fix(aprs): the login line was malformed, and the refusal was invisible

An auditor ran the plan's own release gate against live APRS-IS servers. It failed at
the login step, on every server tried:

    sent: user N0CALL pass -1 vers Look4Sat-4.5.4
    got:  # Invalid login: software name and version are not separated by a space

Reproduced on euro.aprs2.net and noam.aprs2.net, aprsc 2.1.21. `vers` takes TWO tokens,
a software name and a version. An earlier commit read the rule "softwarename must not
contain a space" as "the field must be one token" and hyphenated the space between them
- and the unit test asserted that as correct, so the mistake was frozen in place.

Worse than the malformed line was what happened next. `# Invalid login:` is a comment
but not a logresp, so parse skipped it as keepalive chatter; the login then timed out
into Unknown, which is deliberately treated as "may be working"; so `ok = sent &&
!refused` was true and the operator was shown "APRS: report sent OK" for a login the
server had refused. That is v4.6.0's defining defect - every send reported successful
regardless of outcome - still live on the exact path every operator takes. The rebuild
narrowed it rather than closing it.

Both halves are fixed: the name and version stay separate tokens with whitespace
collapsed within each, and a refusal comment is classified as a refusal before the
logresp test. A socket test now replays the server's actual bytes.

Three smaller things from the same review:

The foreground service type goes back to dataSync. The previous commit chose location
to escape dataSync's six-hour cap, but a location-typed service is refused outright
unless a location runtime permission has already been granted, and the settings card
requests only notifications - so it would have failed silently for anyone who declined
location access. The cap that prompted the switch applies only when targetSdk is 35 or
higher, which this project does not declare. A test now reads the manifest and the
service source and fails if they disagree, which is the only way this class of defect
is visible from a JVM test.

The version string in the login was 4.5.4 while the app was 4.6.0. Now split into name
and version and corrected, though it is still hardcoded - core:data has no BuildConfig,
so passing it in properly is a separate change.

The passcode hint said "empty = auto-computed from callsign" in all five locales. The
app stopped doing that two commits ago; it now connects receive-only, and the hint says
so. It was the first thing an operator read next to the field, promising the behaviour
that was deliberately removed.

Not fixed, and known: the notification body is rebuilt from the previous cycle's state
so it can show a stale verdict, a deliberate receive-only choice is still styled as an
error, and no last-success timestamp exists - so an operator still cannot establish
whether their station has ever reached the network.
This commit is contained in:
mckero committed 2026-08-25 16:04:47 +00:00
1 parent 0208a577c4
commit 321cd8f2fa
13 files changed
+297 -56

No files matched your search

@@ -25,6 +25,7 @@ class AprsIsClient(
private val callsign: String,
private val ssid: String,
private val passcode: Int,
private val softwareName: String,
private val version: String,
private val filter: String = "",
private val timeoutSec: Int = 120
@@ -90,7 +91,7 @@ class AprsIsClient(
loginOutcome = refusal
throw IllegalArgumentException(refusal.detail)
}
val login = AprsLogin.line(callsign, ssid, passcode, version, filter)
val login = AprsLogin.line(callsign, ssid, passcode, softwareName, version, filter)
writer?.print(login)
writer?.print(CRLF)
writer?.flush()
@@ -142,7 +142,12 @@ class AprsReporter(
// Never derives one: a blank or wrong entry logs in receive-only rather than
// transmitting under a passcode the app invented for an unchecked licence.
passcode = AprsPasscode.loginValue(cfg.callsign, cfg.passcode),
version = "Look4Sat 4.5.4"
// Two fields, because APRS-IS wants `vers <name> <version>` as separate tokens.
// The version is hardcoded and drifts - it read 4.5.4 while the app was 4.6.0.
// core:data has no BuildConfig, so fixing that properly means passing it in from
// the app module; noting rather than doing it here to keep this change small.
softwareName = "Look4Sat",
version = "4.6.0"
).also { client = it }
if (!c.isConnected) c.connect()
onState(AprsState.Connected)
@@ -102,7 +102,8 @@ class AprsIsClientSocketTest {
callsign = "TEST",
ssid = "",
passcode = passcode,
version = "Look4Sat-test"
softwareName = "Look4Sat",
version = "test"
)
/**
@@ -140,7 +141,7 @@ class AprsIsClientSocketTest {
c.connect()
assertTrue(server.awaitLogin())
c.disconnect()
assertEquals("user TEST pass 12345 vers Look4Sat-test", server.loginLine)
assertEquals("user TEST pass 12345 vers Look4Sat test", server.loginLine)
}
}
@@ -213,6 +214,34 @@ class AprsIsClientSocketTest {
}
}
/**
* The failure a live server actually produced, and the one that mattered most.
*
* aprsc answers `# Invalid login: ...` and closes. That is a comment but not a logresp, so it
* was skipped as chatter, the login timed out into Unknown - treated as "may be working" - and
* every send afterwards reported success. Measured against euro.aprs2.net before the fix:
* loginOutcome=Unknown, isRefusedByServer=false, sendPacket=(true, "sent").
*/
@Test
fun `a refused login is not reported as a successful send`() {
FakeServer(loginResponse = "# Invalid login: bad software version").use { server ->
server.start()
val c = client(server.port)
// An outright refusal throws from connect(), which is the correct outcome.
val threw = runCatching { c.connect() }.exceptionOrNull()
assertTrue(server.awaitLogin())
assertFalse("a refused login must not read as verified", c.isVerified)
val sentOk = runCatching {
c.sendPacket("TEST>APRS,TCPIP*:=0000.00N/00000.00E>x")?.first
}.getOrNull()
assertTrue(
"the refusal must surface: threw=$threw sentOk=$sentOk",
threw != null || sentOk != true
)
c.disconnect()
}
}
/** Sending after the server has gone must report failure, not success. */
@Test
fun `a send after the server closes is reported as failed`() {