Compare commits

..
Author SHA1 Message Date
97fc21c23f Add localizable strings in show commands view (#828)
* Add localizable strings in show commands view n refactor code to remove duplicate string declarations.

* Modify struct to enum in separate file to Models/CommandsInfo.

* Add corrections code in refactory and enum.

* Correct code in command enum and ContentView.

* Dedicated CommandSuggestionsView to extract code

* Simplify CommandInfo + minor optimization

* Fix preview

---------

Co-authored-by: islam <2553451+qalandarov@users.noreply.github.com>
2025-10-29 22:09:43 +00:00
Jithin RenjiandGitHub 79bd4af912 Remove redundant conditional compilation directive (#863) 2025-10-29 16:02:34 +00:00
96c78ef5a2 Fix verification persistence on iOS when app backgrounds (#822)
* Fix verification persistence on iOS when app backgrounds (#785)

Verification status was not being saved when the iOS app entered background
state, causing verified contacts to lose their verification status after the
app was closed. This happened because iOS can terminate backgrounded apps
without calling applicationWillTerminate.

Changes:
- Add saveIdentityState() method to force-save identity data without stopping services
- Call saveIdentityState() when iOS app enters background state
- Refactor applicationWillTerminate() to use new method
- Fix selector name typo (appWillTerminate -> applicationWillTerminate)

The verification data is now properly persisted to encrypted keychain storage
whenever the app backgrounds, ensuring verification status persists across
app launches.

Fixes #785

* Save identity state during verification events

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-28 19:19:00 +01:00
01256f3041 Add source-based routing support (#862)
* Add source-based routing support

* include neighbors in ANNOUNCE

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
Co-authored-by: callebtc <93376500+callebtc@users.noreply.github.com>
2025-10-28 12:38:44 +01:00
2edbe2bbbd Extract public message pipeline from ChatViewModel (#870)
* Extract public timeline helpers and rate limiter

* Extract public message pipeline

* Fix Swift concurrency warnings

* Incorporate public chat review feedback

* Tighten nostr key removal loop

* Address review feedback

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-28 12:10:09 +01:00
jackandGitHub a91978c10e Extract public timeline helpers and rate limiter (#869) 2025-10-27 14:13:57 +01:00
14c4e586fc Improve background BLE stability and nearby alerts (#864)
* Harden background BLE restoration and notifications

* Guard BLE restoration paths to iOS

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-23 19:54:06 +02:00
83779240ae Prevent mesh self-sync duplicates (#856)
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-23 10:41:28 +02:00
5034732515 Simplify validation, compression heuristics, and notification scheduling (#841)
* Simplify validation, compression heuristics, and notification scheduling

* Consolidate notification logic and add InputValidator monitoring

Follow-up improvements to address PR feedback:

1. Consolidate notification functions
   - Add interruptionLevel parameter to sendLocalNotification
   - Refactor sendNetworkAvailableNotification to use consolidated function
   - Removes 12 lines of duplicate code

2. Add monitoring to InputValidator
   - Log control character rejections for production monitoring
   - Privacy-preserving: logs length + count, not actual content
   - Uses .security category for proper log routing

3. Add comprehensive InputValidator tests
   - 28 test cases covering validation, control characters, unicode, edge cases
   - Ensures behavioral changes are well-tested and documented

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-22 12:33:37 +02:00
b6ce4fae43 Add type-aware REQUEST_SYNC sync rounds (#853)
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-22 12:24:29 +02:00
98fa02cc16 Prevent duplicate action emote echoes (#852)
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-21 13:47:24 +02:00
0812cafd55 Improve mesh media throughput (#845)
* Improve mesh media throughput

* Reserve media slots atomically

* Prioritize small fragment trains

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-21 12:53:54 +02:00
IslamandGitHub 450955525c No fallback mime-type + remove dead code (#844) 2025-10-20 01:50:33 +02:00
IslamandGitHub 475bc70c71 Extract MimeTypes into a separate file + add tests (#843) 2025-10-20 01:21:23 +02:00
IslamandGitHub af6136c01c Minor cleanup (#842) 2025-10-20 01:11:44 +02:00
b839ce5f6c PeerID 31/n: Remove String interop to be explicit (#840)
* PeerID 28/n: `ChatViewModel.getShortIDForNoiseKey`

* PeerID 29/n: `BLEService` + remove dupe funcs from #823

* `handleFileTransfer` to use PeerID

* `sendMessage` and `sendPrivateMessage`

* PeerID 30/n: Update some leftovers

* `lowercased()` inside PeerID for normalization

* PeerID 31/n: Remove String interop to be explicit

* MockBLEService: Remove direct target delivery

This causes a delivery even if the sender and receiver are not connected

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-19 20:50:44 +02:00
0776c9813c PeerID 30/n: Update some leftovers + case normalization (#839)
* PeerID 28/n: `ChatViewModel.getShortIDForNoiseKey`

* PeerID 29/n: `BLEService` + remove dupe funcs from #823

* `handleFileTransfer` to use PeerID

* `sendMessage` and `sendPrivateMessage`

* PeerID 30/n: Update some leftovers

* `lowercased()` inside PeerID for normalization

---------

Co-authored-by: jack <212554440+jackjackbits@users.noreply.github.com>
2025-10-19 20:40:45 +02:00
0dd999af6b PeerID 29/n: BLEService + remove dupe funcs from #823 (#838)
* PeerID 28/n: `ChatViewModel.getShortIDForNoiseKey`

* PeerID 29/n: `BLEService` + remove dupe funcs from #823

* `handleFileTransfer` to use PeerID

* `sendMessage` and `sendPrivateMessage`

---------

Co-authored-by: jack <212554440+jackjackbits@users.noreply.github.com>
2025-10-19 20:35:41 +02:00
IslamandGitHub c3a1af7023 PeerID 28/n: ChatViewModel.getShortIDForNoiseKey (#836) 2025-10-19 20:30:10 +02:00
880813f256 Fix GeoRelay prefetch isolation (#837)
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-19 17:24:17 +01:00
64fb634166 Fix camera icon in DM sheets using parent-child presentation pattern (#834)
Implements mutually-exclusive image picker presentations to fix the error
"Currently, only presenting a single sheet is supported" when tapping
camera in a DM.

Solution:
- ContentView: Only presents image picker when NOT in a sheet
  (when showSidebar=false and no private chat active)
- peopleSheetView: Only presents image picker when IN a sheet
  (when showSidebar=true or private chat active)

This ensures only ONE presentation is active at any time, preventing
conflicts. Uses fullScreenCover on iOS to allow presentation over sheets.

Addresses feedback from @qalandarov in PR #834 with minimal approach.

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-19 15:23:05 +02:00
IslamandGitHub 13b19fb8eb PeerID 27/n: ContentView and MeshPeerList (#835) 2025-10-19 14:42:50 +02:00
IslamandGitHub d4967ae9c3 PeerID 26/n: FingerprintView (#833) 2025-10-19 14:36:06 +02:00
IslamandGitHub 435744a977 PeerID 25/n: ReadReceipt (#832) 2025-10-19 14:30:27 +02:00
IslamandGitHub 70caa9e24a PeerID 24/n: Nostr Transport and Embedding (#830) 2025-10-19 13:54:32 +02:00
5084f87fe5 Improve geohash media gating and relay refresh (#831)
Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-19 13:48:33 +02:00
lollerfirstandGitHub 8f56e4f0fb no longer commit into main. open PRs instead (#829) 2025-10-19 12:23:11 +02:00
aca44f9f55 Extract sanitization logic into an extensions + add tests (#827)
Co-authored-by: jack <212554440+jackjackbits@users.noreply.github.com>
2025-10-19 11:34:21 +02:00
IslamandGitHub 3f00cf9467 Remove presentationDetents as default is already large (#826) 2025-10-19 11:16:57 +02:00
40e54a5120 Add voice notes and images over BLE mesh (audio + image only) (#823)
* Add BLE file transfer support and media UX

* Gracefully disable mac attachment pickers in sandbox

* Tighten spacing above media message bubbles

* Reduce vertical padding between chat rows

* Restore iOS file importer for attachments

* Copy imported files before sending to preserve access

* Allow file transfers from connected but unverified peers

* Raise BLE notification buffer cap for large file transfers

* Revert "Raise BLE notification buffer cap for large file transfers"

This reverts commit b624523af843475db84e4a846db8dcbe824ae408.

* Add guard to drop oversized BLE notification assemblies

* Let BLE assembler accept large frames up to hard cap

* Add detailed logging for BLE fragment assembly

* Log incomplete BLE frames for debugging

* Stop dropping partial BLE frames while assembling notifications

* Fix compressed BLE file transfers

* Enable mac attachment importers

* Allow mac microphone access

* Permit mac media library access

* Describe microphone usage

* Harden attachment transfer bookkeeping

* Display recording milliseconds

* Restore mac photo picker access

* Use Photos picker on mac

* Allow long-press reblur on images

* Reblur images via swipe

* Lowercase image preview buttons

* Keep processed images for outgoing messages

* Use save panel for mac image export

* Fix image attachment detection

* Allow user-selected write access

* Align mac image JPEG encoding

* Revert unsupported JPEG option

* Strip metadata in mac image encoding

* Normalize mac JPEG color space

* Target image byte size across platforms

* Fix CFMutableData handling

* Preserve packet version when signing

* Use unique transfer identifiers

* Stub file transfer methods in mock

* Stub file transfer methods in mock

* Hide absolute paths in media messages

* Resolve image/voice path handling

* Fix cleanupLocalFile lookup

* Restore BLE broadcasts when notify buffer is saturated

* Guard peer map reads on BLE message path

* Drop attachment ceilings to 1 MiB and bump release version

* Reset BLE assembler on stalled fragment trains

* Fix binary protocol test fixtures

* Fix critical issues from PR #681 review

Critical fixes:
- BinaryProtocol: Return nil for unknown versions (prevents buffer underflows)
- Add BinaryProtocol.Offsets struct to centralize magic numbers
- Replace magic offset calculations with named constants

Security/Privacy:
- FileAttachmentView: Use url.lastPathComponent instead of url.path
  (prevents exposing full system paths)

Documentation:
- Fix compression algorithm documentation (zlib, not LZ4)

All tests passing.

* Fix UI freeze when receiving voice notes

Problem: AVAudioPlayer initialization in VoiceNotePlaybackController.init()
was running synchronously on main thread during view creation, blocking
UI for 50-200ms per voice note.

Solution:
- Remove eager preparePlayer() call from init
- Load duration asynchronously on background queue
- Player is only prepared when playback is actually requested via ensurePlayerReady()

This prevents UI freezes when voice notes appear in the chat.

* Fix memory leaks and post-playback freeze

Fixes:
1. Post-playback freeze: audioPlayerDidFinishPlaying now dispatches to main
   thread before updating @Published properties (Swift concurrency violation)

2. Unbounded waveform cache: Implement LRU eviction with 20-entry limit
   - Track last access time for each cached waveform
   - Evict oldest entry when cache is full
   - Prevents unlimited memory growth as voice notes accumulate

3. Audio buffer memory leaks: Wrap computeWaveform in autoreleasepool
   - AVAudioPCMBuffer allocations are autoreleased
   - Pool ensures buffers are freed promptly

4. Image processing memory: Add autoreleasepool around compression loops
   - Each jpegData() call creates temporary objects
   - Inner pool per iteration prevents memory spikes during quality search

Memory should now remain stable during extended use.

* Eliminate disk I/O from SwiftUI view rendering path

Critical performance fix for UI freezes when receiving media:

Problem: mediaAttachment(for:) was called during every SwiftUI render,
performing synchronous disk I/O on main thread:
- FileManager.fileExists() called 2-6x per message (checking subdirs)
- applicationFilesDirectory() creating directories on every call
- With multiple media messages, this meant 20-100+ disk ops per render

Solution:
1. Remove fileExists checks - construct URLs directly
   - Files are validated during playback/display (fail gracefully if missing)
   - Sender determines subdirectory (outgoing vs incoming)

2. Cache applicationFilesDirectory() result
   - Static cache prevents repeated FileManager.url() calls
   - Directory created only once

3. Remove redundant playback.replaceURL() in VoiceNoteView.onAppear
   - Controller already initialized with correct URL

This eliminates ALL disk I/O from the view rendering hot path.

