* Expand coverage for relay, identity, and location flows
* Fix macOS SwiftPM CI failures
---------
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
Added secureClear() calls for all 6 DH operations in NoiseProtocol.swift
to properly clear sensitive shared secrets from memory after use:
- writeMessage(): .es initiator/responder, .se initiator/responder
- performDHOperation(): .ee and .ss operations
This fixes a forward secrecy vulnerability where shared secrets could
persist in memory after handshake completion.
Also adds:
- TrackingMockKeychain to count secureClear calls in tests
- 3 new tests verifying secureClear is called during handshake
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix fragmentation + BLE long-write + padding
- Accumulate CBATTRequest long writes by offset and decode once per central
- Decode original packet after fragment reassembly (preserve flags/compression)
- Switch MessagePadding to strict PKCS#7 and validate before unpadding
- Make BinaryProtocol.decode robust: try raw first, then unpad fallback
- Unpad frames before BLE notify; fragment when exceeding centrals' max update length
- Skip notify path when max update length < 21 bytes (protocol minimum)
Verified large PMs and announces route without decode errors and peers show reliably.
* Tests: fix weak delegate lifetime, legacy constants, and unused vars; fragment unpadded frames
- BLEServiceTests: hold strong reference to MockBitchatDelegate
- IntegrationTests: fix inline comment braces; replace removed types with test-safe values; use numeric 0x06 for legacy handshake resp checks
- BinaryProtocolTests: remove unused minResult variable
- BLEService: fragment the unpadded frame so fragments are efficient
* tests: add Noise rehandshake recovery test; document in-memory test bus and autoFlood; stabilize large-network broadcast
* tests: align suite with current behavior (compression, padding, routing, nonce); deflake and stabilize
---------
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
- Remove unused migrateSession() functions (never called in production)
- NoiseSession.migrateSession() - 13 lines
- NoiseEncryptionService.migratePeerSession() - 18 lines
- Test for migration functionality - 17 lines
- Remove unnecessary keychain cleanup code (no legacy data existed)
- cleanupLegacyKeychainItems() - 62 lines
- aggressiveCleanupLegacyItems() - 72 lines
- resetCleanupFlag() - 4 lines
- Simplified panic mode to just use deleteAllKeychainData()
Total removed: 194 lines of dead/unnecessary code
Analysis revealed:
- KeychainManager introduced July 5, 2025
- Cleanup code added July 15, 2025 (10 days later)
- Legacy service names were never used in production
- Migration functions were incomplete implementation never called
- Peer ID rotation remains active (not legacy)
Previously, NoiseSessionManager would reject handshake initiations if it had an existing established session. This caused deadlocks when one peer cleared their session (e.g., after decryption failure) but the other peer rejected the new handshake.
Changes:
- NoiseSessionManager now always accepts handshake initiations, clearing any existing session
- Added comprehensive tests for handshake recovery scenarios
- Tests verify proper re-establishment after decryption failures and nonce desynchronization
- Add test for peer restart detection and session recovery
- Add test for nonce desynchronization detection
- Add test for concurrent encryption thread safety
- Add test for session stale detection
- Add test for handshake after decryption failure
- Add integration test for peer presence tracking and reconnection
- Add integration test for encrypted messages after peer restart
These tests ensure:
- Sessions properly recover when a peer restarts
- Nonce desynchronization is detected correctly
- Encryption operations are thread-safe under concurrent load
- Identity announcements are sent on reconnection after silence
- Encrypted messages work after session re-establishment
- Fixed mock service property overrides to match base class properties
- Added missing CryptoKit imports where needed
- Fixed immutable property assignments by creating new instances
- Replaced XCTAssertThrows with XCTAssertThrowsError
- Fixed DeliveryAck serialization method names (serialize -> encode)
- Fixed unused variable warnings
- Ensured all BitchatPacket modifications create new instances
- Fixed BitchatMessage property mutations by creating new instances
All test targets now build successfully for both iOS and macOS platforms.
- Created test utilities and helpers for common test operations
- Implemented Binary Protocol tests covering encoding/decoding, compression, and padding
- Added Noise Protocol tests for handshake, encryption, and session management
- Created Public Chat E2E tests for broadcasting, routing, TTL, and mesh topologies
- Implemented Private Chat E2E tests for direct messaging, delivery ACKs, and retry logic
- Added Integration tests for multi-peer scenarios, network resilience, and mixed traffic patterns
- Created mock implementations for BluetoothMeshService and NoiseSession
Test coverage includes:
- Protocol layer (binary encoding, message serialization)
- Security layer (Noise handshake, encryption/decryption)
- Application layer (public/private messaging, delivery tracking)
- Network scenarios (mesh topology, partitions, churn)
- Performance and stress testing