RNS Logo

rns.recipes

◈ 9ce92808be498e9e05590ff27cbfdfe4
RNS 1.5.5 released https://pypi.org/project/rns/

RNS 1.5.0 - Protocol Violation Control

Started by Mark bc7291552be7a58f... ·

Mark 8dd57a7382268096...
#1

The upcoming release of RNS 1.5.0 will introduce per-interface protocol violation tracking and control. This means, that going forward, it will be a lot easier to handle broken implementations and clients doing things that no sane implementation would do. For example, protocol violations include:

  • Sending announces that are cryptographically invalid
  • Forwarding meaningless link requests
  • Transporting completely malformed packets
  • Ignoring negotiated link MTUs
  • Dumping random data at 35 Mbps to bogus links
  • And all kinds of other "fun", but meaningless stuff

This will also make testing things much easier, since protocol violation stats can be viewed live per interface with rnstatus.

Since nothing is perfect, and there's bound to be both some false hits and missed cases initially, the actual control part of this will not be enabled by default in 1.5.0. But if everything works out nicely, it will be the default behavior (on interface types where this makes sense, BackboneInterface for example) from 1.5.1 to instantly tear down excessively violating clients, and potentially block their IP for a period of time. All configurable of course, so you decide how to use this.

Mark 8dd57a7382268096...
#2

And while RNS itself does correctly drop packets with invalid hop counts if received, before 1.5.0, it does actually allow constructing and sending them, so I'm officially the OG Protocol Violator here ;)

Post a Reply

Supports Markdown: **bold**, *italic*, `code`, ```code blocks```, [links](url)

Log in to upload images

Quote
Copied to clipboard