* Cache Nostr identity derivation to prevent crypto during view rendering

Critical performance fix:

Problem: formatMessageHeader() called deriveIdentity(forGeohash:) during
every SwiftUI render for every media message. Each call performed:
- Keychain I/O (getOrCreateDeviceSeed)
- HMAC-SHA256 computation
- Up to 10 secp256k1 key validations (elliptic curve crypto)

With multiple media messages, this resulted in 100s of milliseconds of
blocking crypto on main thread per render cycle.

Solution: Add thread-safe cache for derived identities
- Check cache before expensive crypto operations
- NSLock protects concurrent access
- Identity is deterministic per geohash, so caching is safe

This eliminates crypto from the hot rendering path.

* Cache geohash identity in ChatViewModel to prevent crypto during rendering

Additional optimization for location channels (voice notes are mesh-only,
but this helps with text message rendering in geohash channels):

- Add cachedGeohashIdentity to avoid deriveIdentity calls during rendering
- Check cache before falling back to crypto derivation
- Reduces main thread crypto work in location channels

* Make voice note loading completely lazy with deferred initialization

Aggressive performance optimization to prevent UI freezes:

Problem: Even with async loading, creating 10+ VoiceNotePlaybackController
instances simultaneously (when scrolling past multiple voice notes) spawned
20+ concurrent background tasks, potentially starving main thread.

Solution - Ultra-lazy loading:
1. VoiceNotePlaybackController.init() now does ZERO work
   - No duration loading
   - No player creation
   - Instant initialization

2. Duration loaded on-demand via public loadDuration() method
   - Called from VoiceNoteView.onAppear after 150ms delay
   - Reduced priority: .utility instead of .userInitiated
   - Guard prevents duplicate loading

3. Waveform loading also deferred 150ms
   - Gives UI time to settle after message appears
   - Prevents task storms when multiple voice notes appear

This spreads the work over time instead of all at once.

* Ensure /clear and panic triple-tap delete media files

Fix: /clear command and panicClearAllData() now properly delete media files

1. /clear (triple-tap on chat):
   - Deletes outgoing media (voice notes, images, files)
   - Conservative: only our sent media, preserves received media
   - Runs in background to avoid UI freeze

2. panicClearAllData() (triple-tap on bitchat/ header):
   - Deletes ALL media files (incoming + outgoing)
   - Removes entire files directory and recreates structure
   - Ensures complete data wipe for emergency scenarios

Both operations run async on .utility queue to prevent blocking UI.

* Fix infinite render loop and apply all security fixes

CRITICAL BUG FIX - Infinite Render Loop:

Root Cause: Duplicate view identity in ContentView.swift:368
  ForEach(messageItems) { item in  // Already uses item.id via Identifiable
      messageRow(...)
          .id(item.id)  //  REDUNDANT modifier caused identity re-evaluation loop
  }

When @Published properties updated, SwiftUI re-evaluated .id() → appeared as
'new' identity → triggered re-render → infinite loop. Caused UI freezes,
keyboard failures, and 100% CPU usage.

Fix: Remove redundant .id() modifier - ForEach already has stable identity.

PERFORMANCE FIXES:

1. Waveform Cache Deadlock (Waveform.swift)
   - Removed nested queue.async(barrier) on cache hits
   - Was causing task saturation and potential deadlocks

2. Async Send Pattern (ContentView.swift)
   - Clear input immediately, defer actual send to next runloop
   - Prevents blocking current event handler

3. Proper Swift Concurrency (VoiceNoteView.swift)
   - Switch from .onAppear + DispatchQueue to .task
   - Cleaner async/await pattern for loading

4. Remove Redundant objectWillChange (ChatViewModel.swift)
   - @Published already triggers updates automatically
   - Explicit send() was causing double update cycles

SECURITY FIXES (C1-C5, H1-H2):

C1. Path Traversal Protection (BLEService.swift)
    - Unicode normalization, null byte removal
    - Replace ALL path separators, reject dotfiles
    - Validate paths don't escape directory

C2. Integer Overflow (BitchatFilePacket.swift)
    - Use UInt64 for TLV parsing, safe Int conversion

C3. MIME Validation (BLEService.swift)
    - Whitelist: JPEG, PNG, GIF, WebP, M4A, MP3, WAV, OGG, PDF
    - Magic byte validation for all types
    - Lenient on M4A (platform variations)

C4. Compression Bomb (BinaryProtocol.swift)
    - Ratio validation <= 50,000:1
    - Defense-in-depth with 1MB size cap

C5. TOCTOU Race (ChatViewModel.swift)
    - Direct removeItem without fileExists check

H1. File Size Validation (ChatViewModel, ImageUtils)
    - Check attributes BEFORE Data(contentsOf:)
    - Prevents memory exhaustion

H2. Metadata Stripping (ImageUtils.swift)
    - Remove ALL metadata keys from JPEG encoding
    - Only compression quality set
    - Protects GPS/EXIF/device info privacy

RESULT:
 No render loops
 Works with Xcode debugger
 Voice notes display properly
 All security vulnerabilities fixed
 164 tests passing

Production ready.

* Complete all translations to 100% and fix auto-extraction

- Mark non-localizable strings with Text(verbatim:) to prevent extraction
- Update UI strings to lowercase per style guide (open, save, close, recording)
- Add complete translations for all 29 languages (194/194 strings at 100%)
- Remove empty/duplicate entries (@, bitchat/, Open, Recording %@)
- Add proper localization comments for all user-facing strings

* macOS: Focus message input on launch instead of nickname field

* Remove debug print statements from sendMessage

* Optimize voice note codec to 16 kHz / 20 kbps for smaller file sizes

- Reduce sample rate from 44.1 kHz to 16 kHz (telephony standard)
- Lower bitrate from 32 kbps to 20 kbps
- Results in ~37% file size reduction (~150 KB/min vs 240 KB/min)
- Increases max voice note length from 4.4 to 7 minutes over 1 MiB BLE limit
- Maintains excellent voice quality using native AAC-LC codec

* Fix critical security issues in fragment reassembly and file cleanup

Fragment Reassembly Race Condition (CRITICAL):
- Wrap all incomingFragments/fragmentMetadata access in collectionsQueue.sync
- Prevents concurrent modification crashes from multi-threaded access
- Minimizes lock contention by doing heavy work (reassembly/decode) outside locks
- Add upper bound check: reject fragments with total > 10,000 (DoS prevention)
- Add cumulative size validation before storing fragments (memory DoS prevention)

File Cleanup Path Traversal (CRITICAL):
- Use NSString.lastPathComponent to extract filename safely
- Prevents directory traversal attacks via malicious filenames
- Add path prefix validation before file deletion
- Now checks both incoming and outgoing directories (fixes disk leak)

Additional Protections:
- Fragment assemblies now limited by both count (128) and cumulative bytes (1MB)
- Explicit checks for "." and ".." filenames in cleanup
- Defense-in-depth: multiple validation layers

* Fix post-rebase compilation errors

- Remove duplicate NostrIdentityBridge and Bech32 from NostrIdentity.swift (now in separate files)
- Add caching to NostrIdentityBridge.deriveIdentity() for performance
- Remove duplicate NotificationStreamAssembler from BLEService.swift
- Remove duplicate function declarations in BLEService.swift
- Remove duplicate DeliveryStatusView and PaymentChipView from ContentView.swift
- Fix PeerID type conversions throughout (use .id for String, PeerID(str:) for wrapping)
- Update ContentView body to use main's simple VStack structure
- Fix NostrIdentityBridge instance method calls
- Remove privateChatView (replaced with sheet-based UI in main)

Build and tests passing (137/139 tests pass).

* Fix remaining compilation issues after rebase

- Fix PhotosUI import order (must be after platform imports)
- Fix Data.WritingOptions.atomic reference
- Add identity derivation caching to NostrIdentityBridge
- Fix all remaining PeerID type conversions in ChatViewModel
- Fix ContentView body structure to use main's VStack layout
- Fix PaymentChipView API usage (now uses PaymentType enum)

Build and tests now passing.

* Add proper availability checks for PhotosPickerItem

PhotosPickerItem requires iOS 16+ / macOS 13+ but canImport(PhotosUI)
succeeds on older macOS versions. Add compiler version check to ensure
PhotosPicker code only compiles when actually available.

This fixes CI build failures on older macOS environments.

* Limit PhotosPicker to iOS only to fix CI

PhotosPickerItem has SDK availability issues on macOS in CI.
Change PhotosPicker from canImport(PhotosUI) to os(iOS) only.

macOS users can still import images via file importer (.fileImporter).
This is actually cleaner as macOS file picker is more familiar to users.

Fixes CI build failures.

* Convert new tests to Swift Testing

* Fix compilation issue

* Add the missing `fileTransfer` case

* Explicitly list all Enum cases to get compile-time errors

* Revive lost `NotificationStreamAssembler` changes

* Allow file fragments to account for protocol overhead

* Simplify PR: Focus on audio+image, fix EXIF stripping, remove file transfers

- Fix critical EXIF privacy issue in iOS image processing
  - Both iOS and macOS now use CGImageDestination for metadata stripping
  - Shared encodeJPEG function ensures no GPS, camera, or metadata leaks

- Remove file transfer functionality to simplify PR scope
  - Deleted FileAttachmentView
  - Removed sendFileAttachment from ChatViewModel
  - Removed file picker UI from ContentView
  - Simplified attachment dialog to image only (iOS) or voice only

- Keep focused media features:
  - Voice recording and playback
  - Image sending with progressive reveal
  - Binary protocol for media transfer

* Improve camera UX: Direct camera access with camera icon

- Change paperclip icon to camera icon for clearer affordance
- Open camera directly on tap (no confirmation dialog)
- Add CameraPickerView wrapper for UIImagePickerController
- Remove PhotosPicker in favor of direct camera access
- Images still processed through ImageUtils with EXIF stripping
- Accessibility: Added 'Take photo' label

* Full-screen camera with photo library option

- Change to fullScreenCover for immersive camera experience
- Add action sheet with 'Take Photo' and 'Choose from Library' options
- Renamed ImagePickerView to support both camera and library sources
- Both options open full-screen for better UX
- Updated accessibility label to 'Add photo' (more accurate)

* Fix camera white bars with overFullScreen presentation

- Changed modalPresentationStyle from .fullScreen to .overFullScreen
- This should eliminate white bars at top/bottom on notched devices
- Explicitly set showsCameraControls and cameraOverlayView for camera mode

* Gesture-based photo access: Tap for library, long-press for camera

UX improvements:
- Tap camera icon → Photo library (common use case)
- Long press camera icon (0.3s) → Direct camera (quick photos)
- Removed action sheet entirely for cleaner flow
- Power users can long-press for instant camera access

This is more discoverable and eliminates an extra step in the UI.

* Simplify camera presentation to reduce frame errors

- Changed back to standard .fullScreen presentation
- Removed overFullScreen which was causing frame dimension errors
- Let iOS handle safe areas automatically (white bars are intentional)
- Reduces gesture gate timeout warnings

Note: White bars on notched devices are iOS default behavior for
UIImagePickerController. This respects safe areas for status bar
and home indicator. True edge-to-edge would require custom AVFoundation
camera implementation.

* Force dark mode on camera/picker for black safe area bars

- Set overrideUserInterfaceStyle = .dark on UIImagePickerController
- Changes white bars to black (much better looking)
- Camera controls and photo library also appear in dark mode
- Consistent dark appearance regardless of system settings

* Optimize sheet presentation for camera UI

- Force .large detent for maximum height
- Hide drag indicator for cleaner look
- Use ignoresSafeArea to give camera full space
- Should show complete flash button and controls

* Fix P1: Add DoS protections to PeerID fragment handler

Critical security fix addressing Codex review feedback:

The PeerID overload of handleFragment (which is actually called by
CoreBluetooth) was missing key safety checks that existed in the
String overload:

1. Added total <= 10000 check to prevent unbounded fragment counts
2. Added cumulative size check against FileTransferLimits before
   storing each fragment
3. Prevents memory exhaustion DoS attacks via malicious fragment streams

This ensures the actually-used code path has proper bounds checking.

* Fix decompression size limit to support max-sized file transfers

Root cause: BinaryProtocol.decode() was rejecting decompressed payloads
larger than maxPayloadBytes (1 MB), but TLV-encoded file transfers are
slightly larger due to metadata overhead.

