feat: scope server pins by port, default port inherits (agreed with bunshin)

This commit is contained in:
randogoth 2026-09-30 13:46:05 +03:00
parent 96a558da16
commit 13c624f2b0
7 changed files with 149 additions and 48 deletions

View file

@ -79,10 +79,11 @@ pub fn connect(
) -> Result<Session, Error> {
match addr.scheme {
Scheme::Tcp => {
let pinned = store.server_pin(&addr.host)?;
let pinned = store.server_pin(&addr.host, addr.port)?;
if pinned.is_none() && require_pin {
return Err(Error::NotPinned {
host: addr.host.clone(),
port: addr.port,
});
}
// The dial hint lets a host that resolves DNS itself (an
@ -94,6 +95,19 @@ pub fn connect(
pinned,
timeout,
)?;
// Pin enforcement lives here, one layer above the transport: the
// identity host names the trust object even when a dial hint
// routed the packets elsewhere (sec 4).
if let Some(pinned) = pinned {
if !ct_eq(&pinned, transport.server_static()) {
return Err(Error::PinMismatch {
host: addr.host.clone(),
port: addr.port,
pinned,
presented: *transport.server_static(),
});
}
}
let unpinned_static = if pinned.is_none() {
Some(*transport.server_static())
} else {