fix: correct 7 bugs found in security audit

Critical:
- crypto.rs (server): use BTreeMap for canonical JSON so key order
  matches JS client's JSON.stringify sort — sig verification was always
  failing silently
- heartbeat.js: capture sentSalt before rotating to next_salt so both
  sides compute next_chain_hash with the same salt — chain was broken
  after the first heartbeat

High:
- trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not
  distance/event_count — legitimate users were always rejected
- ratelimit.rs: add evict_stale() to drain expired entries and prevent
  unbounded HashMap memory growth
- cleanup.rs: call rl.evict_stale() from the periodic cleanup loop

Medium:
- vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth
  is not decremented incorrectly
- wasm/crypto.rs: replace unwrap() panics in sign_message /
  get_public_key with unwrap_or_default(); add JS-side guard

Low:
- shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments
- Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
This commit is contained in:
thakares committed 2026-05-08 14:27:41 +05:30
1 parent 3f779a5295
commit b75d586b86
10 files changed
+103 -43

No files matched your search

+18 -5
View File
@@ -1,28 +1,41 @@
use rand::Rng;
pub fn generate_random_program(len_range: std::ops::RangeInclusive<usize>) -> Vec<u8> {
// Same logic as earlier, using shared::hashing for HASH if needed
let mut rng = rand::thread_rng();
let count = rng.gen_range(len_range);
let mut ops = Vec::new();
let mut depth: i32 = 0;
for _ in 0..count {
if depth < 2 {
ops.push(0x00); // PUSH
// Not enough operands for any binary op — push a literal.
ops.push(0x00);
let val = rng.gen::<u32>();
ops.extend_from_slice(&val.to_le_bytes());
depth += 1;
} else {
let op = rng.gen_range(0..10);
let op = rng.gen_range(0u8..10);
match op {
0x00 => {
// PUSH literal
ops.push(0x00);
let val = rng.gen::<u32>();
ops.extend_from_slice(&val.to_le_bytes());
depth += 1;
}
0x01..=0x08 => { ops.push(op as u8); depth -= 1; }
0x09 => { ops.push(0x09); depth = 1; }
0x01..=0x07 => {
// Binary ops (ADD, SUB, MUL, XOR, AND, OR, ROT): pops 2, pushes 1 → net −1
ops.push(op);
depth -= 1;
}
0x08 => {
// Unary NOT: pops 1, pushes 1 → net 0; depth unchanged
ops.push(0x08);
}
0x09 => {
// HASH: collapses entire stack to one u32 → depth becomes 1
ops.push(0x09);
depth = 1;
}
_ => unreachable!(),
}
}