Fixes:
- Changed decompression limit from maxPayloadBytes to maxFramedFileBytes
- This accounts for TLV overhead (~50 bytes) + binary protocol headers
- Now allows ~1.12 MB decompressed payloads (1 MB + overhead budget)

The failing test was:
- Creating 1 MB file content
- TLV encoding adds ~50 bytes (1,048,627 total)
- Compression reduces to ~1,084 bytes (highly repetitive data)
- During decode, decompression was rejecting the 1,048,627 byte output
- Now correctly allows it since 1,048,627 < 1,179,760 (maxFramedFileBytes)

All 154 tests now pass including 'Max-sized file transfer survives reassembly'

* Fix critical thread-safety crash in PeerID fragment handler

CRITICAL: The PeerID version of _handleFragment was accessing
incomingFragments dictionary without collectionsQueue synchronization,
causing crashes when multiple BLE threads processed fragments concurrently.

Crash stack trace pointed to line 3431 (dictionary subscript) with:
'doesNotRecognizeSelector' - classic concurrent mutation crash.

Fix:
- Wrapped ALL incomingFragments/fragmentMetadata access in
  collectionsQueue.sync(flags: .barrier)
- Matches the thread-safe pattern used in String version
- Separate cleanup into its own barrier block after reassembly
- Prevents concurrent dictionary mutations from multiple BLE threads

This is the same pattern as the String version (line 1128) which didn't crash.

* Remove Localizable.xcstrings formatting noise

The Localizable.xcstrings file had massive formatting-only changes
(spacing: 'key' vs 'key :') that added 50K+ lines to the PR diff.

This was just Xcode reformatting with no actual string changes.

Reverted to main's version to keep PR focused on actual code changes.

* Add macOS photo picker support

- Added MacImagePickerView with NSOpenPanel for macOS
- macOS shows photo.circle.fill icon (no camera hardware)
- Opens native file picker for images (.png, .jpeg, .heic)
- Images processed through ImageUtils with EXIF stripping
- Simple sheet with Select/Cancel buttons

Cross-platform photo sharing now works:
- iOS: Tap for library, long-press for camera
- macOS: Tap for file picker

* Add Localizable strings for camera and voice features

Xcode auto-generated localization strings for new UI elements:
- Camera/photo picker labels
- Voice recording UI strings
- Media attachment descriptions

These are legitimate new strings needed for the audio+image feature,
not just formatting changes.

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
Co-authored-by: islam <2553451+qalandarov@users.noreply.github.com>
2025-10-18 20:55:33 +02:00
7040d9ecb0 Add plus-minus feature to location notes (± 1 grid) (#821)
Expands location notes coverage to include 8 neighboring geohash cells,
creating a 3×3 grid around the user's current building-level location.

Changes:
- Add Geohash.neighbors() method to calculate 8 surrounding cells
- Update LocationNotesManager to subscribe to center + neighbors (9 cells total)
- Add NostrFilter.geohashNotes([String]) overload for multi-cell subscriptions
- Display '± 1' indicator in LocationNotesView header

Coverage:
- Single cell: ~38m × 19m
- 3×3 grid: ~114m × 57m total area
- Better discovery of nearby activity

Behavior:
- Subscribe: Fetches notes from all 9 cells (single efficient subscription)
- Post: Still uses center geohash only (correct privacy-preserving behavior)
- UI: Shows 'geohash ± 1' to indicate expanded coverage

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-18 12:44:06 +02:00
88bafb41cc Remove LocationNotesCounter for privacy-first approach (#820)
Simplifies geonotes architecture by eliminating all background subscriptions:

- Delete LocationNotesCounter.swift (104 lines) and related tests (58 lines)
- Remove background subscription system entirely
- Icon is now constant darker orange (indicates availability, not state)
- Subscription ONLY happens when user explicitly opens the sheet
- Total: ~220 lines of code removed

Privacy Benefits:
- Zero network traffic until user action
- No location leaking to relays via background polling
- User must explicitly opt-in to discover notes

The icon (note.text in orange) simply indicates the feature is available
when location permission is granted. Notes are only fetched when the
sheet is opened, prioritizing privacy over convenience.

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-18 12:06:31 +02:00
jackandGitHub fb43a8b0f5 Reuse cached mention regex in parseMentions (#812) 2025-10-17 23:02:58 +02:00
jackandGitHub eb35608fa1 Remove unused helpers and add cross-platform logging fallbacks (#811) 2025-10-17 22:58:56 +02:00
RedThoroughbredandGitHub b81ae0b4c0 fix: improve Xcode detection in Justfile (#814)
- Add check for full Xcode vs command line tools only
- Provide clearer error messages with setup instructions
- Verify Xcode is installed and properly configured
- Add better validation for development environment

Fixes issue where 'just run' fails with cryptic error when only
command line tools are installed. Now gives clear guidance on
installing full Xcode and configuring xcode-select properly.

Resolves #760
2025-10-17 21:37:51 +02:00
jackandGitHub b6d42261d0 Guard peer collision checks with snapshot (#810) 2025-10-15 16:12:16 +02:00
3d914dcf46 Convert the remaining tests to Swift Testing (#781)
* SwiftTesting: NoiseProtocolTests + BinaryProtocolPaddingTests

* SwiftTesting: `NotificationStreamAssemblerTests`

* SwiftTesting: `NostrProtocolTests`

* SwiftTesting: `BinaryProtocolTests`

* SwiftTesting: `PeerIDTests`

* SwiftTesting: `BLEServiceTests`

* SwiftTesting: `CommandProcessorTests`

* SwiftTesting: `GCSFilterTests`

* SwiftTesting: `GeohashBookmarksStoreTests`

* Remove `peerID` test constants

* Remove PeerID + String interop from tests

* Refactor IntegrationTests to extract state management

* Refactor global state management of MockBLEService

* NoiseProtocolSwiftTests: `actor` -> `struct`

* Remove measurement tests w/ no benchmark

* `NoiseProtocolSwiftTests` -> `NoiseProtocolTests`

* SwiftTesting: `LocationChannelsTests`

* SwiftTesting: `GossipSyncManagerTests`

* SwiftTesting: `LocationNotesManagerTests`

* Global `sleep` function for tests

* SwiftTesting: `IntegrationTests`

---------

Co-authored-by: jack <jackjackbits@users.noreply.github.com>
2025-10-15 01:04:01 +02:00
b3ec5eeda0 Refactor Noise: Extract files and remove dead code (#806)
* Extract each type to a separate file

