODE_C_SERVER=... NETCODE_C_CLIENT=... cargo test --test c_interop -- --ignored --test-threads=1 --nocaptureagainst C 1.4.8Fixes #24