tests: cover the two refusals on the two-button devices - #145
Merged
Merged
Conversation
Every two-button test walks a path that succeeds: a phrase that matches, shares that recombine, a set that generates. The screens that refuse are a different flow -- ux_bip39_invalid_flow and ux_sskr_invalid_flow in src/bagl/ux_nano.c -- reached from a different branch of screen_onboarding_restore_word_validate(), and neither had ever been displayed under test on these devices. They are also the screens with the most at stake. Telling a holder their backup is unreadable when it is fine sends them to re-enter it; telling them it is fine when it is not sends them away with something that will not open their device. Both cases stop before the seed comparison, and for different reasons, which is why both are here: the phrase is twelve real words whose checksum does not close, so bolos_ux_bip39_mnemonic_check() refuses it and no seed is derived; the shares carry one substituted ByteWord, so the CRC-32 over the frame no longer matches and bolos_ux_sskr_hex_check() refuses the set. Each vector differs from a passing test by exactly one word -- "planet" to "zoo" against test_bip39_seed_match.py, "chef" to "cost" against the shares test_sskr_128bit.py enters -- and every word stays in its wordlist, so entry accepts them all and the refusal comes from the check under test rather than from a word the screen would not take. Both verdicts are asserted on two lines. The first line alone appears on screens that are not these, and the verdict screens of this application differ by their second line rather than their first.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every two-button test walks a path that succeeds: a phrase that matches, shares that recombine, a set that generates. The screens that refuse are a different flow —
ux_bip39_invalid_flowandux_sskr_invalid_flowinsrc/bagl/ux_nano.c— reached from a different branch ofscreen_onboarding_restore_word_validate(), and neither had ever been displayed under test on these devices.They are also the screens with the most at stake. Telling a holder their backup is unreadable when it is fine sends them to re-enter it; telling them it is fine when it is not sends them away with something that will not open their device.
Both cases stop before the seed comparison, and for different reasons, which is why both are here:
bolos_ux_bip39_mnemonic_check()refuses it and no seed is ever derived;bolos_ux_sskr_hex_check()refuses the set.Each vector differs from a passing test by exactly one word —
planet→zooagainsttest_bip39_seed_match.py,chef→costagainst the sharestest_sskr_128bit.pyenters — and every word stays in its wordlist, so entry accepts them all and the refusal comes from the check under test rather than from a word the screen would not take.Both verdicts are asserted on two lines. The first line alone appears on screens that are not these, and the verdict screens of this application differ by their second line rather than their first.
Verification
Not covered
Still uncovered on these devices: too few shares, a duplicated share, a threshold the scheme refuses, and the rest of the suite that skips there.