* NoiseSessionManager: Remove unused functions

---------

Co-authored-by: jack <212554440+jackjackbits@users.noreply.github.com>
2025-10-15 00:32:44 +02:00
IslamandGitHub 47d75ab9d8 PeerID 23/n: ChatViewModel + its dependences (#801) 2025-10-15 00:20:19 +02:00
98 changed files with 30879 additions and 29356 deletions
+45 -14
View File
@@ -7,6 +7,7 @@ on:
permissions: permissions:
contents: write contents: write
pull-requests: write
jobs: jobs:
update-relay-data: update-relay-data:
@@ -17,24 +18,54 @@ jobs:
uses: actions/checkout@v4 uses: actions/checkout@v4
with: with:
token: ${{ secrets.GITHUB_TOKEN }} token: ${{ secrets.GITHUB_TOKEN }}
fetch-depth: 0
- name: Fetch GeoRelays - name: Fetch GeoRelays
run: | run: |
wget https://raw.githubusercontent.com/permissionlesstech/georelays/refs/heads/main/nostr_relays.csv wget -q https://raw.githubusercontent.com/permissionlesstech/georelays/refs/heads/main/nostr_relays.csv
mv nostr_relays.csv ./relays/online_relays_gps.csv mv nostr_relays.csv ./relays/online_relays_gps.csv
- name: Check for changes - name: Configure git
id: git-check
run: | run: |
git diff --exit-code || echo "changes=true" >> $GITHUB_OUTPUT git config user.email "action@github.com"
git config user.name "GitHub Action"
- name: Commit and push changes
if: steps.git-check.outputs.changes == 'true' - name: Create update branch if changes
id: create_branch
run: | run: |
git config --local user.email "action@github.com" # exit early if no changes
git config --local user.name "GitHub Action" if git diff --quiet --relays/online_relays_gps.csv; then
echo "changed=false" >> $GITHUB_OUTPUT
exit 0
fi
# branch name with timestamp
BRANCH="update-georelays-$(date -u +%Y%m%dT%H%M%SZ)"
git checkout -b "$BRANCH"
git add relays/online_relays_gps.csv git add relays/online_relays_gps.csv
git commit -m "Automated update of relay data - $(date -u)" git commit -m "Automated update of relay data - $(date -u --rfc-3339=seconds)"
git push echo "changed=true" >> $GITHUB_OUTPUT
env: echo "branch=$BRANCH" >> $GITHUB_OUTPUT
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Push branch
if: steps.create_branch.outputs.changed == 'true'
run: |
git push --set-upstream origin "${{ steps.create_branch.outputs.branch }}"
- name: Create pull request
if: steps.create_branch.outputs.changed == 'true'
uses: peter-evans/create-pull-request@v5
with:
token: ${{ secrets.GITHUB_TOKEN }}
commit-message: Automated update of relay data
branch: ${{ steps.create_branch.outputs.branch }}
base: main
title: Automated update of relay data
body: |
This PR was created automatically by the scheduled workflow. It updates relays/online_relays_gps.csv from the GeoRelays source.
labels: automated, georelays
- name: No changes
if: steps.create_branch.outputs.changed != 'true'
run: echo "No changes to relays/online_relays_gps.csv"
+5 -2
View File
@@ -14,8 +14,11 @@ default:
# Check prerequisites # Check prerequisites
check: check:
@echo "Checking prerequisites..." @echo "Checking prerequisites..."
@command -v xcodebuild >/dev/null 2>&1 || (echo "❌ Xcode not found. Install Xcode from App Store" && exit 1) @command -v xcodebuild >/dev/null 2>&1 || (echo "❌ xcodebuild not found. Install Xcode from App Store" && exit 1)
@security find-identity -v -p codesigning | grep -q "Developer ID" || (echo "⚠️ No Developer ID found - code signing may fail" && exit 0) @xcode-select -p | grep -q "Xcode.app" || (echo "❌ Full Xcode required, not just command line tools. Install from App Store and run:\n sudo xcode-select -s /Applications/Xcode.app/Contents/Developer" && exit 1)
@test -d "/Applications/Xcode.app" || (echo "❌ Xcode.app not found in Applications folder. Install from App Store" && exit 1)
@xcodebuild -version >/dev/null 2>&1 || (echo "❌ Xcode not properly configured. Try:\n sudo xcode-select -s /Applications/Xcode.app/Contents/Developer" && exit 1)
@security find-identity -v -p codesigning | grep -q "Apple Development\|Developer ID" || (echo "⚠️ No Developer ID found - code signing may fail" && exit 0)
@echo "✅ All prerequisites met" @echo "✅ All prerequisites met"
# Backup original files # Backup original files
@@ -98,8 +98,8 @@
</BuildableProductRunnable> </BuildableProductRunnable>
<EnvironmentVariables> <EnvironmentVariables>
<EnvironmentVariable <EnvironmentVariable
key = "-DBITCHAT_DEV_ALLOW_CLEARNET" key = "BITCHAT_LOG_LEVEL"
value = "" value = "debug"
isEnabled = "YES"> isEnabled = "YES">
</EnvironmentVariable> </EnvironmentVariable>
</EnvironmentVariables> </EnvironmentVariables>
+8 -6
View File
@@ -57,11 +57,9 @@ struct BitchatApp: App {
let npub = try? idBridge.getCurrentNostrIdentity()?.npub let npub = try? idBridge.getCurrentNostrIdentity()?.npub
_ = VerificationService.shared.buildMyQRString(nickname: chatViewModel.nickname, npub: npub) _ = VerificationService.shared.buildMyQRString(nickname: chatViewModel.nickname, npub: npub)
} }
#if os(iOS)
appDelegate.chatViewModel = chatViewModel appDelegate.chatViewModel = chatViewModel
#elseif os(macOS)
appDelegate.chatViewModel = chatViewModel
#endif
// Initialize network activation policy; will start Tor/Nostr only when allowed // Initialize network activation policy; will start Tor/Nostr only when allowed
NetworkActivationService.shared.start() NetworkActivationService.shared.start()
// Check for shared content // Check for shared content
@@ -189,6 +187,10 @@ final class AppDelegate: NSObject, UIApplicationDelegate {
func application(_ application: UIApplication, didFinishLaunchingWithOptions launchOptions: [UIApplication.LaunchOptionsKey : Any]? = nil) -> Bool { func application(_ application: UIApplication, didFinishLaunchingWithOptions launchOptions: [UIApplication.LaunchOptionsKey : Any]? = nil) -> Bool {
return true return true
} }
func applicationWillTerminate(_ application: UIApplication) {
chatViewModel?.applicationWillTerminate()
}
} }
#endif #endif
@@ -221,7 +223,7 @@ final class NotificationDelegate: NSObject, UNUserNotificationCenterDelegate {
// Get peer ID from userInfo // Get peer ID from userInfo
if let peerID = userInfo["peerID"] as? String { if let peerID = userInfo["peerID"] as? String {
DispatchQueue.main.async { DispatchQueue.main.async {
self.chatViewModel?.startPrivateChat(with: peerID) self.chatViewModel?.startPrivateChat(with: PeerID(str: peerID))
} }
} }
} }
@@ -246,7 +248,7 @@ final class NotificationDelegate: NSObject, UNUserNotificationCenterDelegate {
// Get peer ID from userInfo // Get peer ID from userInfo
if let peerID = userInfo["peerID"] as? String { if let peerID = userInfo["peerID"] as? String {
// Don't show notification if the private chat is already open // Don't show notification if the private chat is already open
if chatViewModel?.selectedPrivateChatPeer == peerID { if chatViewModel?.selectedPrivateChatPeer == PeerID(str: peerID) {
completionHandler([]) completionHandler([])
return return
} }
+48 -12
View File
@@ -1,10 +1,10 @@
import Foundation import Foundation
import ImageIO
import UniformTypeIdentifiers
#if os(iOS) #if os(iOS)
import UIKit import UIKit
#else #else
import AppKit import AppKit
import ImageIO
import UniformTypeIdentifiers
#endif #endif
enum ImageUtilsError: Error { enum ImageUtilsError: Error {
@@ -13,10 +13,10 @@ enum ImageUtilsError: Error {
} }
enum ImageUtils { enum ImageUtils {
private static let compressionQuality: CGFloat = 0.85 private static let compressionQuality: CGFloat = 0.82
private static let targetImageBytes: Int = 60_000 private static let targetImageBytes: Int = 45_000
static func processImage(at url: URL, maxDimension: CGFloat = 512) throws -> URL { static func processImage(at url: URL, maxDimension: CGFloat = 448) throws -> URL {
// Security H1: Check file size BEFORE reading into memory // Security H1: Check file size BEFORE reading into memory
let attrs = try FileManager.default.attributesOfItem(atPath: url.path) let attrs = try FileManager.default.attributesOfItem(atPath: url.path)
guard let fileSize = attrs[.size] as? Int else { guard let fileSize = attrs[.size] as? Int else {
@@ -38,21 +38,32 @@ enum ImageUtils {
} }
#if os(iOS) #if os(iOS)
static func processImage(_ image: UIImage, maxDimension: CGFloat = 512) throws -> URL { static func processImage(_ image: UIImage, maxDimension: CGFloat = 448) throws -> URL {
return try autoreleasepool { return try autoreleasepool {
// Scale the image first
let scaled = scaledImage(image, maxDimension: maxDimension) let scaled = scaledImage(image, maxDimension: maxDimension)
var quality = compressionQuality
guard var jpegData = scaled.jpegData(compressionQuality: quality) else { // Get CGImage from UIImage - this is the key to stripping metadata
guard let cgImage = scaled.cgImage else {
throw ImageUtilsError.encodingFailed throw ImageUtilsError.encodingFailed
} }
// Use CGImageDestination to encode without metadata (same as macOS)
var quality = compressionQuality
guard var jpegData = encodeJPEG(from: cgImage, quality: quality) else {
throw ImageUtilsError.encodingFailed
}
// Compress to target size
while jpegData.count > targetImageBytes && quality > 0.3 { while jpegData.count > targetImageBytes && quality > 0.3 {
quality -= 0.1 quality -= 0.1
autoreleasepool { autoreleasepool {
if let next = scaled.jpegData(compressionQuality: quality) { if let next = encodeJPEG(from: cgImage, quality: quality) {
jpegData = next jpegData = next
} }
} }
} }
let outputURL = try makeOutputURL() let outputURL = try makeOutputURL()
try jpegData.write(to: outputURL, options: .atomic) try jpegData.write(to: outputURL, options: .atomic)
return outputURL return outputURL
@@ -65,14 +76,37 @@ enum ImageUtils {
guard maxSide > maxDimension else { return image } guard maxSide > maxDimension else { return image }
let scale = maxDimension / maxSide let scale = maxDimension / maxSide
let newSize = CGSize(width: size.width * scale, height: size.height * scale) let newSize = CGSize(width: size.width * scale, height: size.height * scale)
// Draw into a new context to get a clean CGImage without metadata
UIGraphicsBeginImageContextWithOptions(newSize, true, 1.0) UIGraphicsBeginImageContextWithOptions(newSize, true, 1.0)
image.draw(in: CGRect(origin: .zero, size: newSize)) image.draw(in: CGRect(origin: .zero, size: newSize))
let rendered = UIGraphicsGetImageFromCurrentImageContext() let rendered = UIGraphicsGetImageFromCurrentImageContext()
UIGraphicsEndImageContext() UIGraphicsEndImageContext()
return rendered ?? image return rendered ?? image
} }
// Shared EXIF-stripping JPEG encoder for both iOS and macOS
private static func encodeJPEG(from cgImage: CGImage, quality: CGFloat) -> Data? {
guard let data = CFDataCreateMutable(nil, 0) else {
return nil
}
guard let destination = CGImageDestinationCreateWithData(data, UTType.jpeg.identifier as CFString, 1, nil) else {
return nil
}
// Security: Strip ALL metadata (EXIF, GPS, TIFF, IPTC, XMP)
// By only specifying compression quality and no metadata keys,
// we ensure a clean JPEG with no privacy-leaking information
let options: [CFString: Any] = [
kCGImageDestinationLossyCompressionQuality: quality
]
CGImageDestinationAddImage(destination, cgImage, options as CFDictionary)
guard CGImageDestinationFinalize(destination) else {
return nil
}
return data as Data
}
#else #else
static func processImage(_ image: NSImage, maxDimension: CGFloat = 512) throws -> URL { static func processImage(_ image: NSImage, maxDimension: CGFloat = 448) throws -> URL {
return try autoreleasepool { return try autoreleasepool {
let scaled = scaledImage(image, maxDimension: maxDimension) let scaled = scaledImage(image, maxDimension: maxDimension)
guard let inputCG = scaled.cgImage(forProposedRect: nil, context: nil, hints: nil) else { guard let inputCG = scaled.cgImage(forProposedRect: nil, context: nil, hints: nil) else {
@@ -130,6 +164,7 @@ enum ImageUtils {
return scaledImage return scaledImage
} }
// Shared EXIF-stripping JPEG encoder for both iOS and macOS
private static func encodeJPEG(from cgImage: CGImage, quality: CGFloat) -> Data? { private static func encodeJPEG(from cgImage: CGImage, quality: CGFloat) -> Data? {
guard let data = CFDataCreateMutable(nil, 0) else { guard let data = CFDataCreateMutable(nil, 0) else {
return nil return nil
@@ -137,8 +172,9 @@ enum ImageUtils {
guard let destination = CGImageDestinationCreateWithData(data, UTType.jpeg.identifier as CFString, 1, nil) else { guard let destination = CGImageDestinationCreateWithData(data, UTType.jpeg.identifier as CFString, 1, nil) else {
