fix: correct 7 bugs found in security audit
Critical: - crypto.rs (server): use BTreeMap for canonical JSON so key order matches JS client's JSON.stringify sort — sig verification was always failing silently - heartbeat.js: capture sentSalt before rotating to next_salt so both sides compute next_chain_hash with the same salt — chain was broken after the first heartbeat High: - trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not distance/event_count — legitimate users were always rejected - ratelimit.rs: add evict_stale() to drain expired entries and prevent unbounded HashMap memory growth - cleanup.rs: call rl.evict_stale() from the periodic cleanup loop Medium: - vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth is not decremented incorrectly - wasm/crypto.rs: replace unwrap() panics in sign_message / get_public_key with unwrap_or_default(); add JS-side guard Low: - shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments - Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
This commit is contained in:
1 parent
3f779a5295
commit
b75d586b86
10 files changed
+103
-43
No files matched your search
+23
-10
@@ -1,4 +1,4 @@
|
||||
use ed25519_dalek::{SigningKey, Signer};
|
||||
use ed25519_dalek::{Signer, SigningKey};
|
||||
use std::cell::RefCell;
|
||||
use wasm_bindgen::prelude::*;
|
||||
|
||||
@@ -16,17 +16,28 @@ pub fn generate_keypair() -> String {
|
||||
hex_pub
|
||||
}
|
||||
|
||||
/// Returns the hex-encoded public key, or an empty string if the keypair has not
|
||||
/// been generated yet. Callers must check for an empty return value.
|
||||
#[wasm_bindgen]
|
||||
pub fn get_public_key() -> String {
|
||||
KEYPAIR.with(|kp| hex::encode(kp.borrow().as_ref().unwrap().verifying_key().as_bytes()))
|
||||
KEYPAIR.with(|kp| {
|
||||
kp.borrow()
|
||||
.as_ref()
|
||||
.map(|sk| hex::encode(sk.verifying_key().as_bytes()))
|
||||
.unwrap_or_default()
|
||||
})
|
||||
}
|
||||
|
||||
/// Signs `message_json` and returns a hex-encoded signature, or an empty string
|
||||
/// if the keypair has not been initialised. Callers must check for an empty
|
||||
/// return value before sending a heartbeat.
|
||||
#[wasm_bindgen]
|
||||
pub fn sign_message(message_json: &str) -> String {
|
||||
KEYPAIR.with(|kp| {
|
||||
let sk = kp.borrow();
|
||||
let sig = sk.as_ref().unwrap().sign(message_json.as_bytes());
|
||||
hex::encode(sig.to_bytes())
|
||||
kp.borrow()
|
||||
.as_ref()
|
||||
.map(|sk| hex::encode(sk.sign(message_json.as_bytes()).to_bytes()))
|
||||
.unwrap_or_default()
|
||||
})
|
||||
}
|
||||
|
||||
@@ -38,10 +49,12 @@ pub fn compute_next_hash(
|
||||
stack_state_json: &str,
|
||||
salt_hex: &str,
|
||||
) -> String {
|
||||
let prev = hex::decode(prev_hash_hex).unwrap();
|
||||
let salt = hex::decode(salt_hex).unwrap();
|
||||
let entropy = serde_json::from_str::<shared::protocol::EntropyData>(entropy_data_json).unwrap();
|
||||
let stack = serde_json::from_str::<shared::protocol::StackState>(stack_state_json).unwrap();
|
||||
let prev = hex::decode(prev_hash_hex).unwrap_or_default();
|
||||
let salt = hex::decode(salt_hex).unwrap_or_default();
|
||||
let entropy =
|
||||
serde_json::from_str::<shared::protocol::EntropyData>(entropy_data_json).unwrap();
|
||||
let stack =
|
||||
serde_json::from_str::<shared::protocol::StackState>(stack_state_json).unwrap();
|
||||
let new = shared::hashing::next_chain_hash(&prev, timestamp, &entropy, &stack, &salt);
|
||||
hex::encode(&new)
|
||||
hex::encode(new)
|
||||
}
|
||||
Reference in new issue
Block a user