fix/audit-security #5

Merged
faicel merged 38 commits from fix/audit-security into dev 2026-09-05 13:39:27 +00:00
Owner
No description provided.
class,
  re-exported at the crate root (`tools::Mac`). It is now the single
  source of
  truth for every identity conversion in the ecosystem: hardware UID to
  MAC
  display string (`getmac`), wire PeerId (`peer_id`), and
  text-to/from-wire
  forms (`peer_id_from_mac_str`, `peer_id_from_hex`, `peer_id_to_hex`).
- Breaking: the legacy free-function MAC API is removed outright (no
  deprecated alias, no compatibility shim); use the `Mac` class instead.
  Display-MAC output is byte-identical to the former API (golden tests
  pin
  the compatibility), so already-provisioned identities keep working.
- Tests for the `mac` module migrated to the `src/mac/tests/` directory
  architecture and extended with wire-compatibility golden vectors.
- Update README.md
- Forgejo CI migrated to the shared faicel/central_ci thin-caller
All checks were successful
Run checks on feature branches / rust-crate-checks (push) Successful in 22s
Run checks on feature branches / checks (push) Successful in 0s
011b372126
setup
  (as in `lis2dh12`): `check-on-feature-branch`, `create-tag-on-dev`,
  `create-tag-on-main`, `publish-on-tag`, `validate-branch-flow`, plus a
  `.forgejo/README.md`. The former self-contained workflows
  (`enforce-branch-flow`, `publish-on-dev`, `publish-on-main`,
  `publish-on-tag`) are removed.
- `deny.toml` (cargo-deny): advisories with `yanked = "deny"`,
  transitive
  unmaintained non-fatal (`unmaintained = "workspace"`), license
  allow-list,
  wildcard-path and unknown-source bans; checked in CI.
- `scripts/`: shared quality-gate entrypoint (`test.sh`) with
  `check-version-sync.sh`, `deny-check.sh`, `release-branch-name.sh`,
  `resolve-cargo-registry.sh` and their self-tests (mirrors `lis2dh12`).

- New `default` feature enabling every module, so plain `cargo clippy` /
  `cargo test` (and CI) exercise the whole crate. Consumers should keep
  `default-features = false` and enable only the features they use.
- `spin` lockfile entry updated `0.9.8` → `0.9.9` (0.9.8 was yanked).
- Fixed a broken intra-doc link (`AD[5:0]`) in `register::st_mems` docs
  caught by the new `cargo doc` gate.
- Share one MAX_PAYLOAD frame limit across all register protocols;
  oversized burst reads and writes return BusError::PayloadTooLong
  instead of panicking on a fixed-size frame or silently truncating.
- msb_flag read/write return Result and propagate bus errors instead
  of fabricating a zero reading; the MSB-flag payload capacity grows
  from 31 to 32 bytes; the frame uses a plain stack array instead of
  heapless::Vec.
- Remove the top-level register re-exports of the msb_flag functions
  and all backward-compatibility wording; both protocol modules are
  documented as equal first-class options (module name kept: it
  describes the bit-7 read/write flag wire encoding required by the
  SX1278).
- Drop the unexplained inline(never) attributes; add debug asserts on
  the 6-bit ST-MEMS register address field.
- Document the breaking signature changes and the libs/lora migration
  impact in the changelog.
encrypt/decrypt now take caller-owned slices with an explicit length and
return the number of bytes written or read, removing the transitive
chacha20poly1305::aead::heapless::Vec from the public API. The capacity
requirement (message + 28 bytes) is validated with checked arithmetic via
a unit-testable helper, and any decrypt failure zeroes the frame region so
no unauthenticated bytes survive in the caller's buffer. The nonce-prefixed
wire format is unchanged, so previously stored ciphertexts remain
decryptable. Tests rewritten to the slice API with length-boundary,
overflow-helper, tamper-reject, AAD-mismatch and at-capacity coverage.
Both public constructors now delegate to one private constructor holding
the single field-assembly body; the duplicated argument doc block is
documented once. Public API, signatures and behavior are unchanged.
Move the flat per-module tests.rs files of encryption, register, rgb and
compression into tests/mod.rs, matching the layout the other modules
already use, and make every test module private. Pure moves plus the
module declaration edits: no test content changes, test count unchanged
at 53.
The alias name now describes the LZSS codec configuration instead of
carrying a meaningless prefix. The alias is private, so this is a pure
internal rename with no public API or behavior change.
Source-level rename under the no-legacy policy: no deprecated alias, no
wrapper. The display MAC string format is unchanged and all golden vectors
stay byte-identical. Test functions carrying the old name (and the former
compatibility label) are renamed accordingly. Migration note added to the
CHANGELOG Unreleased section.
