Files
nx9-chronoseal-rs/wasm/src/crypto.rs
T
thakares b75d586b86 fix: correct 7 bugs found in security audit
Critical:
- crypto.rs (server): use BTreeMap for canonical JSON so key order
  matches JS client's JSON.stringify sort — sig verification was always
  failing silently
- heartbeat.js: capture sentSalt before rotating to next_salt so both
  sides compute next_chain_hash with the same salt — chain was broken
  after the first heartbeat

High:
- trust.rs: avg_speed = total_dist / total_time_ms (px/ms), not
  distance/event_count — legitimate users were always rejected
- ratelimit.rs: add evict_stale() to drain expired entries and prevent
  unbounded HashMap memory growth
- cleanup.rs: call rl.evict_stale() from the periodic cleanup loop

Medium:
- vm.rs: op 0x08 (NOT) is unary — split from binary-op arm so depth
  is not decremented incorrectly
- wasm/crypto.rs: replace unwrap() panics in sign_message /
  get_public_key with unwrap_or_default(); add JS-side guard

Low:
- shared/Cargo.toml, wasm/Cargo.toml: remove leftover add-this comments
- Dockerfile: rust:1.88-bookworm -> rust:1.87-bookworm (1.88 non-existent)
2026-05-08 14:27:41 +05:30

60 lines
1.9 KiB
Rust

use ed25519_dalek::{Signer, SigningKey};
use std::cell::RefCell;
use wasm_bindgen::prelude::*;
thread_local! {
static KEYPAIR: RefCell<Option<SigningKey>> = RefCell::new(None);
}
#[wasm_bindgen]
pub fn generate_keypair() -> String {
let mut rng = rand::thread_rng();
let sk = SigningKey::generate(&mut rng);
let pk = sk.verifying_key();
let hex_pub = hex::encode(pk.as_bytes());
KEYPAIR.with(|kp| *kp.borrow_mut() = Some(sk));
hex_pub
}
/// Returns the hex-encoded public key, or an empty string if the keypair has not
/// been generated yet. Callers must check for an empty return value.
#[wasm_bindgen]
pub fn get_public_key() -> String {
KEYPAIR.with(|kp| {
kp.borrow()
.as_ref()
.map(|sk| hex::encode(sk.verifying_key().as_bytes()))
.unwrap_or_default()
})
}
/// Signs `message_json` and returns a hex-encoded signature, or an empty string
/// if the keypair has not been initialised. Callers must check for an empty
/// return value before sending a heartbeat.
#[wasm_bindgen]
pub fn sign_message(message_json: &str) -> String {
KEYPAIR.with(|kp| {
kp.borrow()
.as_ref()
.map(|sk| hex::encode(sk.sign(message_json.as_bytes()).to_bytes()))
.unwrap_or_default()
})
}
#[wasm_bindgen]
pub fn compute_next_hash(
prev_hash_hex: &str,
timestamp: u64,
entropy_data_json: &str,
stack_state_json: &str,
salt_hex: &str,
) -> String {
let prev = hex::decode(prev_hash_hex).unwrap_or_default();
let salt = hex::decode(salt_hex).unwrap_or_default();
let entropy =
serde_json::from_str::<shared::protocol::EntropyData>(entropy_data_json).unwrap();
let stack =
serde_json::from_str::<shared::protocol::StackState>(stack_state_json).unwrap();
let new = shared::hashing::next_chain_hash(&prev, timestamp, &entropy, &stack, &salt);
hex::encode(new)
}