return nil return nil
} }
// Security H2: Strip ALL metadata (EXIF, GPS, TIFF, IPTC, XMP) // Security: Strip ALL metadata (EXIF, GPS, TIFF, IPTC, XMP)
// Don't add any metadata dictionary keys - fresh CGContext ensures clean image // By only specifying compression quality and no metadata keys,
// we ensure a clean JPEG with no privacy-leaking information
let options: [CFString: Any] = [ let options: [CFString: Any] = [
kCGImageDestinationLossyCompressionQuality: quality kCGImageDestinationLossyCompressionQuality: quality
] ]
+3 -2
View File
@@ -14,6 +14,7 @@ final class VoiceRecorder: NSObject, AVAudioRecorderDelegate {
private let queue = DispatchQueue(label: "com.bitchat.voice-recorder") private let queue = DispatchQueue(label: "com.bitchat.voice-recorder")
private let paddingInterval: TimeInterval = 0.5 private let paddingInterval: TimeInterval = 0.5
private let maxRecordingDuration: TimeInterval = 120
private var recorder: AVAudioRecorder? private var recorder: AVAudioRecorder?
private var currentURL: URL? private var currentURL: URL?
@@ -75,14 +76,14 @@ final class VoiceRecorder: NSObject, AVAudioRecorderDelegate {
AVFormatIDKey: kAudioFormatMPEG4AAC, AVFormatIDKey: kAudioFormatMPEG4AAC,
AVSampleRateKey: 16_000, AVSampleRateKey: 16_000,
AVNumberOfChannelsKey: 1, AVNumberOfChannelsKey: 1,
AVEncoderBitRateKey: 20_000 AVEncoderBitRateKey: 16_000
] ]
let audioRecorder = try AVAudioRecorder(url: outputURL, settings: settings) let audioRecorder = try AVAudioRecorder(url: outputURL, settings: settings)
audioRecorder.delegate = self audioRecorder.delegate = self
audioRecorder.isMeteringEnabled = true audioRecorder.isMeteringEnabled = true
audioRecorder.prepareToRecord() audioRecorder.prepareToRecord()
audioRecorder.record() audioRecorder.record(forDuration: maxRecordingDuration)
recorder = audioRecorder recorder = audioRecorder
currentURL = outputURL currentURL = outputURL
+24248 -23926
View File
File diff suppressed because it is too large Load Diff
+6 -2
View File
@@ -21,8 +21,9 @@ struct BitchatPacket: Codable {
let payload: Data let payload: Data
var signature: Data? var signature: Data?
var ttl: UInt8 var ttl: UInt8
var route: [Data]?
init(type: UInt8, senderID: Data, recipientID: Data?, timestamp: UInt64, payload: Data, signature: Data?, ttl: UInt8, version: UInt8 = 1) { init(type: UInt8, senderID: Data, recipientID: Data?, timestamp: UInt64, payload: Data, signature: Data?, ttl: UInt8, version: UInt8 = 1, route: [Data]? = nil) {
self.version = version self.version = version
self.type = type self.type = type
self.senderID = senderID self.senderID = senderID
@@ -31,6 +32,7 @@ struct BitchatPacket: Codable {
self.payload = payload self.payload = payload
self.signature = signature self.signature = signature
self.ttl = ttl self.ttl = ttl
self.route = route
} }
// Convenience initializer for new binary format // Convenience initializer for new binary format
@@ -53,6 +55,7 @@ struct BitchatPacket: Codable {
self.payload = payload self.payload = payload
self.signature = nil self.signature = nil
self.ttl = ttl self.ttl = ttl
self.route = nil
} }
var data: Data? { var data: Data? {
@@ -81,7 +84,8 @@ struct BitchatPacket: Codable {
payload: payload, payload: payload,
signature: nil, // Remove signature for signing signature: nil, // Remove signature for signing
ttl: 0, // Use fixed TTL=0 for signing to ensure relay compatibility ttl: 0, // Use fixed TTL=0 for signing to ensure relay compatibility
version: version version: version,
route: route
) )
return BinaryProtocol.encode(unsignedPacket) return BinaryProtocol.encode(unsignedPacket)
} }
+58
View File
@@ -0,0 +1,58 @@
//
// CommandsInfo.swift
// bitchat
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import Foundation
// MARK: - CommandInfo Enum
enum CommandInfo: String, Identifiable {
case block
case clear
case hug
case message = "dm"
case slap
case unblock
case who
case favorite
case unfavorite
var id: String { rawValue }
var alias: String { "/" + rawValue }
var placeholder: String? {
switch self {
case .block, .hug, .message, .slap, .unblock, .favorite, .unfavorite:
return "<" + String(localized: "content.input.nickname_placeholder") + ">"
case .clear, .who:
return nil
}
}
var description: String {
switch self {
case .block: String(localized: "content.commands.block")
case .clear: String(localized: "content.commands.clear")
case .hug: String(localized: "content.commands.hug")
case .message: String(localized: "content.commands.message")
case .slap: String(localized: "content.commands.slap")
case .unblock: String(localized: "content.commands.unblock")
case .who: String(localized: "content.commands.who")
case .favorite: String(localized: "content.commands.favorite")
case .unfavorite: String(localized: "content.commands.unfavorite")
}
}
static func all(isGeoPublic: Bool, isGeoDM: Bool) -> [CommandInfo] {
let baseCommands: [CommandInfo] = [.block, .unblock, .clear, .hug, .message, .slap, .who]
if isGeoPublic || isGeoDM {
return baseCommands + [.favorite, .unfavorite]
}
return baseCommands
}
}
+22 -18
View File
@@ -35,7 +35,7 @@ struct PeerID: Equatable, Hashable {
// Private so the callers have to go through a convenience init // Private so the callers have to go through a convenience init
private init(prefix: Prefix, bare: any StringProtocol) { private init(prefix: Prefix, bare: any StringProtocol) {
self.prefix = prefix self.prefix = prefix
self.bare = String(bare) self.bare = String(bare).lowercased()
} }
} }
@@ -76,6 +76,12 @@ extension PeerID {
init(hexData: Data) { init(hexData: Data) {
self.init(str: hexData.hexEncodedString()) self.init(str: hexData.hexEncodedString())
} }
/// Convenience init to "hide" hex-encoding implementation detail
init?(hexData: Data?) {
guard let hexData else { return nil }
self.init(hexData: hexData)
}
} }
// MARK: - Noise Public Key Helpers // MARK: - Noise Public Key Helpers
@@ -130,6 +136,20 @@ extension PeerID {
} }
} }
extension PeerID {
var routingData: Data? {
if let direct = Data(hexString: id), direct.count == 8 { return direct }
if let bareData = Data(hexString: bare), bareData.count == 8 { return bareData }
let short = toShort()
return Data(hexString: short.id)
}
init?(routingData: Data) {
guard routingData.count == 8 else { return nil }
self.init(hexData: routingData)
}
}
// MARK: - Validation // MARK: - Validation
extension PeerID { extension PeerID {
@@ -191,9 +211,7 @@ extension PeerID: Comparable {
} }
} }
// MARK: - String Interop Helpers // MARK: - CustomStringConvertible
// MARK: CustomStringConvertible
extension PeerID: CustomStringConvertible { extension PeerID: CustomStringConvertible {
/// So it returns the actual `id` like before even inside another String /// So it returns the actual `id` like before even inside another String
@@ -201,17 +219,3 @@ extension PeerID: CustomStringConvertible {
id id
} }
} }
// MARK: Custom Equatable w/ String & Optionality
// PeerID <> String
extension Optional where Wrapped == PeerID {
static func ==(lhs: Optional<Wrapped>, rhs: Optional<String>) -> Bool { lhs?.id == rhs }
static func !=(lhs: Optional<Wrapped>, rhs: Optional<String>) -> Bool { lhs?.id != rhs }
}
// String <> PeerID
extension Optional where Wrapped == String {
static func ==(lhs: Optional<Wrapped>, rhs: Optional<PeerID>) -> Bool { lhs == rhs?.id }
static func !=(lhs: Optional<Wrapped>, rhs: Optional<PeerID>) -> Bool { lhs != rhs?.id }
}
+6 -6
View File
@@ -11,11 +11,11 @@ import Foundation
struct ReadReceipt: Codable { struct ReadReceipt: Codable {
let originalMessageID: String let originalMessageID: String
let receiptID: String let receiptID: String
var readerID: String // Who read it var readerID: PeerID // Who read it
let readerNickname: String let readerNickname: String
let timestamp: Date let timestamp: Date
init(originalMessageID: String, readerID: String, readerNickname: String) { init(originalMessageID: String, readerID: PeerID, readerNickname: String) {
self.originalMessageID = originalMessageID self.originalMessageID = originalMessageID
self.receiptID = UUID().uuidString self.receiptID = UUID().uuidString
self.readerID = readerID self.readerID = readerID
@@ -24,7 +24,7 @@ struct ReadReceipt: Codable {
} }
// For binary decoding // For binary decoding
private init(originalMessageID: String, receiptID: String, readerID: String, readerNickname: String, timestamp: Date) { private init(originalMessageID: String, receiptID: String, readerID: PeerID, readerNickname: String, timestamp: Date) {
self.originalMessageID = originalMessageID self.originalMessageID = originalMessageID
self.receiptID = receiptID self.receiptID = receiptID
self.readerID = readerID self.readerID = readerID
@@ -48,7 +48,7 @@ struct ReadReceipt: Codable {
data.appendUUID(receiptID) data.appendUUID(receiptID)
// ReaderID as 8-byte hex string // ReaderID as 8-byte hex string
var readerData = Data() var readerData = Data()
var tempID = readerID var tempID = readerID.id
while tempID.count >= 2 && readerData.count < 8 { while tempID.count >= 2 && readerData.count < 8 {
let hexByte = String(tempID.prefix(2)) let hexByte = String(tempID.prefix(2))
if let byte = UInt8(hexByte, radix: 16) { if let byte = UInt8(hexByte, radix: 16) {
@@ -78,8 +78,8 @@ struct ReadReceipt: Codable {
let receiptID = dataCopy.readUUID(at: &offset) else { return nil } let receiptID = dataCopy.readUUID(at: &offset) else { return nil }
guard let readerIDData = dataCopy.readFixedBytes(at: &offset, count: 8) else { return nil } guard let readerIDData = dataCopy.readFixedBytes(at: &offset, count: 8) else { return nil }
let readerID = readerIDData.hexEncodedString() let readerID = PeerID(hexData: readerIDData)
guard PeerID(str: readerID).isValid else { return nil } guard readerID.isValid else { return nil }
guard let timestamp = dataCopy.readDate(at: &offset), guard let timestamp = dataCopy.readDate(at: &offset),
InputValidator.validateTimestamp(timestamp), InputValidator.validateTimestamp(timestamp),
+17 -1
View File
@@ -8,6 +8,14 @@ struct RequestSyncPacket {
let p: Int let p: Int
let m: UInt32 let m: UInt32
let data: Data let data: Data
let types: SyncTypeFlags?
init(p: Int, m: UInt32, data: Data, types: SyncTypeFlags? = nil) {
self.p = p
self.m = m
self.data = data
self.types = types
}
func encode() -> Data { func encode() -> Data {
var out = Data() var out = Data()
@@ -25,6 +33,9 @@ struct RequestSyncPacket {
putTLV(0x02, withUnsafeBytes(of: &mBE) { Data($0) }) putTLV(0x02, withUnsafeBytes(of: &mBE) { Data($0) })
// data // data
putTLV(0x03, data) putTLV(0x03, data)
if let typesData = types?.toData() {
putTLV(0x04, typesData)
}
return out return out
} }
@@ -33,6 +44,7 @@ struct RequestSyncPacket {
var p: Int? = nil var p: Int? = nil
var m: UInt32? = nil var m: UInt32? = nil
var payload: Data? = nil var payload: Data? = nil
var types: SyncTypeFlags? = nil
while off + 3 <= data.count { while off + 3 <= data.count {
let t = Int(data[off]); off += 1 let t = Int(data[off]); off += 1
@@ -52,12 +64,16 @@ struct RequestSyncPacket {
case 0x03: case 0x03:
if v.count > maxAcceptBytes { return nil } if v.count > maxAcceptBytes { return nil }
payload = v payload = v
case 0x04:
if let decoded = SyncTypeFlags.decode(v) {
types = decoded
}
default: default:
break // forward compatible; ignore unknown TLVs break // forward compatible; ignore unknown TLVs
} }
} }
guard let pp = p, let mm = m, let dd = payload, pp >= 1, mm > 0 else { return nil } guard let pp = p, let mm = m, let dd = payload, pp >= 1, mm > 0 else { return nil }
return RequestSyncPacket(p: pp, m: mm, data: dd) return RequestSyncPacket(p: pp, m: mm, data: dd, types: types)
} }
} }
+1 -1
View File
@@ -767,7 +767,7 @@ final class NoiseHandshakeState {
let shared = try localStatic.sharedSecretFromKeyAgreement(with: remoteStatic) let shared = try localStatic.sharedSecretFromKeyAgreement(with: remoteStatic)
symmetricState.mixKey(shared.withUnsafeBytes { Data($0) }) symmetricState.mixKey(shared.withUnsafeBytes { Data($0) })
default: case .e, .s:
break break
} }
} }
+95
View File
@@ -0,0 +1,95 @@
//
// NoiseRateLimiter.swift
// bitchat
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import BitLogger
import Foundation
final class NoiseRateLimiter {
private var handshakeTimestamps: [PeerID: [Date]] = [:]
private var messageTimestamps: [PeerID: [Date]] = [:]
// Global rate limiting
private var globalHandshakeTimestamps: [Date] = []
private var globalMessageTimestamps: [Date] = []
private let queue = DispatchQueue(label: "chat.bitchat.noise.ratelimit", attributes: .concurrent)
func allowHandshake(from peerID: PeerID) -> Bool {
return queue.sync(flags: .barrier) {
let now = Date()
let oneMinuteAgo = now.addingTimeInterval(-60)
// Check global rate limit first
globalHandshakeTimestamps = globalHandshakeTimestamps.filter { $0 > oneMinuteAgo }
if globalHandshakeTimestamps.count >= NoiseSecurityConstants.maxGlobalHandshakesPerMinute {
SecureLogger.warning("Global handshake rate limit exceeded: \(globalHandshakeTimestamps.count)/\(NoiseSecurityConstants.maxGlobalHandshakesPerMinute) per minute", category: .security)
return false
}
// Check per-peer rate limit
var timestamps = handshakeTimestamps[peerID] ?? []
timestamps = timestamps.filter { $0 > oneMinuteAgo }
if timestamps.count >= NoiseSecurityConstants.maxHandshakesPerMinute {
SecureLogger.warning("Per-peer handshake rate limit exceeded for \(peerID): \(timestamps.count)/\(NoiseSecurityConstants.maxHandshakesPerMinute) per minute", category: .security)
return false
}
// Record new handshake
timestamps.append(now)
handshakeTimestamps[peerID] = timestamps
globalHandshakeTimestamps.append(now)
return true
}
}
func allowMessage(from peerID: PeerID) -> Bool {
return queue.sync(flags: .barrier) {
let now = Date()
let oneSecondAgo = now.addingTimeInterval(-1)
// Check global rate limit first
globalMessageTimestamps = globalMessageTimestamps.filter { $0 > oneSecondAgo }
if globalMessageTimestamps.count >= NoiseSecurityConstants.maxGlobalMessagesPerSecond {
SecureLogger.warning("Global message rate limit exceeded: \(globalMessageTimestamps.count)/\(NoiseSecurityConstants.maxGlobalMessagesPerSecond) per second", category: .security)
return false
}
// Check per-peer rate limit
var timestamps = messageTimestamps[peerID] ?? []
timestamps = timestamps.filter { $0 > oneSecondAgo }
if timestamps.count >= NoiseSecurityConstants.maxMessagesPerSecond {
SecureLogger.warning("Per-peer message rate limit exceeded for \(peerID): \(timestamps.count)/\(NoiseSecurityConstants.maxMessagesPerSecond) per second", category: .security)
return false
}
// Record new message
timestamps.append(now)
messageTimestamps[peerID] = timestamps
globalMessageTimestamps.append(now)
return true
}
}
func reset(for peerID: PeerID) {
queue.async(flags: .barrier) {
self.handshakeTimestamps.removeValue(forKey: peerID)
self.messageTimestamps.removeValue(forKey: peerID)
}
}
func resetAll() {
queue.async(flags: .barrier) {
self.handshakeTimestamps.removeAll()
self.messageTimestamps.removeAll()
self.globalHandshakeTimestamps.removeAll()
self.globalMessageTimestamps.removeAll()
}
}
}
@@ -1,227 +0,0 @@
//
// NoiseSecurityConsiderations.swift
// bitchat
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import BitLogger
import Foundation
// MARK: - Security Constants
enum NoiseSecurityConstants {
// Maximum message size to prevent memory exhaustion
static let maxMessageSize = 65535 // 64KB as per Noise spec
// Maximum handshake message size
static let maxHandshakeMessageSize = 2048 // 2KB to accommodate XX pattern
// Session timeout - sessions older than this should be renegotiated
static let sessionTimeout: TimeInterval = 86400 // 24 hours
// Maximum number of messages before rekey (2^64 - 1 is the nonce limit)
static let maxMessagesPerSession: UInt64 = 1_000_000_000 // 1 billion messages
// Handshake timeout - abandon incomplete handshakes
static let handshakeTimeout: TimeInterval = 60 // 1 minute
// Maximum concurrent sessions per peer
static let maxSessionsPerPeer = 3
// Rate limiting
static let maxHandshakesPerMinute = 10
static let maxMessagesPerSecond = 100
// Global rate limiting (across all peers)
static let maxGlobalHandshakesPerMinute = 30
static let maxGlobalMessagesPerSecond = 500
}
// MARK: - Security Validations
struct NoiseSecurityValidator {
/// Validate message size
static func validateMessageSize(_ data: Data) -> Bool {
return data.count <= NoiseSecurityConstants.maxMessageSize
}
/// Validate handshake message size
static func validateHandshakeMessageSize(_ data: Data) -> Bool {
return data.count <= NoiseSecurityConstants.maxHandshakeMessageSize
}
}
// MARK: - Enhanced Noise Session with Security
final class SecureNoiseSession: NoiseSession {
private(set) var messageCount: UInt64 = 0
private let sessionStartTime = Date()
private(set) var lastActivityTime = Date()
override func encrypt(_ plaintext: Data) throws -> Data {
// Check session age
if Date().timeIntervalSince(sessionStartTime) > NoiseSecurityConstants.sessionTimeout {
throw NoiseSecurityError.sessionExpired
}
// Check message count
if messageCount >= NoiseSecurityConstants.maxMessagesPerSession {
throw NoiseSecurityError.sessionExhausted
}
// Validate message size
guard NoiseSecurityValidator.validateMessageSize(plaintext) else {
throw NoiseSecurityError.messageTooLarge
}
let encrypted = try super.encrypt(plaintext)
messageCount += 1
lastActivityTime = Date()
return encrypted
}
override func decrypt(_ ciphertext: Data) throws -> Data {
// Check session age
if Date().timeIntervalSince(sessionStartTime) > NoiseSecurityConstants.sessionTimeout {
throw NoiseSecurityError.sessionExpired
}
// Validate message size
guard NoiseSecurityValidator.validateMessageSize(ciphertext) else {
throw NoiseSecurityError.messageTooLarge
}
let decrypted = try super.decrypt(ciphertext)
lastActivityTime = Date()
return decrypted
}
func needsRenegotiation() -> Bool {
// Check if we've used more than 90% of message limit
let messageThreshold = UInt64(Double(NoiseSecurityConstants.maxMessagesPerSession) * 0.9)
if messageCount >= messageThreshold {
return true
}
// Check if last activity was more than 30 minutes ago
if Date().timeIntervalSince(lastActivityTime) > NoiseSecurityConstants.sessionTimeout {
return true
}
return false
}
// MARK: - Testing Support
#if DEBUG
func setLastActivityTimeForTesting(_ date: Date) {
lastActivityTime = date
}
func setMessageCountForTesting(_ count: UInt64) {
messageCount = count
}
#endif
}
// MARK: - Rate Limiter
final class NoiseRateLimiter {
private var handshakeTimestamps: [PeerID: [Date]] = [:]
private var messageTimestamps: [PeerID: [Date]] = [:]
// Global rate limiting
private var globalHandshakeTimestamps: [Date] = []
private var globalMessageTimestamps: [Date] = []
private let queue = DispatchQueue(label: "chat.bitchat.noise.ratelimit", attributes: .concurrent)
func allowHandshake(from peerID: PeerID) -> Bool {
return queue.sync(flags: .barrier) {
let now = Date()
let oneMinuteAgo = now.addingTimeInterval(-60)
// Check global rate limit first
globalHandshakeTimestamps = globalHandshakeTimestamps.filter { $0 > oneMinuteAgo }
if globalHandshakeTimestamps.count >= NoiseSecurityConstants.maxGlobalHandshakesPerMinute {
SecureLogger.warning("Global handshake rate limit exceeded: \(globalHandshakeTimestamps.count)/\(NoiseSecurityConstants.maxGlobalHandshakesPerMinute) per minute", category: .security)
return false
}
// Check per-peer rate limit
var timestamps = handshakeTimestamps[peerID] ?? []
timestamps = timestamps.filter { $0 > oneMinuteAgo }
if timestamps.count >= NoiseSecurityConstants.maxHandshakesPerMinute {
SecureLogger.warning("Per-peer handshake rate limit exceeded for \(peerID): \(timestamps.count)/\(NoiseSecurityConstants.maxHandshakesPerMinute) per minute", category: .security)
return false
}
// Record new handshake
timestamps.append(now)
handshakeTimestamps[peerID] = timestamps
globalHandshakeTimestamps.append(now)
return true
}
}
func allowMessage(from peerID: PeerID) -> Bool {
return queue.sync(flags: .barrier) {
let now = Date()
let oneSecondAgo = now.addingTimeInterval(-1)
// Check global rate limit first
globalMessageTimestamps = globalMessageTimestamps.filter { $0 > oneSecondAgo }
if globalMessageTimestamps.count >= NoiseSecurityConstants.maxGlobalMessagesPerSecond {
SecureLogger.warning("Global message rate limit exceeded: \(globalMessageTimestamps.count)/\(NoiseSecurityConstants.maxGlobalMessagesPerSecond) per second", category: .security)
return false
}
// Check per-peer rate limit
var timestamps = messageTimestamps[peerID] ?? []
timestamps = timestamps.filter { $0 > oneSecondAgo }
if timestamps.count >= NoiseSecurityConstants.maxMessagesPerSecond {
SecureLogger.warning("Per-peer message rate limit exceeded for \(peerID): \(timestamps.count)/\(NoiseSecurityConstants.maxMessagesPerSecond) per second", category: .security)
return false
}
// Record new message
timestamps.append(now)
messageTimestamps[peerID] = timestamps
globalMessageTimestamps.append(now)
return true
}
}
func reset(for peerID: PeerID) {
queue.async(flags: .barrier) {
self.handshakeTimestamps.removeValue(forKey: peerID)
self.messageTimestamps.removeValue(forKey: peerID)
}
}
func resetAll() {
queue.async(flags: .barrier) {
self.handshakeTimestamps.removeAll()
self.messageTimestamps.removeAll()
self.globalHandshakeTimestamps.removeAll()
self.globalMessageTimestamps.removeAll()
}
}
}
// MARK: - Security Errors
enum NoiseSecurityError: Error {
case sessionExpired
case sessionExhausted
case messageTooLarge
case invalidPeerID
case rateLimitExceeded
case handshakeTimeout
}
@@ -0,0 +1,37 @@
//
// NoiseSecurityConstants.swift
// bitchat
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import Foundation
enum NoiseSecurityConstants {
// Maximum message size to prevent memory exhaustion
static let maxMessageSize = 65535 // 64KB as per Noise spec
// Maximum handshake message size
static let maxHandshakeMessageSize = 2048 // 2KB to accommodate XX pattern
// Session timeout - sessions older than this should be renegotiated
static let sessionTimeout: TimeInterval = 86400 // 24 hours
// Maximum number of messages before rekey (2^64 - 1 is the nonce limit)
static let maxMessagesPerSession: UInt64 = 1_000_000_000 // 1 billion messages
// Handshake timeout - abandon incomplete handshakes
static let handshakeTimeout: TimeInterval = 60 // 1 minute
// Maximum concurrent sessions per peer
static let maxSessionsPerPeer = 3
// Rate limiting
static let maxHandshakesPerMinute = 10
static let maxMessagesPerSecond = 100
// Global rate limiting (across all peers)
static let maxGlobalHandshakesPerMinute = 30
static let maxGlobalMessagesPerSecond = 500
}
+18
View File
@@ -0,0 +1,18 @@
//
// NoiseSecurityError.swift
// bitchat
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import Foundation
enum NoiseSecurityError: Error {
case sessionExpired
case sessionExhausted
case messageTooLarge
case invalidPeerID
case rateLimitExceeded
case handshakeTimeout
}
@@ -0,0 +1,22 @@
//
// NoiseSecurityValidator.swift
// bitchat
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import Foundation
struct NoiseSecurityValidator {
/// Validate message size
static func validateMessageSize(_ data: Data) -> Bool {
return data.count <= NoiseSecurityConstants.maxMessageSize
}
/// Validate handshake message size
static func validateHandshakeMessageSize(_ data: Data) -> Bool {
return data.count <= NoiseSecurityConstants.maxHandshakeMessageSize
}
}
-6
View File
@@ -196,12 +196,6 @@ class NoiseSession {
} }
} }
func getHandshakeHash() -> Data? {
return sessionQueue.sync {
return handshakeHash
}
}
func reset() { func reset() {
sessionQueue.sync(flags: .barrier) { sessionQueue.sync(flags: .barrier) {
let wasEstablished = state == .established let wasEstablished = state == .established
+1 -2
View File
@@ -6,10 +6,9 @@
// For more information, see <https://unlicense.org> // For more information, see <https://unlicense.org>
// //
enum NoiseSessionError: Error { enum NoiseSessionError: Error, Equatable {
case invalidState case invalidState
case notEstablished case notEstablished
case sessionNotFound case sessionNotFound
case handshakeFailed(Error)
case alreadyEstablished case alreadyEstablished
} }
+2 -30
View File
@@ -27,19 +27,6 @@ final class NoiseSessionManager {
// MARK: - Session Management // MARK: - Session Management
func createSession(for peerID: PeerID, role: NoiseRole) -> NoiseSession {
return managerQueue.sync(flags: .barrier) {
let session = SecureNoiseSession(
peerID: peerID,
role: role,
keychain: keychain,
localStaticKey: localStaticKey
)
sessions[peerID] = session
return session
}
}
