fix(peer): bound authenticated identities per endpoint IP

Allow at most eight committed peer identities at one pinned QUIC endpoint IP after Hello authentication. Reject excess keys before address-owner eviction, while removals release capacity and other LAN hosts remain admissible.

Test Plan:
- just test
- focused port-rotation, ninth-key, address-owner, other-IP, and release tests
- git diff --check
This commit is contained in:
ddidderr committed 2026-09-12 12:41:20 +02:00
1 parent 06cd8b93ed
commit 145610c0a1
2 files changed
+128 -2

No files matched your search

+6 -1
View File
@@ -75,7 +75,12 @@ When a peer is discovered:
Call-to-Play domains independently. Commit the endpoint and each valid domain
only if the candidate lease is still current for both peer ID and address.
This domain isolation lets an invalid remote Call-to-Play slice be cleared or
preserved according to its session without discarding a valid library.
preserved according to its session without discarding a valid library. After
the pinned Hello succeeds, at most eight committed identities may reside at
one stored endpoint IP, alongside the global 64-peer limit. This
authenticated residency bound is separate from the pre-authentication mDNS
candidate quota; a ninth identity is rejected without evicting an existing
address owner, and removing a peer releases its slot.
5. Assign a fresh endpoint generation to every successful authentication.
Dropped, failed, or superseded work releases its candidate claims, and a late
result cannot mutate a newer generation.