fix(aprs): the login line was malformed, and the refusal was invisible
An auditor ran the plan's own release gate against live APRS-IS servers. It failed at
the login step, on every server tried:
sent: user N0CALL pass -1 vers Look4Sat-4.5.4
got: # Invalid login: software name and version are not separated by a space
Reproduced on euro.aprs2.net and noam.aprs2.net, aprsc 2.1.21. `vers` takes TWO tokens,
a software name and a version. An earlier commit read the rule "softwarename must not
contain a space" as "the field must be one token" and hyphenated the space between them
- and the unit test asserted that as correct, so the mistake was frozen in place.
Worse than the malformed line was what happened next. `# Invalid login:` is a comment
but not a logresp, so parse skipped it as keepalive chatter; the login then timed out
into Unknown, which is deliberately treated as "may be working"; so `ok = sent &&
!refused` was true and the operator was shown "APRS: report sent OK" for a login the
server had refused. That is v4.6.0's defining defect - every send reported successful
regardless of outcome - still live on the exact path every operator takes. The rebuild
narrowed it rather than closing it.
Both halves are fixed: the name and version stay separate tokens with whitespace
collapsed within each, and a refusal comment is classified as a refusal before the
logresp test. A socket test now replays the server's actual bytes.
Three smaller things from the same review:
The foreground service type goes back to dataSync. The previous commit chose location
to escape dataSync's six-hour cap, but a location-typed service is refused outright
unless a location runtime permission has already been granted, and the settings card
requests only notifications - so it would have failed silently for anyone who declined
location access. The cap that prompted the switch applies only when targetSdk is 35 or
higher, which this project does not declare. A test now reads the manifest and the
service source and fails if they disagree, which is the only way this class of defect
is visible from a JVM test.
The version string in the login was 4.5.4 while the app was 4.6.0. Now split into name
and version and corrected, though it is still hardcoded - core:data has no BuildConfig,
so passing it in properly is a separate change.
The passcode hint said "empty = auto-computed from callsign" in all five locales. The
app stopped doing that two commits ago; it now connects receive-only, and the hint says
so. It was the first thing an operator read next to the field, promising the behaviour
that was deliberately removed.
Not fixed, and known: the notification body is rebuilt from the previous cycle's state
so it can show a stale verdict, a deliberate receive-only choice is still styled as an
error, and no last-success timestamp exists - so an operator still cannot establish
whether their station has ever reached the network.
This commit is contained in:
1 parent
0208a577c4
commit
321cd8f2fa
13 files changed
+297
-56
No files matched your search
@@ -25,6 +25,7 @@ class AprsIsClient(
|
||||
private val callsign: String,
|
||||
private val ssid: String,
|
||||
private val passcode: Int,
|
||||
private val softwareName: String,
|
||||
private val version: String,
|
||||
private val filter: String = "",
|
||||
private val timeoutSec: Int = 120
|
||||
@@ -90,7 +91,7 @@ class AprsIsClient(
|
||||
loginOutcome = refusal
|
||||
throw IllegalArgumentException(refusal.detail)
|
||||
}
|
||||
val login = AprsLogin.line(callsign, ssid, passcode, version, filter)
|
||||
val login = AprsLogin.line(callsign, ssid, passcode, softwareName, version, filter)
|
||||
writer?.print(login)
|
||||
writer?.print(CRLF)
|
||||
writer?.flush()
|
||||
|
||||
@@ -142,7 +142,12 @@ class AprsReporter(
|
||||
// Never derives one: a blank or wrong entry logs in receive-only rather than
|
||||
// transmitting under a passcode the app invented for an unchecked licence.
|
||||
passcode = AprsPasscode.loginValue(cfg.callsign, cfg.passcode),
|
||||
version = "Look4Sat 4.5.4"
|
||||
// Two fields, because APRS-IS wants `vers <name> <version>` as separate tokens.
|
||||
// The version is hardcoded and drifts - it read 4.5.4 while the app was 4.6.0.
|
||||
// core:data has no BuildConfig, so fixing that properly means passing it in from
|
||||
// the app module; noting rather than doing it here to keep this change small.
|
||||
softwareName = "Look4Sat",
|
||||
version = "4.6.0"
|
||||
).also { client = it }
|
||||
if (!c.isConnected) c.connect()
|
||||
onState(AprsState.Connected)
|
||||
|
||||
+31
-2
@@ -102,7 +102,8 @@ class AprsIsClientSocketTest {
|
||||
callsign = "TEST",
|
||||
ssid = "",
|
||||
passcode = passcode,
|
||||
version = "Look4Sat-test"
|
||||
softwareName = "Look4Sat",
|
||||
version = "test"
|
||||
)
|
||||
|
||||
/**
|
||||
@@ -140,7 +141,7 @@ class AprsIsClientSocketTest {
|
||||
c.connect()
|
||||
assertTrue(server.awaitLogin())
|
||||
c.disconnect()
|
||||
assertEquals("user TEST pass 12345 vers Look4Sat-test", server.loginLine)
|
||||
assertEquals("user TEST pass 12345 vers Look4Sat test", server.loginLine)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -213,6 +214,34 @@ class AprsIsClientSocketTest {
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* The failure a live server actually produced, and the one that mattered most.
|
||||
*
|
||||
* aprsc answers `# Invalid login: ...` and closes. That is a comment but not a logresp, so it
|
||||
* was skipped as chatter, the login timed out into Unknown - treated as "may be working" - and
|
||||
* every send afterwards reported success. Measured against euro.aprs2.net before the fix:
|
||||
* loginOutcome=Unknown, isRefusedByServer=false, sendPacket=(true, "sent").
|
||||
*/
|
||||
@Test
|
||||
fun `a refused login is not reported as a successful send`() {
|
||||
FakeServer(loginResponse = "# Invalid login: bad software version").use { server ->
|
||||
server.start()
|
||||
val c = client(server.port)
|
||||
// An outright refusal throws from connect(), which is the correct outcome.
|
||||
val threw = runCatching { c.connect() }.exceptionOrNull()
|
||||
assertTrue(server.awaitLogin())
|
||||
assertFalse("a refused login must not read as verified", c.isVerified)
|
||||
val sentOk = runCatching {
|
||||
c.sendPacket("TEST>APRS,TCPIP*:=0000.00N/00000.00E>x")?.first
|
||||
}.getOrNull()
|
||||
assertTrue(
|
||||
"the refusal must surface: threw=$threw sentOk=$sentOk",
|
||||
threw != null || sentOk != true
|
||||
)
|
||||
c.disconnect()
|
||||
}
|
||||
}
|
||||
|
||||
/** Sending after the server has gone must report failure, not success. */
|
||||
@Test
|
||||
fun `a send after the server closes is reported as failed`() {
|
||||
|
||||
Reference in new issue
Block a user