func getSession(for peerID: PeerID) -> NoiseSession? { func getSession(for peerID: PeerID) -> NoiseSession? {
return managerQueue.sync { return managerQueue.sync {
return sessions[peerID] return sessions[peerID]
@@ -48,14 +35,9 @@ final class NoiseSessionManager {
func removeSession(for peerID: PeerID) { func removeSession(for peerID: PeerID) {
managerQueue.sync(flags: .barrier) { managerQueue.sync(flags: .barrier) {
if let session = sessions[peerID] { if let session = sessions.removeValue(forKey: peerID) {
if session.isEstablished() { session.reset() // Clear sensitive data before removing
SecureLogger.info(.sessionExpired(peerID: peerID.id))
}
// Clear sensitive data before removing
session.reset()
} }
_ = sessions.removeValue(forKey: peerID)
} }
} }
@@ -68,12 +50,6 @@ final class NoiseSessionManager {
} }
} }
func getEstablishedSessions() -> [PeerID: NoiseSession] {
return managerQueue.sync {
return sessions.filter { $0.value.isEstablished() }
}
}
// MARK: - Handshake Helpers // MARK: - Handshake Helpers
func initiateHandshake(with peerID: PeerID) throws -> Data { func initiateHandshake(with peerID: PeerID) throws -> Data {
@@ -207,10 +183,6 @@ final class NoiseSessionManager {
return getSession(for: peerID)?.getRemoteStaticPublicKey() return getSession(for: peerID)?.getRemoteStaticPublicKey()
} }
func getHandshakeHash(for peerID: PeerID) -> Data? {
return getSession(for: peerID)?.getHandshakeHash()
}
// MARK: - Session Rekeying // MARK: - Session Rekeying
func getSessionsNeedingRekey() -> [(peerID: PeerID, needsRekey: Bool)] { func getSessionsNeedingRekey() -> [(peerID: PeerID, needsRekey: Bool)] {
+81
View File
@@ -0,0 +1,81 @@
//
// SecureNoiseSession.swift
// bitchat
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import Foundation
final class SecureNoiseSession: NoiseSession {
private(set) var messageCount: UInt64 = 0
private let sessionStartTime = Date()
private(set) var lastActivityTime = Date()
override func encrypt(_ plaintext: Data) throws -> Data {
// Check session age
if Date().timeIntervalSince(sessionStartTime) > NoiseSecurityConstants.sessionTimeout {
throw NoiseSecurityError.sessionExpired
}
// Check message count
if messageCount >= NoiseSecurityConstants.maxMessagesPerSession {
throw NoiseSecurityError.sessionExhausted
}
// Validate message size
guard NoiseSecurityValidator.validateMessageSize(plaintext) else {
throw NoiseSecurityError.messageTooLarge
}
let encrypted = try super.encrypt(plaintext)
messageCount += 1
lastActivityTime = Date()
return encrypted
}
override func decrypt(_ ciphertext: Data) throws -> Data {
// Check session age
if Date().timeIntervalSince(sessionStartTime) > NoiseSecurityConstants.sessionTimeout {
throw NoiseSecurityError.sessionExpired
}
// Validate message size
guard NoiseSecurityValidator.validateMessageSize(ciphertext) else {
throw NoiseSecurityError.messageTooLarge
}
let decrypted = try super.decrypt(ciphertext)
lastActivityTime = Date()
return decrypted
}
func needsRenegotiation() -> Bool {
// Check if we've used more than 90% of message limit
let messageThreshold = UInt64(Double(NoiseSecurityConstants.maxMessagesPerSession) * 0.9)
if messageCount >= messageThreshold {
return true
}
// Check if last activity was more than 30 minutes ago
if Date().timeIntervalSince(lastActivityTime) > NoiseSecurityConstants.sessionTimeout {
return true
}
return false
}
// MARK: - Testing Support
#if DEBUG
func setLastActivityTimeForTesting(_ date: Date) {
lastActivityTime = date
}
func setMessageCountForTesting(_ count: UInt64) {
messageCount = count
}
#endif
}
+219 -36
View File
@@ -1,6 +1,11 @@
import BitLogger import BitLogger
import Foundation import Foundation
import Tor import Tor
#if os(iOS)
import UIKit
#elseif os(macOS)
import AppKit
#endif
/// Directory of online Nostr relays with approximate GPS locations, used for geohash routing. /// Directory of online Nostr relays with approximate GPS locations, used for geohash routing.
@MainActor @MainActor
@@ -12,19 +17,32 @@ final class GeoRelayDirectory {
} }
static let shared = GeoRelayDirectory() static let shared = GeoRelayDirectory()
private(set) var entries: [Entry] = [] private(set) var entries: [Entry] = []
private let cacheFileName = "georelays_cache.csv" private let cacheFileName = "georelays_cache.csv"
private let lastFetchKey = "georelay.lastFetchAt" private let lastFetchKey = "georelay.lastFetchAt"
private let remoteURL = URL(string: "https://raw.githubusercontent.com/permissionlesstech/georelays/refs/heads/main/nostr_relays.csv")! private let remoteURL = URL(string: "https://raw.githubusercontent.com/permissionlesstech/georelays/refs/heads/main/nostr_relays.csv")!
private let fetchInterval: TimeInterval = TransportConfig.geoRelayFetchIntervalSeconds // 24h private let fetchInterval: TimeInterval = TransportConfig.geoRelayFetchIntervalSeconds
private var refreshTimer: Timer?
private var retryTask: Task<Void, Never>?
private var retryAttempt: Int = 0
private var isFetching: Bool = false
private var observers: [NSObjectProtocol] = []
private init() { private init() {
// Load cached or bundled data synchronously entries = loadLocalEntries()
self.entries = self.loadLocalEntries() registerObservers()
// Fire-and-forget remote refresh if stale startRefreshTimer()
prefetchIfNeeded() prefetchIfNeeded()
} }
deinit {
observers.forEach { NotificationCenter.default.removeObserver($0) }
refreshTimer?.invalidate()
retryTask?.cancel()
}
/// Returns up to `count` relay URLs (wss://) closest to the geohash center. /// Returns up to `count` relay URLs (wss://) closest to the geohash center.
func closestRelays(toGeohash geohash: String, count: Int = 5) -> [String] { func closestRelays(toGeohash geohash: String, count: Int = 5) -> [String] {
let center = Geohash.decodeCenter(geohash) let center = Geohash.decodeCenter(geohash)
@@ -33,52 +51,148 @@ final class GeoRelayDirectory {
/// Returns up to `count` relay URLs (wss://) closest to the given coordinate. /// Returns up to `count` relay URLs (wss://) closest to the given coordinate.
func closestRelays(toLat lat: Double, lon: Double, count: Int = 5) -> [String] { func closestRelays(toLat lat: Double, lon: Double, count: Int = 5) -> [String] {
guard !entries.isEmpty else { return [] } guard !entries.isEmpty, count > 0 else { return [] }
let sorted = entries
.sorted { a, b in if entries.count <= count {
haversineKm(lat, lon, a.lat, a.lon) < haversineKm(lat, lon, b.lat, b.lon) return entries
.sorted { a, b in
haversineKm(lat, lon, a.lat, a.lon) < haversineKm(lat, lon, b.lat, b.lon)
}
.map { "wss://\($0.host)" }
}
var best: [(entry: Entry, distance: Double)] = []
best.reserveCapacity(count)
for entry in entries {
let distance = haversineKm(lat, lon, entry.lat, entry.lon)
if best.count < count {
let idx = best.firstIndex { $0.distance > distance } ?? best.count
best.insert((entry, distance), at: idx)
} else if let worstDistance = best.last?.distance, distance < worstDistance {
let idx = best.firstIndex { $0.distance > distance } ?? best.count
best.insert((entry, distance), at: idx)
best.removeLast()
} }
.prefix(count) }
return sorted.map { "wss://\($0.host)" }
return best.map { "wss://\($0.entry.host)" }
} }
// MARK: - Remote Fetch // MARK: - Remote Fetch
func prefetchIfNeeded() { func prefetchIfNeeded(force: Bool = false) {
guard !isFetching else { return }
let now = Date() let now = Date()
let last = UserDefaults.standard.object(forKey: lastFetchKey) as? Date ?? .distantPast let last = UserDefaults.standard.object(forKey: lastFetchKey) as? Date ?? .distantPast
guard now.timeIntervalSince(last) >= fetchInterval else { return }
if !force {
guard now.timeIntervalSince(last) >= fetchInterval else { return }
} else if last != .distantPast,
now.timeIntervalSince(last) < TransportConfig.geoRelayRetryInitialSeconds {
// Skip forced fetches if we just refreshed moments ago.
return
}
cancelRetry()
fetchRemote() fetchRemote()
} }
private func fetchRemote() { private func fetchRemote() {
let req = URLRequest(url: remoteURL, cachePolicy: .reloadIgnoringLocalCacheData, timeoutInterval: 15) guard !isFetching else { return }
// Ensure Tor readiness before fetching (fail-closed by default) isFetching = true
Task.detached {
let request = URLRequest(
url: remoteURL,
cachePolicy: .reloadIgnoringLocalCacheData,
timeoutInterval: 15
)
Task.detached { [weak self] in
guard let self else { return }
let ready = await TorManager.shared.awaitReady() let ready = await TorManager.shared.awaitReady()
if !ready { if !ready {
SecureLogger.warning("GeoRelayDirectory: Tor not ready; skipping remote fetch (fail-closed)", category: .session) await self.handleFetchFailure(.torNotReady)
return return
} }
let task = TorURLSession.shared.session.dataTask(with: req) { [weak self] data, _, error in
guard let self = self else { return } do {
if let data = data, error == nil, let text = String(data: data, encoding: .utf8) { let (data, _) = try await TorURLSession.shared.session.data(for: request)
let parsed = GeoRelayDirectory.parseCSV(text) guard let text = String(data: data, encoding: .utf8) else {
if !parsed.isEmpty { await self.handleFetchFailure(.invalidData)
Task { @MainActor in return
self.entries = parsed
self.persistCache(text)
UserDefaults.standard.set(Date(), forKey: self.lastFetchKey)
SecureLogger.info("GeoRelayDirectory: refreshed \(parsed.count) relays from remote", category: .session)
}
return
}
} }
SecureLogger.warning("GeoRelayDirectory: remote fetch failed; keeping local entries", category: .session)
let parsed = GeoRelayDirectory.parseCSV(text)
guard !parsed.isEmpty else {
await self.handleFetchFailure(.invalidData)
return
}
await self.handleFetchSuccess(entries: parsed, csv: text)
} catch {
await self.handleFetchFailure(.network(error))
} }
task.resume()
} }
} }
private enum FetchFailure {
case torNotReady
case invalidData
case network(Error)
}
@MainActor
private func handleFetchSuccess(entries parsed: [Entry], csv: String) {
entries = parsed
persistCache(csv)
UserDefaults.standard.set(Date(), forKey: lastFetchKey)
SecureLogger.info("GeoRelayDirectory: refreshed \(parsed.count) relays from remote", category: .session)
isFetching = false
retryAttempt = 0
cancelRetry()
}
@MainActor
private func handleFetchFailure(_ reason: FetchFailure) {
switch reason {
case .torNotReady:
SecureLogger.warning("GeoRelayDirectory: Tor not ready; scheduling retry", category: .session)
case .invalidData:
SecureLogger.warning("GeoRelayDirectory: remote fetch returned invalid data; scheduling retry", category: .session)
case .network(let error):
SecureLogger.warning("GeoRelayDirectory: remote fetch failed with error: \(error.localizedDescription)", category: .session)
}
isFetching = false
scheduleRetry()
}
@MainActor
private func scheduleRetry() {
retryAttempt = min(retryAttempt + 1, 10)
let base = TransportConfig.geoRelayRetryInitialSeconds
let maxDelay = TransportConfig.geoRelayRetryMaxSeconds
let multiplier = pow(2.0, Double(max(retryAttempt - 1, 0)))
let calculated = base * multiplier
let delay = min(maxDelay, max(base, calculated))
cancelRetry()
retryTask = Task { [weak self] in
let nanoseconds = UInt64(delay * 1_000_000_000)
try? await Task.sleep(nanoseconds: nanoseconds)
await MainActor.run {
self?.prefetchIfNeeded(force: true)
}
}
}
@MainActor
private func cancelRetry() {
retryTask?.cancel()
retryTask = nil
}
private func persistCache(_ text: String) { private func persistCache(_ text: String) {
guard let url = cacheURL() else { return } guard let url = cacheURL() else { return }
do { do {
@@ -91,30 +205,35 @@ final class GeoRelayDirectory {
// MARK: - Loading // MARK: - Loading
private func loadLocalEntries() -> [Entry] { private func loadLocalEntries() -> [Entry] {
// Prefer cached file if present // Prefer cached file if present
if let cache = self.cacheURL(), if let cache = cacheURL(),
let data = try? Data(contentsOf: cache), let data = try? Data(contentsOf: cache),
let text = String(data: data, encoding: .utf8) { let text = String(data: data, encoding: .utf8) {
let arr = Self.parseCSV(text) let arr = Self.parseCSV(text)
if !arr.isEmpty { return arr } if !arr.isEmpty { return arr }
} }
// Try bundled resource(s) // Try bundled resource(s)
let bundleCandidates = [ let bundleCandidates = [
Bundle.main.url(forResource: "nostr_relays", withExtension: "csv"), Bundle.main.url(forResource: "nostr_relays", withExtension: "csv"),
