Clamp position precision on public / known-keys (#10665)
* Clamp position precision on public / known-keys (Compliance) * Fix review comments: bounds check, all-channel precision clamp, disabled channel guard * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> * Refactor position precision comments for clarity and update channel configuration handling in AdminModule * Potential fix for pull request finding Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
This commit is contained in:
co-authored by
GitHub
copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Copilot Autofix powered by AI
parent
8a0c7592cc
commit
d878c81ce8
@@ -1,6 +1,8 @@
|
||||
#include "Channels.h"
|
||||
#include "PositionPrecision.h"
|
||||
#include "TestUtil.h"
|
||||
#include "mesh-pb-constants.h"
|
||||
#include <cstring>
|
||||
#include <unity.h>
|
||||
|
||||
static meshtastic_Position makePosition()
|
||||
@@ -119,6 +121,92 @@ static void test_getPositionPrecisionForChannel_secondaryWithoutModuleSettingsFa
|
||||
TEST_ASSERT_EQUAL_UINT32(0, getPositionPrecisionForChannel(channel));
|
||||
}
|
||||
|
||||
// End-to-end via the channelIndex overload + live channels singleton, exercising getKey()'s 1-byte->16-byte expansion.
|
||||
static void test_getPositionPrecisionForChannel_clampsPreciseOnDefaultKeyChannel()
|
||||
{
|
||||
channels.initDefaults(); // channel 0: primary, default key (psk {0x01}) -> publicly decryptable
|
||||
uint8_t idx = 0;
|
||||
meshtastic_Channel &ch = channels.getByIndex(idx);
|
||||
ch.settings.has_module_settings = true;
|
||||
ch.settings.module_settings.position_precision = 32; // user requests "Precise" on a public channel
|
||||
|
||||
TEST_ASSERT_EQUAL_UINT32(MAX_POSITION_PRECISION_PUBLIC_KEY, getPositionPrecisionForChannel(idx));
|
||||
}
|
||||
|
||||
static void test_getPositionPrecisionForChannel_keepsPreciseOnStrongKeyChannel()
|
||||
{
|
||||
channels.initDefaults();
|
||||
uint8_t idx = 0;
|
||||
meshtastic_Channel &ch = channels.getByIndex(idx);
|
||||
memset(ch.settings.psk.bytes, 0xAB, 16); // a private 128-bit key, not the defaultpsk family
|
||||
ch.settings.psk.size = 16;
|
||||
ch.settings.has_module_settings = true;
|
||||
ch.settings.module_settings.position_precision = 32;
|
||||
|
||||
TEST_ASSERT_EQUAL_UINT32(32, getPositionPrecisionForChannel(idx));
|
||||
}
|
||||
|
||||
static CryptoKey makeCryptoKey(const uint8_t *bytes, int length)
|
||||
{
|
||||
CryptoKey k;
|
||||
memset(k.bytes, 0, sizeof(k.bytes));
|
||||
|
||||
// CryptoKey::length is int8_t and CryptoKey::bytes is 32 bytes; keep the helper consistent and overflow-safe.
|
||||
int cappedLen = length;
|
||||
if (cappedLen < 0)
|
||||
cappedLen = -1;
|
||||
else if (cappedLen > static_cast<int>(sizeof(k.bytes)))
|
||||
cappedLen = static_cast<int>(sizeof(k.bytes));
|
||||
|
||||
if (cappedLen > 0 && bytes != nullptr) {
|
||||
memcpy(k.bytes, bytes, static_cast<size_t>(cappedLen));
|
||||
}
|
||||
|
||||
k.length = static_cast<int8_t>(cappedLen);
|
||||
return k;
|
||||
}
|
||||
|
||||
static void test_cryptoKeyIsPublic_openKeyIsPublic()
|
||||
{
|
||||
// length 0 == encryption disabled.
|
||||
TEST_ASSERT_TRUE(cryptoKeyIsPublic(makeCryptoKey(nullptr, 0)));
|
||||
}
|
||||
|
||||
static void test_cryptoKeyIsPublic_defaultKeyIsPublic()
|
||||
{
|
||||
// The expanded default PSK (the 16-byte defaultpsk) -- the case a key-length check misses.
|
||||
TEST_ASSERT_TRUE(cryptoKeyIsPublic(makeCryptoKey(defaultpsk, sizeof(defaultpsk))));
|
||||
}
|
||||
|
||||
static void test_cryptoKeyIsPublic_defaultKeyFamilyVariesLastByte()
|
||||
{
|
||||
// Higher indices (e.g. {0x02}) expand to defaultpsk with only the last byte bumped -- still public.
|
||||
uint8_t key[sizeof(defaultpsk)];
|
||||
memcpy(key, defaultpsk, sizeof(defaultpsk));
|
||||
key[sizeof(defaultpsk) - 1] = static_cast<uint8_t>(key[sizeof(defaultpsk) - 1] + 1);
|
||||
TEST_ASSERT_TRUE(cryptoKeyIsPublic(makeCryptoKey(key, sizeof(key))));
|
||||
}
|
||||
|
||||
static void test_cryptoKeyIsPublic_strongKeyIsPrivate()
|
||||
{
|
||||
uint8_t key[16];
|
||||
memset(key, 0xAB, sizeof(key)); // not the defaultpsk family
|
||||
TEST_ASSERT_FALSE(cryptoKeyIsPublic(makeCryptoKey(key, sizeof(key))));
|
||||
}
|
||||
|
||||
static void test_cryptoKeyIsPublic_aes256KeyIsPrivate()
|
||||
{
|
||||
uint8_t key[32];
|
||||
memset(key, 0x11, sizeof(key));
|
||||
TEST_ASSERT_FALSE(cryptoKeyIsPublic(makeCryptoKey(key, sizeof(key))));
|
||||
}
|
||||
|
||||
static void test_cryptoKeyIsPublic_invalidKeyIsNotPublic()
|
||||
{
|
||||
// length < 0 == no/invalid key (e.g. a disabled channel); it carries no traffic to leak.
|
||||
TEST_ASSERT_FALSE(cryptoKeyIsPublic(makeCryptoKey(nullptr, -1)));
|
||||
}
|
||||
|
||||
void setUp(void) {}
|
||||
|
||||
void tearDown(void) {}
|
||||
@@ -136,6 +224,14 @@ void setup()
|
||||
RUN_TEST(test_getPositionPrecisionForChannel_explicitZeroDisablesPrimary);
|
||||
RUN_TEST(test_getPositionPrecisionForChannel_primaryWithoutModuleSettingsFailsClosed);
|
||||
RUN_TEST(test_getPositionPrecisionForChannel_secondaryWithoutModuleSettingsFailsClosed);
|
||||
RUN_TEST(test_getPositionPrecisionForChannel_clampsPreciseOnDefaultKeyChannel);
|
||||
RUN_TEST(test_getPositionPrecisionForChannel_keepsPreciseOnStrongKeyChannel);
|
||||
RUN_TEST(test_cryptoKeyIsPublic_openKeyIsPublic);
|
||||
RUN_TEST(test_cryptoKeyIsPublic_defaultKeyIsPublic);
|
||||
RUN_TEST(test_cryptoKeyIsPublic_defaultKeyFamilyVariesLastByte);
|
||||
RUN_TEST(test_cryptoKeyIsPublic_strongKeyIsPrivate);
|
||||
RUN_TEST(test_cryptoKeyIsPublic_aes256KeyIsPrivate);
|
||||
RUN_TEST(test_cryptoKeyIsPublic_invalidKeyIsNotPublic);
|
||||
exit(UNITY_END());
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user