Review of 083: finishing an enrolment whose token was spent takes proof of the key's private half, a live lease and a first delivery — a public key alone cannot replay a spent token; shutdown leaves held messages for the broker; identical builds supersede; what is held leaves room in the prefetch

This commit is contained in:
2026-09-22 14:33:13 +02:00
parent a3b7e830c8
commit 4567fa666c
7 changed files with 214 additions and 25 deletions
+13 -1
View File
@@ -60,8 +60,20 @@ func (e Enrolment) Enrol(ctx context.Context, request EnrolRequest) (reply Enrol
// token, so the two cannot be one transaction; a failure between them used to leave a spent
// token and a node with no key, which the host — making new keys on every attempt — could not
// recover from. Every write below overwrites, so an attempt made again is safe.
// A proof that does not verify is refused outright: it was made with another key, or for
// another request. One that verifies lets this presenter finish an enrolment whose token it
// already spent — never a request the broker handed over a second time, which may already
// have been answered.
proven := false
if len(request.Proof) > 0 {
if !ed25519.Verify(public, EnrolProof(secret, public, request.OverlayKey, request.SealingKey,
request.ServingKey), request.Proof) {
return EnrolReply{}, errors.New("the enrolment's proof does not match the key it presents")
}
proven = true
}
by := claimant(public)
node, err := e.Inventory.Claim(ctx, secret, by)
node, err := e.Inventory.Claim(ctx, secret, by, proven && !request.Redelivered)
if err != nil {
return EnrolReply{}, err
}