forked from tronprotocol/java-tron
-
Notifications
You must be signed in to change notification settings - Fork 0
fix(config,toolkit): harden keystore, grpc config and build supply chain #17
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
Show all changes
13 commits
Select commit
Hold shift + click to select a range
6aa4388
fix(keystore): fail fast on password stdin EOF instead of NPE
warku123 2a4950c
fix(keystore): validate KDF parameter bounds before decrypt
warku123 6a7000e
feat(cli): deprecate --private-key/--password in favor of localwitnes…
warku123 d8b8bd1
fix(config): harden gRPC connection lifetime default and warn on half…
warku123 6ec3d8a
build: pin Gradle distribution, enforce wrapper validation in CI, and…
warku123 fabe9a0
build(protocol): unify protoc-gen-grpc-java version and rebase docker…
warku123 f4f946e
fix(docker): stop persisting full node command line to command.txt
warku123 6129404
fix(toolkit): enforce owner-only permissions on password and key files
warku123 9b48faf
fix(review): address bot review findings on docker, rpc config, keyst…
warku123 7c67b40
fix(build): restore ProtocGenVersion 1.60 pin for centos7 compatibility
warku123 e963859
revert(docker): drop docker-side changes from this PR
warku123 fbe5bf9
fix(cli): drop @Deprecated from --password pending a real alternative
warku123 52971f5
fix(cli): drop --password startup WARN per review
warku123 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -107,8 +107,10 @@ public void testRpcDefaultsFromReference() { | |
| assertEquals(NodeConfig.RpcConfig.DEFAULT_MAX_CONCURRENT_CALLS_PER_CONNECTION, | ||
| rpc.getMaxConcurrentCallsPerConnection()); | ||
| assertEquals(1048576, rpc.getFlowControlWindow()); | ||
| assertEquals(9223372036854775807L, rpc.getMaxConnectionIdleInMillis()); | ||
| assertEquals(9223372036854775807L, rpc.getMaxConnectionAgeInMillis()); | ||
| // reference.conf keeps 0 (the default marker); postProcess converts 0 to | ||
| // the secure built-in 60s default, so the effective default is 60s. | ||
| assertEquals(60000L, rpc.getMaxConnectionIdleInMillis()); | ||
| assertEquals(60000L, rpc.getMaxConnectionAgeInMillis()); | ||
| assertEquals(4194304, rpc.getMaxMessageSize()); | ||
| assertEquals(8192, rpc.getMaxHeaderListSize()); | ||
| assertEquals(1, rpc.getMinEffectiveConnection()); | ||
|
|
@@ -146,6 +148,93 @@ public void testRpcNegativeConcurrentCallsRejected() { | |
| "node.rpc.maxConcurrentCallsPerConnection must be non-negative, got: -1")); | ||
| } | ||
|
|
||
| @Test | ||
| public void testRpcNegativeIdleAndAgeRejected() { | ||
| Config config = withRef( | ||
| "node { rpc { maxConnectionIdleInMillis = -1, maxConnectionAgeInMillis = 60000 } }"); | ||
|
|
||
| TronError exception = assertThrows(TronError.class, | ||
| () -> NodeConfig.fromConfig(config)); | ||
|
|
||
| assertTrue(exception.getMessage().contains( | ||
| "node.rpc.maxConnectionIdleInMillis and node.rpc.maxConnectionAgeInMillis " | ||
| + "must be non-negative, got: maxConnectionIdleInMillis=-1")); | ||
|
|
||
| Config config2 = withRef( | ||
| "node { rpc { maxConnectionIdleInMillis = 60000, maxConnectionAgeInMillis = -5 } }"); | ||
|
|
||
| exception = assertThrows(TronError.class, | ||
| () -> NodeConfig.fromConfig(config2)); | ||
|
|
||
| assertTrue(exception.getMessage().contains( | ||
| "maxConnectionAgeInMillis=-5")); | ||
| } | ||
|
|
||
| @Test | ||
| public void testRpcExplicitZeroIdleAndAgeFallsBackToSecureDefault() { | ||
| // Explicit 0 no longer means unlimited: postProcess converts 0 to the | ||
| // secure built-in 60s default. Operators wanting a longer lifetime must | ||
| // set an explicit positive value. | ||
| Config config = withRef( | ||
| "node { rpc { maxConnectionIdleInMillis = 0, maxConnectionAgeInMillis = 0 } }"); | ||
| NodeConfig nc = NodeConfig.fromConfig(config); | ||
| assertEquals(NodeConfig.RpcConfig.DEFAULT_MAX_CONNECTION_LIFETIME_IN_MILLIS, | ||
| nc.getRpc().getMaxConnectionIdleInMillis()); | ||
| assertEquals(NodeConfig.RpcConfig.DEFAULT_MAX_CONNECTION_LIFETIME_IN_MILLIS, | ||
| nc.getRpc().getMaxConnectionAgeInMillis()); | ||
| } | ||
|
|
||
| // ----- maxRstStream / secondsPerWindow: must be configured together ----- | ||
|
|
||
| @Test | ||
| public void testRpcRstPairBothZeroOk() { | ||
| // Default: feature off. Must not throw. | ||
| NodeConfig nc = NodeConfig.fromConfig(withRef()); | ||
| assertEquals(0, nc.getRpc().getMaxRstStream()); | ||
| assertEquals(0, nc.getRpc().getSecondsPerWindow()); | ||
| } | ||
|
|
||
| @Test | ||
| public void testRpcRstPairBothPositiveOk() { | ||
| Config config = withRef( | ||
| "node { rpc { maxRstStream = 1000, secondsPerWindow = 60 } }"); | ||
| NodeConfig nc = NodeConfig.fromConfig(config); | ||
| assertEquals(1000, nc.getRpc().getMaxRstStream()); | ||
| assertEquals(60, nc.getRpc().getSecondsPerWindow()); | ||
| } | ||
|
|
||
| private static TronError rstError(String hocon) { | ||
| Config config = withRef("node { rpc { " + hocon + " } }"); | ||
| return assertThrows(TronError.class, () -> NodeConfig.fromConfig(config)); | ||
| } | ||
|
|
||
| @Test | ||
| public void testRpcRstPairHalfConfiguredWarnsButStarts() { | ||
| // Only maxRstStream set: RST flood protection stays disabled, startup | ||
| // continues with a warning. | ||
| Config config = withRef("node { rpc { maxRstStream = 100 } }"); | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. P2: This test claims to verify that half-configured RST settings warn, but it only verifies startup continues and values remain unchanged. Capture the logger output and assert a WARN for each half-configured case so the security diagnostic cannot regress unnoticed. Prompt for AI agents |
||
| NodeConfig nc = NodeConfig.fromConfig(config); | ||
| assertEquals(100, nc.getRpc().getMaxRstStream()); | ||
| assertEquals(0, nc.getRpc().getSecondsPerWindow()); | ||
|
|
||
| // Only secondsPerWindow set: same trap, same warn-and-continue. | ||
| config = withRef("node { rpc { secondsPerWindow = 60 } }"); | ||
| nc = NodeConfig.fromConfig(config); | ||
| assertEquals(0, nc.getRpc().getMaxRstStream()); | ||
| assertEquals(60, nc.getRpc().getSecondsPerWindow()); | ||
| } | ||
|
|
||
| @Test | ||
| public void testRpcRstNegativeValuesRejected() { | ||
| TronError exception = rstError("maxRstStream = -1, secondsPerWindow = 60"); | ||
| assertTrue(exception.getMessage().contains( | ||
| "must be non-negative, got: maxRstStream=-1")); | ||
|
|
||
| exception = rstError("maxRstStream = 100, secondsPerWindow = -5"); | ||
| assertTrue(exception.getMessage().contains( | ||
| "must be non-negative, got: maxRstStream=100, secondsPerWindow=-5")); | ||
| } | ||
|
|
||
| @Test | ||
| public void testRpcUserOverrideExplicitValues() { | ||
| Config config = withRef( | ||
|
|
||
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
P2: When users follow
reference.confordocs/configuration.md, they are told that0means no limit, but this conversion makes both RPC limits 60 seconds. Update the configuration comments and documentation to describe the 60-second effective default and document the age setting consistently.Prompt for AI agents