Skip to content

Commit bdb4444

Browse files
committed
test(ping): capture a paged body, and a body that must not be paged
No suite in the screenshot set had an over-long body, so the pager's own rendering appeared NOWHERE in CI. The one behaviour 7.14.2 changed on the confirm path was the one behaviour no capture could show, which is how it came to be checked by pointing a camera at an OLED instead. test_ping_long_body_is_paged sends 255 characters and captures the numbered pages. The body is a digit ramp -- the Nth character is str(N % 10) -- so a character dropped or repeated at a page seam is visible by inspection rather than by counting. test_ping_short_body_is_not_paged is the control, and it is the more important of the two. A pager that numbered EVERY confirmation would make ordinary approvals cost extra presses, and without a negative case that regression passes unnoticed: more screens always looks like more disclosure. Both gated to 7.14.2 with requires_firmware, so they SKIP rather than fail on older builds. What these do NOT assert: the press durations. Intermediate pages advance on a short click and only the last page takes a hold -- there is no physical button in an emulator, so that half stays a hardware check. It is now a short list rather than a whole round.
1 parent 1a6e785 commit bdb4444

2 files changed

Lines changed: 56 additions & 0 deletions

File tree

‎scripts/generate-test-report.py‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -342,6 +342,21 @@ def parse_junit(path):
342342
'Binance denom renders in full',
343343
'A long denom must render completely and must not overflow the formatting buffer.',
344344
['Transfer screen showing the full denom']),
345+
('S12', 'test_msg_ping', 'test_ping_long_body_is_paged',
346+
'A long body is paged, not clipped',
347+
'A body that will not fit one screen is shown across several, with the page number '
348+
'in the title. Before 7.14.2 the device drew what fitted and stopped - no ellipsis, '
349+
'no warning - and a later warning screen claimed "Hold to view it anyway" while '
350+
're-drawing the same clipped text. These captures are the evidence that the '
351+
'remainder is now actually reachable. The press DURATIONS (click to page, hold to '
352+
'approve) are not assertable in an emulator with no physical button.',
353+
['Numbered page screens covering the whole body']),
354+
('S13', 'test_msg_ping', 'test_ping_short_body_is_not_paged',
355+
'A body that fits is not paged',
356+
'The control for S12. A fitting body must still take exactly one screen with an '
357+
'unnumbered title - otherwise a pager that numbered every confirmation, making '
358+
'ordinary approvals cost extra presses, would pass unnoticed.',
359+
['Single unnumbered confirmation screen']),
345360
]),
346361
('X', 'Device Specifications', '0.0.0',
347362
'The KeepKey is an open-source hardware wallet built on an ARM Cortex-M3 (STM32F205, 120MHz) '

‎tests/test_msg_ping.py‎

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,47 @@ def test_ping(self):
5555
res = self.client.ping('random data', passphrase_protection=True)
5656
self.assertEqual(res, 'random data')
5757

58+
def test_ping_long_body_is_paged(self):
59+
"""A body that will not fit one screen must be shown across several.
60+
61+
Before 7.14.2 the device drew what fitted and stopped: no ellipsis, no
62+
warning, nothing to tell the user the tail of an address or an amount
63+
had been dropped. A warning screen was then added that said "Hold to
64+
view it anyway" and re-drew the SAME clipped body, which is worse --
65+
it claims a disclosure it does not make.
66+
67+
Now the body is paged, and the titles carry n/m. This test exists so
68+
those pages are CAPTURED: the screens are the evidence, and until this
69+
test existed no suite with an over-long body was in the screenshot set,
70+
so the pager's own rendering appeared nowhere in CI.
71+
72+
The press DURATIONS -- click to page, hold to approve -- are not
73+
assertable here. The emulator has no physical button; that half needs
74+
hardware.
75+
"""
76+
self.requires_firmware("7.14.2")
77+
self.setup_mnemonic_nopin_nopassphrase()
78+
79+
# Digit ramp: the Nth character is str(N % 10), so a dropped or
80+
# repeated character at a page seam is visible by inspection.
81+
body = ''.join(str(i % 10) for i in range(255))
82+
res = self.client.ping(body, button_protection=True)
83+
self.assertEqual(res, body)
84+
85+
def test_ping_short_body_is_not_paged(self):
86+
"""The control for the test above.
87+
88+
A body that fits must still take exactly one screen with an unnumbered
89+
title. Without this, a pager that numbered every confirmation -- making
90+
ordinary approvals cost two presses -- would pass unnoticed.
91+
"""
92+
self.requires_firmware("7.14.2")
93+
self.setup_mnemonic_nopin_nopassphrase()
94+
95+
body = ''.join(str(i % 10) for i in range(100))
96+
res = self.client.ping(body, button_protection=True)
97+
self.assertEqual(res, body)
98+
5899
def test_ping_format_specifier_sanitize(self):
59100
self.setup_mnemonic_pin_passphrase()
60101
self.client.clear_session()

0 commit comments

Comments
 (0)