fix: correct 7 bugs found in security audit

Critical:
- crypto.rs (server): use BTreeMap for canonical JSON so key order
  matches JS client's JSON.stringify sort — sig verification was always
  failing silently
- heartbeat.js: capture sentSalt before rotating to next_salt so both
  sides compute next_chain_hash with the same salt — chain was broken
  after the first heartbeat

High:
- trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not
  distance/event_count — legitimate users were always rejected
- ratelimit.rs: add evict_stale() to drain expired entries and prevent
  unbounded HashMap memory growth
- cleanup.rs: call rl.evict_stale() from the periodic cleanup loop

Medium:
- vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth
  is not decremented incorrectly
- wasm/crypto.rs: replace unwrap() panics in sign_message /
  get_public_key with unwrap_or_default(); add JS-side guard

Low:
- shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments
- Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
This commit is contained in:
thakares committed 2026-05-08 14:27:41 +05:30
1 parent 3f779a5295
commit b75d586b86
10 files changed
+103 -43

No files matched your search

+16 -6
View File
@@ -4,11 +4,21 @@ use crate::session::AppState;
pub async fn cleanup_loop(state: Arc<AppState>) {
loop {
tokio::time::sleep(std::time::Duration::from_secs(60)).await;
let db = state.db.lock().await; // this is infallible
let now = crate::storage::current_time_ms();
let _ = db.execute(
"DELETE FROM sessions WHERE expires_at < ?1",
rusqlite::params![now],
);
// Evict expired sessions from SQLite.
{
let db = state.db.lock().await;
let now = crate::storage::current_time_ms();
let _ = db.execute(
"DELETE FROM sessions WHERE expires_at < ?1",
rusqlite::params![now],
);
}
// Evict stale rate-limiter entries to prevent unbounded HashMap growth.
{
let mut rl = state.rate_limiter.lock().await;
rl.evict_stale();
}
}
}