breadcrumbs/networks.example.toml
Breadway 037c6e54c9 Harden breadcrumbs: fix real bugs, restructure as lib, stop storing PSKs twice
Bug fixes:
- mask() panicked on multi-byte UTF-8 passwords (byte-slicing a char
  boundary); now masks by char count and never echoes a real character
- `cd --shell` interpolated the config path into a shell -c string via
  Debug formatting, which doesn't neutralize shell metacharacters; now
  passed as a positional shell argument instead
- connecting to open (no-password) networks failed because an empty PSK
  was always sent to nmcli, which nmcli treats as secured-with-no-password
  instead of open; the password arg is now omitted entirely when empty
- five nmcli terse-output parse sites used a raw splitn(2, ':'), which
  mis-splits any device/connection name containing a literal ':'; unified
  on the existing escape-aware field splitter
- watch's health classifier silently read a config-deleted profile as
  "healthy" off a bare internet check instead of surfacing the misconfig
- the nmcli-monitor thread seeded its debounce clock with
  `Instant::now() - 10s`, which panics on the monotonic clock near boot —
  exactly when the generated systemd unit tends to start the watcher

Architecture:
- extracted src/lib.rs + src/app.rs so command logic can be exercised
  in-process by tests instead of only by spawning the compiled binary
- added a Runner trait (src/util.rs) so subprocess calls can be faked in
  tests; flow::run and watch::classify are now covered by real in-process
  tests of the connect state machine and health transitions, not just
  their pure helpers
- Wi-Fi passwords are no longer kept in breadcrumbs' config once
  NetworkManager durably holds them: NetworkDef.password is now optional,
  and a successful password-based connect clears + persists it
  immediately, so it's never sent again on subsequent connects
- saved networks (SSID + optional local password) moved out of
  breadcrumbs.toml into a separate networks.toml; old configs with
  inline [[networks]] still load and migrate automatically on next save
- corrected a false README claim that passwords are never in nmcli argv

Test count: 20 -> 89 (52 unit, 24 CLI integration, 13 in-process
state-machine tests). Full clean run: cargo build/build --release/
test/clippy --all-targets, verified from a `cargo clean` rebuild.
2026-07-22 06:58:47 +08:00

29 lines
1 KiB
TOML

# breadcrumbs saved-networks file.
#
# Lives alongside breadcrumbs.toml at ~/.config/breadcrumbs/networks.toml,
# 0600 permissions. Shown here purely for reference — you normally never
# hand-edit this file; use `breadcrumbs add` / `scan` / `forget` instead.
#
# `password` is optional and only needed the first time breadcrumbs connects
# to a network. Once NetworkManager has durably saved the credential (either
# a brand-new connection profile, or an updated PSK on an existing one),
# breadcrumbs clears its own local copy and omits the `password` key
# entirely on the next save — both the plaintext-on-disk copy and the
# argv exposure on every subsequent connect go away for that network from
# then on. Omit `password` altogether for a genuinely open (no-security)
# network, or for one NetworkManager already knows about.
[[networks]]
ssid = "HomeWifi"
password = "REPLACE_ME"
hidden = false
[[networks]]
ssid = "WorkGuest"
password = "REPLACE_ME"
hidden = false
[[networks]]
ssid = "CorpWifi"
password = "REPLACE_ME"
hidden = false