Bugfix: Separate login and message replay timestamps to allow companion RTC differs from app clock - #2834
Open
usrflo wants to merge 3 commits into
Open
Bugfix: Separate login and message replay timestamps to allow companion RTC differs from app clock#2834usrflo wants to merge 3 commits into
usrflo wants to merge 3 commits into
Conversation
…o prevent being stuck using different timer values
usrflo
marked this pull request as ready for review
June 28, 2026 06:57
usrflo
marked this pull request as draft
June 28, 2026 19:39
Author
Proof by test case "companion RTC in the future"Stock firmware (dev-Branch) denies messages after login with the debug log statement "possible replay attack detected"Bug: the login-timestamp from the rtc clock is compared with the message-timestamp from the app clock, login_ts>msg_ts, error Companion with future time (+3 months)Repeater-Serial-LogFirmware with this Pull-Request 2834Comparison of login_ts with login_ts from RTC clock and msg_ts with msg_ts from app clock Companion with future time (+3 months)Repeater-Serial-Log--> the wrong evaluation "possible replay attack detected" doesn't occur anymore with the bugfix |
usrflo
marked this pull request as ready for review
July 14, 2026 20:18
Author
|
It is always a pleasure to see how smoothly repeater/room-server logins work with this pull request. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Properly fixes the silent-message-rejection issue that was also addressed in #1551 and #1889.
It does so by tracking login replay and message replay in two separate per-client fields instead of sharing one to fix clock/timestamp differences at the client. This uniformly applies to room-server, repeater and sensor.
Fix
Split the two replay tracks:
ClientInfo::last_login_timestamp.last_login_timestamp.last_timestamp.Result:
getCurrentTimeUnique()is monotonic per device, every login's timestamp strictly exceeds the previous one → repeated logins work again (regression fixed).last_timestamp, which is no longer poisoned by the login's RTC value → messages are no longer rejected when the RTC runs ahead.clock sync/timerefuse to go backwards) no longer matters, because the two replay tracks are independent.Backward compatibility
No wire-protocol change. Old clients keep working against a patched server (the server just tracks login and messages separately), and patched clients work against an unpatched server.