Format: 1.8
Date: Wed, 22 Jul 2026 08:25:00 +0200
Source: libnetplus
Binary: libnetplus-dev libnetplus1 libnetplus1-dbgsym netplus-certgen netplus-certgen-dbgsym
Architecture: source amd64
Version: 20260722+27
Distribution: unstable
Urgency: high
Maintainer: Jan Koester <jan.koester@tuxist.de>
Changed-By: Jan Koester <jan.koester@tuxist.de>
Description:
 libnetplus-dev - C++ socket and event library - development files
 libnetplus1 - C++ socket and event library
 netplus-certgen - Self-signed TLS certificate generator
Changes:
 libnetplus (20260722+27) unstable; urgency=high
 .
   * quic: fix Initial keys being derived from the wrong DCID after a
     Retry, both server- and client-side — the actual cause of every real
     QUIC client (curl/ngtcp2, confirmed against a live capture) hanging
     to ERR_HANDSHAKE_TIMEOUT against this server's always-on-Retry mode,
     despite our own client/server pair passing every existing test
     (self-consistently sharing the same wrong assumption end to end).
     RFC 9001 §5.2 derives the Initial secret from whatever DCID is
     *currently* on the wire, which changes to the server's Retry SCID
     after a Retry — not, as previously assumed here, from the
     connection's original self-chosen DCID (which never changes across
     a Retry). accept() now calls deriveInitialKeys(dcid, ...) — this
     packet's own DCID — instead of the ODCID recovered from the retry
     token; processRetryPacket() now re-derives keys from the new
     _remote_cid before resending the Initial, instead of deliberately
     keeping the pre-Retry keys. The recovered original DCID
     (true_original_dcid / _original_dcid) is still tracked and still
     used for exactly what RFC 9000 §7.3 actually needs it for: the
     original_destination_connection_id transport parameter, which lets
     the client detect an off-path attacker's forged Retry — it was never
     part of key derivation, just misdocumented as such at both call
     sites.
   * quic: de-dupe Retry sends per client DCID (5s window). A client's
     first-flight CRYPTO data can span more than one UDP datagram (e.g. a
     large post-quantum-hybrid ClientHello); each such datagram shares
     the same token-less DCID with no registry entry yet to recognize it
     as already-answered, so each independently minted its own Retry with
     its own random SCID/token for what the client considers one attempt.
     Not the root cause above, but a real bug in its own right and
     cleaned up alongside it.
   * quic: restore QUIC_DBG tracing (a previous debugging session left it
     disabled via a bare `do {} while(0)`); gated behind the QUIC_TRACE
     env var as before. This is what made the root cause above provable:
     without it, decrypt failures on real traffic were entirely silent.
Checksums-Sha1:
 0571f6cb323910feeedd834c46d47f603f2e0a5c 778 libnetplus_20260722+27.dsc
 4dc8ba4a263c567493e84efcf548c6e88fc8ae35 283712 libnetplus_20260722+27.tar.xz
 978161e4cc85637be94c3a2b1baaffc06d52df75 413844 libnetplus-dev_20260722+27_amd64.deb
 951ec8a1a3f5e5abb89a8eeba19b861ca3e25cac 5074860 libnetplus1-dbgsym_20260722+27_amd64.deb
 1773c8478224874f342839f4b709141c4c8f9390 361624 libnetplus1_20260722+27_amd64.deb
 6b45d8a4724d0f31946bc72895940fe09ec8392e 8531 libnetplus_20260722+27_amd64.buildinfo
 a9db1df1e328eb95f84fb7e8be9106169c9d420e 662976 netplus-certgen-dbgsym_20260722+27_amd64.deb
 1a5995675d6d7045d975671fe4a1b5c1a7165852 67552 netplus-certgen_20260722+27_amd64.deb
Checksums-Sha256:
 e7439bf3b12590894c6db06b0cc01be0be394f9d3e7c21ddf91b3240fd1c40ce 778 libnetplus_20260722+27.dsc
 9e41df7654caf3acc5f5075d531fc7ce3567323eac0dca8e6277f24b14b524eb 283712 libnetplus_20260722+27.tar.xz
 d261eefe9f9242d900aac3d799b369d2d975bed9f055bb4929576025fa0ed891 413844 libnetplus-dev_20260722+27_amd64.deb
 1011beb6e6e31078f79ecaf1f7b48cfb93899860d1e58e85f3bd1b0b3992ec37 5074860 libnetplus1-dbgsym_20260722+27_amd64.deb
 c9bb2ccf1e43e8bd3b3e19fa641afeb6fbf70bb7ed9848429df98d8ca1c8d596 361624 libnetplus1_20260722+27_amd64.deb
 92443fb3a4bf1248614eefb9ddff25026789a7d766c14c791d4c9510e0b54d1f 8531 libnetplus_20260722+27_amd64.buildinfo
 12d04beb641ada73c1f695c6253600d6e712c020bc8bda513c7e648be29bb25d 662976 netplus-certgen-dbgsym_20260722+27_amd64.deb
 d0b5f552ebe7eea69dfe697cb21f550e74e6454a3af8c13106f6a629a2c355fa 67552 netplus-certgen_20260722+27_amd64.deb
Files:
 f3003997f019d356d4e3a2fe373d8def 778 libs optional libnetplus_20260722+27.dsc
 f2152dd90f4b86af1cb1f8d5266ffd27 283712 libs optional libnetplus_20260722+27.tar.xz
 f4f3051b801f2d0b24a6b64009d60962 413844 libdevel optional libnetplus-dev_20260722+27_amd64.deb
 adcaf7e8980358ce798f1b45fc94c350 5074860 debug optional libnetplus1-dbgsym_20260722+27_amd64.deb
 c3533857f7c7ac714975850dd9c87e50 361624 libs optional libnetplus1_20260722+27_amd64.deb
 23718f23b5fa60b0405363947ccb3cd6 8531 libs optional libnetplus_20260722+27_amd64.buildinfo
 ee4fd82d4de249c0eb7523c81031a74b 662976 debug optional netplus-certgen-dbgsym_20260722+27_amd64.deb
 a05cdf8dc13d367ceaaef31ef72019c7 67552 utils optional netplus-certgen_20260722+27_amd64.deb
