fix: correct 7 bugs found in security audit
Critical: - crypto.rs (server): use BTreeMap for canonical JSON so key order matches JS client's JSON.stringify sort — sig verification was always failing silently - heartbeat.js: capture sentSalt before rotating to next_salt so both sides compute next_chain_hash with the same salt — chain was broken after the first heartbeat High: - trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not distance/event_count — legitimate users were always rejected - ratelimit.rs: add evict_stale() to drain expired entries and prevent unbounded HashMap memory growth - cleanup.rs: call rl.evict_stale() from the periodic cleanup loop Medium: - vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth is not decremented incorrectly - wasm/crypto.rs: replace unwrap() panics in sign_message / get_public_key with unwrap_or_default(); add JS-side guard Low: - shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments - Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
This commit is contained in:
1 parent
3f779a5295
commit
b75d586b86
10 files changed
+103
-43
No files matched your search
@@ -47,7 +47,10 @@ async function sendHeartbeat() {
|
||||
};
|
||||
const msg = JSON.stringify(signable, Object.keys(signable).sort());
|
||||
const sig = sign_message(msg);
|
||||
|
||||
if (!sig) {
|
||||
console.error('Keypair not initialised — skipping heartbeat');
|
||||
return;
|
||||
}
|
||||
const resp = await sendRequest('/hb', 'POST', {
|
||||
session_id: session,
|
||||
prev_hash: prevHash,
|
||||
@@ -59,8 +62,12 @@ async function sendHeartbeat() {
|
||||
});
|
||||
|
||||
if (resp.next_salt) {
|
||||
// IMPORTANT: capture the salt that was active when this heartbeat was sent.
|
||||
// The server computes new_hash = H(prev, ts, entropy, stack, OLD_salt) and stores it,
|
||||
// then rotates to next_salt. We must mirror that using the same old salt, then rotate.
|
||||
const sentSalt = currentSalt;
|
||||
currentSalt = resp.next_salt;
|
||||
prevHash = compute_next_hash(prevHash, timestamp, entropyJson, stackState, currentSalt);
|
||||
prevHash = compute_next_hash(prevHash, timestamp, entropyJson, stackState, sentSalt);
|
||||
} else {
|
||||
console.warn('Heartbeat rejected');
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user