Skip to content

Develop - #28

Merged
EarMaster merged 3 commits into
mainfrom
develop
Sep 27, 2026
Merged

EarMaster merged 3 commits into
mainfrom
develop

Conversation

@EarMaster

Copy link
Copy Markdown
Owner

No description provided.

EarMaster and others added 3 commits September 27, 2026 16:50
The tree had never been through rustfmt, so `cargo fmt --check` found
324 differences and failed every CI run. This is `cargo fmt` and
nothing else, in its own commit so the next one's fixes stay readable
and `git blame` can skip it (.git-blame-ignore-revs, added next).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Clippy and fmt ran on every push but were advisory, so their failures
showed as two red annotations on a green pipeline and nobody acted on
them. This clears all 20 findings - 14 in the lib, 6 in tests: flatten
instead of `if let Ok`, a slice instead of `&Vec`, a useless `.max(0)`
on a u32, a `?` for an if-let chain, a match that only builds the
handshake timeout error, and the like. None changes behaviour. The one
Linux-only finding, an unused `safe_path` in show_in_folder, moves the
conversion into the two branches that use it.

The workflow now runs `cargo clippy --all-targets -- -D warnings` so
tests are covered too, and drops continue-on-error from both steps.

Checked: clippy --all-targets and fmt --check clean, 169 cargo tests
and 248 vitest pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
CodeQL's rust/hard-coded-cryptographic-value query flagged the
Argon2id salt in localkey.rs: it reads a zeroed array literal and
doesn't follow the fill_bytes call right after it that overwrites
the array with random bytes, so it sees the zero bytes as the salt
actually used.

Collapse every salt and nonce built this way to a single
`let x: [u8; N] = rand::random();`, so the randomness is the
declaration's own value with no later mutation for the scanner to
miss. Same thread CSPRNG, same output distribution - only the shape
of the code changes. Left the key buffers that are Zeroizing
wrappers on fill_bytes, since filling them in place is what keeps an
unzeroed copy of the key off the stack. Dropped the now-unused
rand::RngCore imports.

No user-visible behavior changes, so no CHANGELOG entry.

Checked: cargo fmt, cargo clippy --all-targets -D warnings, and
cargo test (169 passed) all clean.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@EarMaster
EarMaster merged commit 9e78238 into main Sep 27, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant