[noise] Simplify the resume cache accept path and guard the sensitive message set

This commit is contained in:
J. Nick Koston
2026-08-24 16:44:47 -05:00
parent 1cb2136c38
commit 46de7335b2
6 changed files with 97 additions and 72 deletions
+11 -4
View File
@@ -2518,6 +2518,11 @@ def calculate_message_max_size(desc: descriptor.DescriptorProto) -> int | None:
return total_size
# Contents must never reach the log: dump_to prints only the name
SENSITIVE_MESSAGES = {"NoiseResumeTicket"}
SENSITIVE_MESSAGES_SEEN: set[str] = set()
def build_message_type(
desc: descriptor.DescriptorProto,
base_class_fields: dict[str, list[descriptor.FieldDescriptorProto]],
@@ -2799,9 +2804,9 @@ def build_message_type(
public_content.append(prot)
# If no fields to calculate size for or message doesn't need encoding, the default implementation in ProtoMessage will be used
# Sensitive messages (keys, tickets) dump only their name
if desc.name in SENSITIVE_MESSAGES:
dump = []
SENSITIVE_MESSAGES_SEEN.add(desc.name)
# dump_to method declaration in header
prot = "#ifdef HAS_PROTO_MESSAGE_DUMP\n"
@@ -2849,9 +2854,6 @@ def build_message_type(
return out, cpp, dump_cpp
# Messages whose contents are secret; dump_to prints only the name
SENSITIVE_MESSAGES = {"NoiseResumeTicket"}
SOURCE_BOTH = 0
SOURCE_SERVER = 1
SOURCE_CLIENT = 2
@@ -3709,6 +3711,11 @@ static const char *const TAG = "api.service";
except ImportError:
pass
# A renamed message must fail the build, not silently start dumping secrets
missing = SENSITIVE_MESSAGES - SENSITIVE_MESSAGES_SEEN
if missing:
raise RuntimeError(f"SENSITIVE_MESSAGES not found in api.proto: {missing}")
if __name__ == "__main__":
sys.exit(main())