Add assertions to mnemonic generation - #976
Open
insumisos wants to merge 1 commit into
Open
Conversation
Should the UI not pass the correct number of dice rolls or coin flips then fail hard.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Problem or Issue being addressed
The dice and coin seed generation functions are trusting that the UI will submit the appropriate number of dice rolls or coin flips. Should the UI not do this, for whatever reason, then insufficient entropy could be passed to the hash function.
Solution
Don't trust the UI (client side validation), do local validation and fail hard if there isn't sufficient entropy.
Additional Information
Since the asserts are not handled then will probably crash the UI but that's probably desirable.
This pull request is categorized as a:
Checklist
I ran
pytestlocallyI added or updated tests
Any new or altered functionality should be covered in a unit test. Any new or updated sequences require FlowTests.
Removed ColdCard test as their example has small number of rolls (since it was supposed to be mixed with a HRNG) which fails. Instead tests whether assertion is thrown for invalid rolls.
I tested this PR hands-on on the following platform(s):
I have reviewed these notes: