Refuse a key index with no hardened child
All checks were successful
check / check (push) Successful in 23s
All checks were successful
check / check (push) Successful in 23s
Every element of the derivation path is hardened, so an index above 2147483647 has no child to derive: the hardened offset wrapped around and the tool silently produced a non-hardened key that no other implementation reading the path as written would reproduce. Such an index is now refused with a message before anything is derived, and tests pin the refusal at both the derivation and the command level. Also use the hook path variable in script/install-precommit instead of repeating the literal beside it. Model: opus-5
This commit is contained in:
@@ -38,6 +38,16 @@ func TestEveryIndexGivesItsOwnBytes(t *testing.T) {
|
||||
require.False(t, bytes.Equal(first, second))
|
||||
}
|
||||
|
||||
func TestAnIndexWithNoHardenedChildIsRefused(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
_, err := derive.Bytes(example(), application, derive.MaxIndex+1)
|
||||
require.ErrorIs(t, err, derive.ErrIndexTooLarge)
|
||||
|
||||
_, err = derive.Bytes(example(), application, derive.MaxIndex)
|
||||
require.NoError(t, err)
|
||||
}
|
||||
|
||||
func TestTheSameInputAlwaysGivesTheSameBytes(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user