Add compress_with_buffer/decompress_with_buffer with typed CompressWindow
(2048 B) and DecompressWindow (1024 B) aliases so embedded callers place
the LZSS window in static or caller-controlled memory instead of the
stack. Semantics, error mapping and compressed bytes are identical to the
stack-based API. compress/decompress docs now state their window stack
depth and full-window memset per call. Additive and non-breaking.
read_burst drops its 33-byte staging frame and the final copy: inside the
same chip-select window it now writes the command byte, zero-fills the
payload region (dummy bytes on MOSI stay zeros, as the old zero-initialized
frame transmitted) and transfers the payload in place, directly into the
caller's buffer. Wire bytes are identical, the 32-byte PayloadTooLong
contract is unchanged, and the inter-frame-interval caveat of the split
transfer (two SPI operations under one GPIO-held CS) is documented in the
bus module docs. Mock expectations updated; a new test pins that a
non-zero-prefilled buffer never leaks onto MOSI.
st_mems::write_register and msb_flag::write_register now write the
command byte and the payload as two spi.write operations inside one
with_cs window, straight from the caller's slice, via the shared
private helper bus::write_cmd_then_payload. The 33-byte staging frame
and the payload copy are gone; the effective wire bytes (command then
payload), the empty-write and PayloadTooLong contracts are unchanged.
The inter-frame-interval caveat for the split transfer is documented in
the bus module docs and both write_register doc comments. Mock write
expectations updated to the two-write sequence.
New core primitive register:🚌:with_cs_timing takes explicit setup_us
and post_cs_us values, applied in the fixed electrical order CS low ->
setup delay -> SPI operation(s) -> CS high -> post-CS spacing delay.
Timing variants of every register helper delegate to it, and the
existing defaults become one-line wrappers passing CS_DELAY_US for both
windows, so their behavior is byte-identical (10 us setup + 10 us
post-CS). New shared-log recorder tests pin the default 10/10 counts
and the configured counts in order.
Both hex directions now go through a shared 16-entry uppercase nibble
table: mac_string and peer_id_to_hex index it per nibble for output,
peer_id_from_hex searches it per digit for decoding, folding lowercase
digits to uppercase so the accepted input set stays identical to the
former case-insensitive radix-16 parse. The strict contract (34 digits,
optional 0x/0X prefix, rejection of wrong lengths, non-hex digits and
separators) is unchanged, output bytes are identical (golden vectors and
round-trip tests pass unchanged), no public API change, and core::fmt
formatting machinery is no longer linked on this path.
The slice-based encryption API never touches the aead::heapless re-export,
so the cargo feature only linked heapless 0.7 and its transitive
unmaintained-advisory chain (atomic-polyfill) into every encryption
consumer. Cargo.lock refreshed; the stale heapless-0.7 advisory comment in
deny.toml now reflects the shorter graph; heapless 0.9 remains solely
behind the mac feature.
Raw bits are von Neumann-debiased in pairs (01 -> 0, 10 -> 1, 00/11
discarded), removing stationary bias from independent samples. Two
fail-closed health checks guard every call: 640+ consecutive identical
raw samples return EntropyError::Degenerate (stuck source, detected
after exactly 640 samples) and a 256 x N raw-sample cap returns
EntropyError::Exhausted instead of blocking forever on a marginal
source. rand now returns Result<[u8; N], EntropyError>; migration note
documented in the 1.1.0 breaking-changes section, README example and
cost figures updated (nominal ~320 us/byte, cap-bounded ~81.9 ms per
32-byte nonce).
State the ChaCha20-Poly1305 nonce contract on encrypt (unique per key for
the key lifetime, random 12-byte nonces acceptable up to ~2^32 messages
per key, full-entropy keys and nonces, matching AAD on both sides) and
the key-ownership contract on encrypt and decrypt (caller owns the key
buffer's lifetime and wiping; the cipher's internal key-schedule copy is
zeroized on drop by the RustCrypto stack via cipher's default zeroize
feature). Add a compiling and running round-trip rustdoc example.
Documentation only: no signature change, no dependency, no behavior
change.
Add Unreleased section to changelog
All checks were successful
Enforce branch flow / validate-flow (pull_request_target) Successful in 2s
Enforce branch flow / lint-and-test (pull_request_target) Successful in 1m31s
Run checks on feature branches / rust-crate-checks (push) Successful in 18s
Run checks on feature branches / checks (push) Successful in 0s
c645dae32f
Merge branch 'dev' into fix/audit-security
All checks were successful
Enforce branch flow / validate-flow (pull_request_target) Successful in 2s
Enforce branch flow / lint-and-test (pull_request_target) Successful in 1m30s
Run checks on feature branches / rust-crate-checks (push) Successful in 17s
Run checks on feature branches / checks (push) Successful in 0s
fd293a13ce
Add codeOwners
All checks were successful
Run checks on feature branches / rust-crate-checks (push) Successful in 16s
Enforce branch flow / validate-flow (pull_request_target) Successful in 2s
Run checks on feature branches / checks (push) Successful in 0s
Enforce branch flow / lint-and-test (pull_request_target) Successful in 1m33s
e2180cc713
faicel deleted branch fix/audit-security 2026-09-05 13:39:28 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
homeiot/tools!5
No description provided.