security: E2EE and transport correctness (issue #147)
Some checks failed
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 24s
CI Code / Linux (debian) (pull_request) Failing after 45s
CI Code / Linux (arch) (pull_request) Failing after 51s
CI Code / Linux (ubuntu) (pull_request) Failing after 3m57s
CI Code / Code Coverage (pull_request) Failing after 6m19s
Some checks failed
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 24s
CI Code / Linux (debian) (pull_request) Failing after 45s
CI Code / Linux (arch) (pull_request) Failing after 51s
CI Code / Linux (ubuntu) (pull_request) Failing after 3m57s
CI Code / Code Coverage (pull_request) Failing after 6m19s
T04: promote security events to warnings — SASL auth failure, TLS handshake failure, cert-failure details, see-other-host redirect; DISABLE_TLS, TRUST_TLS and LEGACY_AUTH get a log warning plus a console notice (REQ-LOG-01, REQ-LOG-02, REQ-AUTH-03) T05: warn when a session ends up unencrypted without the user having asked for it; refuse in-band registration on an unencrypted stream; warn on each HTTP transfer with certificate verification disabled (REQ-CRY-03, REQ-CFG-01) T06: pin the update check to https with peer/host verification and no redirects; strict N.N.N parser for the fetched version, which is untrusted network input (REQ-VUL-02) T09: no plaintext logging on failed MUC OMEMO sends; OTR opportunistic first message passes allow_unencrypted_message(); get_random_string() draws from a CSPRNG without modulo bias; guard the identity-key length decrement against unsigned underflow (REQ-CRY-01, REQ-CRY-02, REQ-CRY-07, REQ-MEM-05) REQ-VUL-03 and REQ-CRY-09 are already satisfied on master and are left unchanged. The console warnings use cons_show_warning() from #87, so this needs that change in master first.
This commit is contained in:
@@ -1089,6 +1089,45 @@ release_is_new__tests__various(void** state)
|
||||
assert_false(release_is_new("0.16.0", ""));
|
||||
assert_false(release_is_new(NULL, "1.0.0"));
|
||||
assert_false(release_is_new("1.0.0", NULL));
|
||||
|
||||
// the found version is untrusted network input: nothing but strictly N.N.N may parse
|
||||
assert_false(release_is_new("0.16.0", " 1.0.0")); // leading whitespace
|
||||
assert_false(release_is_new("0.16.0", "+1.0.0")); // explicit sign
|
||||
assert_false(release_is_new("0.16.0", "-1.0.0")); // negative major
|
||||
assert_false(release_is_new("0.16.0", "1.0.0-rc1")); // trailing garbage
|
||||
assert_false(release_is_new("0.16.0", "1.0.0\n")); // trailing newline
|
||||
assert_false(release_is_new("0.16.0", "1..0")); // empty component
|
||||
assert_false(release_is_new("0.16.0", "0x10.0.0")); // hex is not accepted
|
||||
assert_false(release_is_new("0.16.0", "99999999999.0.0")); // out of int range, must not wrap
|
||||
assert_false(release_is_new("0.16.0", "1.0.0 malicious"));
|
||||
|
||||
// Boundary: the largest still-parsable component is accepted
|
||||
assert_true(release_is_new("0.16.0", "2147483647.0.0"));
|
||||
}
|
||||
|
||||
void
|
||||
get_random_string__generates_valid_ids(void** state)
|
||||
{
|
||||
const gchar* alphabet = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ";
|
||||
|
||||
for (size_t len = 1; len <= 40; len++) {
|
||||
gchar* id = get_random_string(len);
|
||||
assert_non_null(id);
|
||||
assert_int_equal(len, strlen(id));
|
||||
for (size_t i = 0; i < len; i++) {
|
||||
assert_non_null(strchr(alphabet, id[i]));
|
||||
}
|
||||
g_free(id);
|
||||
}
|
||||
|
||||
// a collision here would mean a dead random source
|
||||
gchar* a = get_random_string(20);
|
||||
gchar* b = get_random_string(20);
|
||||
assert_non_null(a);
|
||||
assert_non_null(b);
|
||||
assert_string_not_equal(a, b);
|
||||
g_free(a);
|
||||
g_free(b);
|
||||
}
|
||||
|
||||
void
|
||||
|
||||
Reference in New Issue
Block a user