Harden breadcrumbs: fix real bugs, restructure as lib, stop storing PSKs twice
Bug fixes: - mask() panicked on multi-byte UTF-8 passwords (byte-slicing a char boundary); now masks by char count and never echoes a real character - `cd --shell` interpolated the config path into a shell -c string via Debug formatting, which doesn't neutralize shell metacharacters; now passed as a positional shell argument instead - connecting to open (no-password) networks failed because an empty PSK was always sent to nmcli, which nmcli treats as secured-with-no-password instead of open; the password arg is now omitted entirely when empty - five nmcli terse-output parse sites used a raw splitn(2, ':'), which mis-splits any device/connection name containing a literal ':'; unified on the existing escape-aware field splitter - watch's health classifier silently read a config-deleted profile as "healthy" off a bare internet check instead of surfacing the misconfig - the nmcli-monitor thread seeded its debounce clock with `Instant::now() - 10s`, which panics on the monotonic clock near boot — exactly when the generated systemd unit tends to start the watcher Architecture: - extracted src/lib.rs + src/app.rs so command logic can be exercised in-process by tests instead of only by spawning the compiled binary - added a Runner trait (src/util.rs) so subprocess calls can be faked in tests; flow::run and watch::classify are now covered by real in-process tests of the connect state machine and health transitions, not just their pure helpers - Wi-Fi passwords are no longer kept in breadcrumbs' config once NetworkManager durably holds them: NetworkDef.password is now optional, and a successful password-based connect clears + persists it immediately, so it's never sent again on subsequent connects - saved networks (SSID + optional local password) moved out of breadcrumbs.toml into a separate networks.toml; old configs with inline [[networks]] still load and migrate automatically on next save - corrected a false README claim that passwords are never in nmcli argv Test count: 20 -> 89 (52 unit, 24 CLI integration, 13 in-process state-machine tests). Full clean run: cargo build/build --release/ test/clippy --all-targets, verified from a `cargo clean` rebuild.
This commit is contained in:
parent
d177cc8d82
commit
037c6e54c9
16 changed files with 2688 additions and 834 deletions
29
networks.example.toml
Normal file
29
networks.example.toml
Normal file
|
|
@ -0,0 +1,29 @@
|
|||
# breadcrumbs saved-networks file.
|
||||
#
|
||||
# Lives alongside breadcrumbs.toml at ~/.config/breadcrumbs/networks.toml,
|
||||
# 0600 permissions. Shown here purely for reference — you normally never
|
||||
# hand-edit this file; use `breadcrumbs add` / `scan` / `forget` instead.
|
||||
#
|
||||
# `password` is optional and only needed the first time breadcrumbs connects
|
||||
# to a network. Once NetworkManager has durably saved the credential (either
|
||||
# a brand-new connection profile, or an updated PSK on an existing one),
|
||||
# breadcrumbs clears its own local copy and omits the `password` key
|
||||
# entirely on the next save — both the plaintext-on-disk copy and the
|
||||
# argv exposure on every subsequent connect go away for that network from
|
||||
# then on. Omit `password` altogether for a genuinely open (no-security)
|
||||
# network, or for one NetworkManager already knows about.
|
||||
|
||||
[[networks]]
|
||||
ssid = "HomeWifi"
|
||||
password = "REPLACE_ME"
|
||||
hidden = false
|
||||
|
||||
[[networks]]
|
||||
ssid = "WorkGuest"
|
||||
password = "REPLACE_ME"
|
||||
hidden = false
|
||||
|
||||
[[networks]]
|
||||
ssid = "CorpWifi"
|
||||
password = "REPLACE_ME"
|
||||
hidden = false
|
||||
Loading…
Add table
Add a link
Reference in a new issue