fix(connectivity): guard BLE preference writes - #528
meganetaaan wants to merge 3 commits into
Conversation
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughThis PR adds a BLE preference write validation mechanism: a new ChangesBLE Preference Write Guard
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant SetupMode
participant PreferenceServer
participant WriteGuard as validatePreferenceWrite
participant Preference
SetupMode->>PreferenceServer: enableWrites(durationMs)
PreferenceServer->>PreferenceServer: start write-window timer, set writesEnabled=true
Note over PreferenceServer: BLE client sends domain.key/value
PreferenceServer->>WriteGuard: validatePreferenceWrite(allowedKeys, writesEnabled, domain, key)
WriteGuard-->>PreferenceServer: decision (allowed or rejection reason)
alt allowed
PreferenceServer->>Preference: set(domain.key, value)
PreferenceServer-->>SetupMode: onPreferenceChanged
else rejected
PreferenceServer->>PreferenceServer: trace(rejection reason)
end
PreferenceServer->>PreferenceServer: write-window timer fires, disableWrites()
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
firmware/host/app/setup-mode.ts (1)
60-76: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winTime-box the BLE write window
firmware/host/app/setup-mode.ts:76— pass adurationMstopreferenceServer.enableWrites(). The whitelist limits what can change, but the opt-in write window should still expire automatically instead of staying open for the full setup session.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@firmware/host/app/setup-mode.ts` around lines 60 - 76, The BLE write window is left open indefinitely because PreferenceServer.enableWrites() is called without an expiry; update setup-mode.ts to pass a durationMs when enabling writes so the opt-in window closes automatically after a short period. Use the existing PreferenceServer instance in setup-mode.ts and adjust the enableWrites() call to include an appropriate time limit while keeping the current whitelist behavior intact.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@firmware/host/app/setup-mode.ts`:
- Around line 60-76: The BLE write window is left open indefinitely because
PreferenceServer.enableWrites() is called without an expiry; update
setup-mode.ts to pass a durationMs when enabling writes so the opt-in window
closes automatically after a short period. Use the existing PreferenceServer
instance in setup-mode.ts and adjust the enableWrites() call to include an
appropriate time limit while keeping the current whitelist behavior intact.
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 56099d6d-b46f-4dd1-b20b-038c4da05ab2
📒 Files selected for processing (6)
firmware/host/app/setup-mode.tsfirmware/host/modules/connectivity/__tests__/fakes/uartserver.tsfirmware/host/modules/connectivity/__tests__/preference-write-guard.test.tsfirmware/host/modules/connectivity/preference-server.tsfirmware/host/modules/connectivity/preference-write-guard.tsfirmware/tsconfig.test.json
概要
BLE preference server が任意の Preference 書き込みを受け付けないよう、書き込み window と whitelist を追加します。
変更内容
検証
未実施
リリース影響
patch。脆弱な書き込み経路を制限する修正のため、リリースノート記載が必要です。
Closes #505
関連 #399
🤖 Generated with Claude Code
Summary by CodeRabbit
New Features
Bug Fixes