Critical: - crypto.rs (server): use BTreeMap for canonical JSON so key order matches JS client's JSON.stringify sort — sig verification was always failing silently - heartbeat.js: capture sentSalt before rotating to next_salt so both sides compute next_chain_hash with the same salt — chain was broken after the first heartbeat High: - trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not distance/event_count — legitimate users were always rejected - ratelimit.rs: add evict_stale() to drain expired entries and prevent unbounded HashMap memory growth - cleanup.rs: call rl.evict_stale() from the periodic cleanup loop Medium: - vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth is not decremented incorrectly - wasm/crypto.rs: replace unwrap() panics in sign_message / get_public_key with unwrap_or_default(); add JS-side guard Low: - shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments - Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
24 lines
375 B
Docker
24 lines
375 B
Docker
FROM rust:1.87-bookworm AS builder
|
|
|
|
WORKDIR /app
|
|
|
|
COPY . .
|
|
|
|
RUN cargo build -p server --release
|
|
|
|
FROM debian:bookworm-slim
|
|
|
|
RUN apt-get update && apt-get install -y \
|
|
ca-certificates \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
WORKDIR /opt/chronoseal
|
|
|
|
COPY --from=builder /app/target/release/server /usr/local/bin/chronoseal
|
|
|
|
EXPOSE 3000
|
|
|
|
ENV RUST_LOG=info
|
|
|
|
CMD ["chronoseal"]
|