Repository navigation
fix(e2e-exe-dev): validate the whole credential file as sent - #30
Merged
Merged
Conversation
check_key_file and exe-run.sh read only the first 4096 characters, but every consumer sends the whole file with CR/LF removed. A valid key plus enough blank lines and trailing text passed, the text was stored with the key, and NANOCLAW_E2E_FORCE_AUTH=1 then deleted the working secret. Check the full value and refuse files over 64 KiB.
Text mode folds CRLF before counting, so CRLF padding halved the apparent size and slipped past the 64 KiB limit.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes?
check_key_fileine2e-install.sh(added by #28) and the matching host check inexe-run.shread only the first 4096 characters of the credential file. Every consumer sends the whole file with CR/LF removed:onecli secrets createon the gateway seam,auth --create [--force] --valueon the legacy path, andKEY_VALUEfor iron-proxy.So a valid
sk-ant-key, then enough blank lines to pass 4096 characters, then other text, passed the check, and the extra text was stored with the key. Since #29,NANOCLAW_E2E_FORCE_AUTH=1then deleted the working old secret.proxmox-run.py, which already reads the whole file.Plugin 0.12.4; CHANGELOG and catalog updated.
Validation
python -m unittest discover -s testswithskills/e2e-wizard/requirements.txtinstalled: 362 tests, one error. That error istest_payload_transport.test_alternate_owning_remote_transports_exact_selected_commit, which also fails on main.exe-run.shdriver: key + 5000 newlines + text is refused before any VM call (exit 66).secrets createnever runs, and the old secret stays in the vault.