Commit 69573b2
authored
Collection of bug-fixes (#993)
* fix #948: missing return in IOU amount underflow path (#948)
When an IOU value's normalized mantissa falls below MIN_IOU_MANTISSA
or its exponent falls below MIN_IOU_EXPONENT, the serializer computed
the canonical zero bytes but dropped the result on the floor. Execution
fell through to the general serialization path, producing a non-zero
amount for a value that should round to zero (e.g. "1e-82" serialized
to c0405af3107a4000 instead of 8000000000000000).
Add the missing `return` so underflowing IOU amounts serialize to the
canonical zero representation defined in the XRPL binary format spec
(type bit set, sign/exponent/mantissa all zero).
Includes a regression test covering 1e-82, 1e-96, and -1e-96.
* fix: do not expose seed in Wallet init error message (#987)
The XRPLAddressCodecException raised when a Wallet is constructed with
an invalid seed embedded the raw seed in the message. Exception text is
commonly logged or shipped to error-tracking systems, so this leaked
secret material into places it should never reach.
Remove the seed from the error message; keep the algorithm and the
underlying decoder error for debuggability. Add a regression test that
constructs a Wallet with a bogus seed and asserts the seed string is
not present in str(exc).
* fix: redact secret fields in BaseModel __repr__ (#992)
repr()/str() of Sign, SignFor, SignAndSubmit, and ChannelAuthorize
included the raw `secret`, `seed`, `seed_hex`, and `passphrase` values
because @DataClass auto-generated a __repr__ on each subclass that
shadowed BaseModel's. That placed secret material anywhere object
reprs land: logs, error-tracking systems (Sentry, Datadog), debugger
output, and traceback frame locals.
Fix centrally on BaseModel:
- Define _SENSITIVE_FIELDS listing the redacted field names.
- Install BaseModel.__repr__ via __init_subclass__ before @DataClass
runs, so the decorator sees __repr__ already defined and skips
auto-generating. Every BaseModel subclass now flows through the
redacting repr with no per-class opt-in.
- Rewrite BaseModel.__repr__ to iterate dataclasses.fields() and emit
'***REDACTED***' for sensitive fields. to_dict() is unchanged, so the
wire payload still carries real values.
* fix: use cryptographic RNG for WebSocket request IDs (#986)
Request ID generation used random.randrange over a 1M-element keyspace.
Mersenne Twister state is recoverable from observed outputs, so an
attacker who can inject WebSocket frames (wss misconfiguration,
TLS-intercepting proxy, relay between client and server) could predict
upcoming IDs and race a forged response to resolve a pending await
with attacker-controlled data — forged balances, fake tesSUCCESS on
submit, bogus tx confirmations.
The small keyspace also caused birthday collisions on long-lived
connections around 1,177 requests, triggering spurious "already in
progress" errors without an attacker.
Switch to secrets.randbelow and widen _REQ_ID_MAX to 2**62 so both
issues go away. IDs are embedded in a string so arbitrary Python
ints are fine; no wire-format change.
* minor: linter fixes
* minor: fix mypy error
* minor: Use HIDDEN instead of REDACTED to denote sensitive field-values
* tests: address PR comments suggesting wider test coverage (points 4, 5)
* integ test: update docker command to be consistent with recent updates to xrpld executable
* fix: skip malformed JSON frames in WebSocket handler (#977)
A single malformed frame used to propagate json.JSONDecodeError out of
_handler, killing the background task and silencing the client for the
remainder of the connection. Wrap json.loads in try/except so malformed
frames are dropped and the async-for loop continues.
Also backfills CHANGELOG entries for this fix and for the earlier
cryptographic RNG change (#986), both landing in websocket_base.py.
* minor: print warnings to stdout before dropping a malformed frame
* minor: address PR comments
* minor: remove traces of seed material in error msg1 parent a68a2f0 commit 69573b2
11 files changed
Lines changed: 310 additions & 18 deletions
File tree
- tests/unit
- asyn/clients
- core/binarycodec/types
- models
- requests
- wallet
- xrpl
- asyncio/clients
- core/binarycodec/types
- models
- wallet
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| 19 | + | |
| 20 | + | |
19 | 21 | | |
20 | 22 | | |
21 | 23 | | |
| |||
Whitespace-only changes.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
205 | 205 | | |
206 | 206 | | |
207 | 207 | | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
208 | 238 | | |
209 | 239 | | |
210 | 240 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
80 | 80 | | |
81 | 81 | | |
82 | 82 | | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
3 | 4 | | |
4 | 5 | | |
| 6 | + | |
| 7 | + | |
5 | 8 | | |
6 | 9 | | |
| 10 | + | |
7 | 11 | | |
8 | 12 | | |
9 | 13 | | |
10 | 14 | | |
| 15 | + | |
11 | 16 | | |
12 | 17 | | |
13 | 18 | | |
14 | 19 | | |
15 | 20 | | |
| 21 | + | |
| 22 | + | |
16 | 23 | | |
17 | 24 | | |
18 | 25 | | |
19 | 26 | | |
20 | 27 | | |
| 28 | + | |
| 29 | + | |
21 | 30 | | |
22 | 31 | | |
23 | 32 | | |
| |||
70 | 79 | | |
71 | 80 | | |
72 | 81 | | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
73 | 127 | | |
74 | 128 | | |
75 | 129 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
| 7 | + | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
22 | 25 | | |
23 | 26 | | |
24 | 27 | | |
| |||
47 | 50 | | |
48 | 51 | | |
49 | 52 | | |
50 | | - | |
| 53 | + | |
51 | 54 | | |
52 | 55 | | |
53 | 56 | | |
| |||
133 | 136 | | |
134 | 137 | | |
135 | 138 | | |
136 | | - | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
137 | 149 | | |
138 | 150 | | |
139 | 151 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
209 | 209 | | |
210 | 210 | | |
211 | 211 | | |
212 | | - | |
| 212 | + | |
213 | 213 | | |
214 | 214 | | |
215 | 215 | | |
| |||
0 commit comments