Bundle.main.url(forResource: "online_relays_gps", withExtension: "csv"), Bundle.main.url(forResource: "online_relays_gps", withExtension: "csv"),
Bundle.main.url(forResource: "online_relays_gps", withExtension: "csv", subdirectory: "relays") Bundle.main.url(forResource: "online_relays_gps", withExtension: "csv", subdirectory: "relays")
].compactMap { $0 } ].compactMap { $0 }
for url in bundleCandidates { for url in bundleCandidates {
if let data = try? Data(contentsOf: url), let text = String(data: data, encoding: .utf8) { if let data = try? Data(contentsOf: url),
let text = String(data: data, encoding: .utf8) {
let arr = Self.parseCSV(text) let arr = Self.parseCSV(text)
if !arr.isEmpty { return arr } if !arr.isEmpty { return arr }
} }
} }
// Try filesystem path (development/test) // Try filesystem path (development/test)
if let cwd = FileManager.default.currentDirectoryPath as String?, if let cwd = FileManager.default.currentDirectoryPath as String?,
let data = try? Data(contentsOf: URL(fileURLWithPath: cwd).appendingPathComponent("relays/online_relays_gps.csv")), let data = try? Data(contentsOf: URL(fileURLWithPath: cwd).appendingPathComponent("relays/online_relays_gps.csv")),
let text = String(data: data, encoding: .utf8) { let text = String(data: data, encoding: .utf8) {
return Self.parseCSV(text) return Self.parseCSV(text)
} }
SecureLogger.warning("GeoRelayDirectory: no local CSV found; entries empty", category: .session) SecureLogger.warning("GeoRelayDirectory: no local CSV found; entries empty", category: .session)
return [] return []
} }
@@ -122,7 +241,6 @@ final class GeoRelayDirectory {
nonisolated static func parseCSV(_ text: String) -> [Entry] { nonisolated static func parseCSV(_ text: String) -> [Entry] {
var result: Set<Entry> = [] var result: Set<Entry> = []
let lines = text.split(whereSeparator: { $0.isNewline }) let lines = text.split(whereSeparator: { $0.isNewline })
// Skip header if present
for (idx, raw) in lines.enumerated() { for (idx, raw) in lines.enumerated() {
let line = raw.trimmingCharacters(in: .whitespacesAndNewlines) let line = raw.trimmingCharacters(in: .whitespacesAndNewlines)
if line.isEmpty { continue } if line.isEmpty { continue }
@@ -143,11 +261,76 @@ final class GeoRelayDirectory {
private func cacheURL() -> URL? { private func cacheURL() -> URL? {
do { do {
let base = try FileManager.default.url(for: .applicationSupportDirectory, in: .userDomainMask, appropriateFor: nil, create: true) let base = try FileManager.default.url(
for: .applicationSupportDirectory,
in: .userDomainMask,
appropriateFor: nil,
create: true
)
let dir = base.appendingPathComponent("bitchat", isDirectory: true) let dir = base.appendingPathComponent("bitchat", isDirectory: true)
try? FileManager.default.createDirectory(at: dir, withIntermediateDirectories: true) try? FileManager.default.createDirectory(at: dir, withIntermediateDirectories: true)
return dir.appendingPathComponent(cacheFileName) return dir.appendingPathComponent(cacheFileName)
} catch { return nil } } catch {
return nil
}
}
// MARK: - Observers & Timers
private func registerObservers() {
let center = NotificationCenter.default
let torReady = center.addObserver(
forName: .TorDidBecomeReady,
object: nil,
queue: .main
) { [weak self] _ in
guard let self else { return }
Task { @MainActor in
self.prefetchIfNeeded(force: true)
}
}
observers.append(torReady)
#if os(iOS)
let didBecomeActive = center.addObserver(
forName: UIApplication.didBecomeActiveNotification,
object: nil,
queue: .main
) { [weak self] _ in
guard let self else { return }
Task { @MainActor in
self.prefetchIfNeeded()
}
}
observers.append(didBecomeActive)
#elseif os(macOS)
let didBecomeActive = center.addObserver(
forName: NSApplication.didBecomeActiveNotification,
object: nil,
queue: .main
) { [weak self] _ in
guard let self else { return }
Task { @MainActor in
self.prefetchIfNeeded()
}
}
observers.append(didBecomeActive)
#endif
}
private func startRefreshTimer() {
refreshTimer?.invalidate()
let interval = TransportConfig.geoRelayRefreshCheckIntervalSeconds
guard interval > 0 else { return }
let timer = Timer.scheduledTimer(withTimeInterval: interval, repeats: true) { [weak self] _ in
guard let self else { return }
Task { @MainActor in
self.prefetchIfNeeded()
}
}
refreshTimer = timer
RunLoop.main.add(timer, forMode: .common)
} }
} }
+15 -15
View File
@@ -4,7 +4,7 @@ import Foundation
struct NostrEmbeddedBitChat { struct NostrEmbeddedBitChat {
/// Build a `bitchat1:` base64url-encoded BitChat packet carrying a private message for Nostr DMs. /// Build a `bitchat1:` base64url-encoded BitChat packet carrying a private message for Nostr DMs.
static func encodePMForNostr(content: String, messageID: String, recipientPeerID: String, senderPeerID: String) -> String? { static func encodePMForNostr(content: String, messageID: String, recipientPeerID: PeerID, senderPeerID: PeerID) -> String? {
// TLV-encode the private message // TLV-encode the private message
let pm = PrivateMessagePacket(messageID: messageID, content: content) let pm = PrivateMessagePacket(messageID: messageID, content: content)
guard let tlv = pm.encode() else { return nil } guard let tlv = pm.encode() else { return nil }
@@ -14,12 +14,12 @@ struct NostrEmbeddedBitChat {
payload.append(tlv) payload.append(tlv)
// Determine 8-byte recipient ID to embed // Determine 8-byte recipient ID to embed
let recipientIDHex: String = normalizeRecipientPeerID(recipientPeerID) let recipientID = normalizeRecipientPeerID(recipientPeerID)
let packet = BitchatPacket( let packet = BitchatPacket(
type: MessageType.noiseEncrypted.rawValue, type: MessageType.noiseEncrypted.rawValue,
senderID: Data(hexString: senderPeerID) ?? Data(), senderID: Data(hexString: senderPeerID.id) ?? Data(),
recipientID: Data(hexString: recipientIDHex), recipientID: Data(hexString: recipientID.id),
timestamp: UInt64(Date().timeIntervalSince1970 * 1000), timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload, payload: payload,
signature: nil, signature: nil,
@@ -31,18 +31,18 @@ struct NostrEmbeddedBitChat {
} }
/// Build a `bitchat1:` base64url-encoded BitChat packet carrying a delivery/read ack for Nostr DMs. /// Build a `bitchat1:` base64url-encoded BitChat packet carrying a delivery/read ack for Nostr DMs.
static func encodeAckForNostr(type: NoisePayloadType, messageID: String, recipientPeerID: String, senderPeerID: String) -> String? { static func encodeAckForNostr(type: NoisePayloadType, messageID: String, recipientPeerID: PeerID, senderPeerID: PeerID) -> String? {
guard type == .delivered || type == .readReceipt else { return nil } guard type == .delivered || type == .readReceipt else { return nil }
var payload = Data([type.rawValue]) var payload = Data([type.rawValue])
payload.append(Data(messageID.utf8)) payload.append(Data(messageID.utf8))
let recipientIDHex: String = normalizeRecipientPeerID(recipientPeerID) let recipientID = normalizeRecipientPeerID(recipientPeerID)
let packet = BitchatPacket( let packet = BitchatPacket(
type: MessageType.noiseEncrypted.rawValue, type: MessageType.noiseEncrypted.rawValue,
senderID: Data(hexString: senderPeerID) ?? Data(), senderID: Data(hexString: senderPeerID.id) ?? Data(),
recipientID: Data(hexString: recipientIDHex), recipientID: Data(hexString: recipientID.id),
timestamp: UInt64(Date().timeIntervalSince1970 * 1000), timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload, payload: payload,
signature: nil, signature: nil,
@@ -54,7 +54,7 @@ struct NostrEmbeddedBitChat {
} }
/// Build a `bitchat1:` ACK (delivered/read) without an embedded recipient peer ID (geohash DMs). /// Build a `bitchat1:` ACK (delivered/read) without an embedded recipient peer ID (geohash DMs).
static func encodeAckForNostrNoRecipient(type: NoisePayloadType, messageID: String, senderPeerID: String) -> String? { static func encodeAckForNostrNoRecipient(type: NoisePayloadType, messageID: String, senderPeerID: PeerID) -> String? {
guard type == .delivered || type == .readReceipt else { return nil } guard type == .delivered || type == .readReceipt else { return nil }
var payload = Data([type.rawValue]) var payload = Data([type.rawValue])
@@ -62,7 +62,7 @@ struct NostrEmbeddedBitChat {
let packet = BitchatPacket( let packet = BitchatPacket(
type: MessageType.noiseEncrypted.rawValue, type: MessageType.noiseEncrypted.rawValue,
senderID: Data(hexString: senderPeerID) ?? Data(), senderID: Data(hexString: senderPeerID.id) ?? Data(),
recipientID: nil, recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000), timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload, payload: payload,
@@ -75,7 +75,7 @@ struct NostrEmbeddedBitChat {
} }
/// Build a `bitchat1:` payload without an embedded recipient peer ID (used for geohash DMs). /// Build a `bitchat1:` payload without an embedded recipient peer ID (used for geohash DMs).
static func encodePMForNostrNoRecipient(content: String, messageID: String, senderPeerID: String) -> String? { static func encodePMForNostrNoRecipient(content: String, messageID: String, senderPeerID: PeerID) -> String? {
let pm = PrivateMessagePacket(messageID: messageID, content: content) let pm = PrivateMessagePacket(messageID: messageID, content: content)
guard let tlv = pm.encode() else { return nil } guard let tlv = pm.encode() else { return nil }
@@ -84,7 +84,7 @@ struct NostrEmbeddedBitChat {
let packet = BitchatPacket( let packet = BitchatPacket(
type: MessageType.noiseEncrypted.rawValue, type: MessageType.noiseEncrypted.rawValue,
senderID: Data(hexString: senderPeerID) ?? Data(), senderID: Data(hexString: senderPeerID.id) ?? Data(),
recipientID: nil, recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000), timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload, payload: payload,
@@ -96,11 +96,11 @@ struct NostrEmbeddedBitChat {
return "bitchat1:" + base64URLEncode(data) return "bitchat1:" + base64URLEncode(data)
} }
private static func normalizeRecipientPeerID(_ recipientPeerID: String) -> String { private static func normalizeRecipientPeerID(_ recipientPeerID: PeerID) -> PeerID {
if let maybeData = Data(hexString: recipientPeerID) { if let maybeData = Data(hexString: recipientPeerID.id) {
if maybeData.count == 32 { if maybeData.count == 32 {
// Treat as Noise static public key; derive peerID from fingerprint // Treat as Noise static public key; derive peerID from fingerprint
return PeerID(publicKey: maybeData).id return PeerID(publicKey: maybeData)
} else if maybeData.count == 8 { } else if maybeData.count == 8 {
// Already an 8-byte peer ID // Already an 8-byte peer ID
return recipientPeerID return recipientPeerID
+10
View File
@@ -906,6 +906,16 @@ struct NostrFilter: Encodable {
filter.limit = limit filter.limit = limit
return filter return filter
} }
// For location notes with neighbors: subscribe to multiple geohashes (center + neighbors)
static func geohashNotes(_ geohashes: [String], since: Date? = nil, limit: Int = 200) -> NostrFilter {
var filter = NostrFilter()
filter.kinds = [1]
filter.since = since?.timeIntervalSince1970.toInt()
filter.tagFilters = ["g": geohashes]
filter.limit = limit
return filter
}
} }
// Dynamic coding key for tag filters // Dynamic coding key for tag filters
+52 -12
View File
@@ -137,6 +137,7 @@ struct BinaryProtocol {
static let hasRecipient: UInt8 = 0x01 static let hasRecipient: UInt8 = 0x01
static let hasSignature: UInt8 = 0x02 static let hasSignature: UInt8 = 0x02
static let isCompressed: UInt8 = 0x04 static let isCompressed: UInt8 = 0x04
static let hasRoute: UInt8 = 0x08
} }
// Encode BitchatPacket to binary format // Encode BitchatPacket to binary format
@@ -160,8 +161,21 @@ struct BinaryProtocol {
} }
let lengthFieldBytes = lengthFieldSize(for: version) let lengthFieldBytes = lengthFieldSize(for: version)
let originalRoute = packet.route ?? []
if originalRoute.contains(where: { $0.isEmpty }) { return nil }
let sanitizedRoute: [Data] = originalRoute.map { hop in
if hop.count == senderIDSize { return hop }
if hop.count > senderIDSize { return Data(hop.prefix(senderIDSize)) }
var padded = hop
padded.append(Data(repeating: 0, count: senderIDSize - hop.count))
return padded
}
guard sanitizedRoute.count <= 255 else { return nil }
let hasRoute = !sanitizedRoute.isEmpty
let routeLength = hasRoute ? 1 + sanitizedRoute.count * senderIDSize : 0
let originalSizeFieldBytes = isCompressed ? lengthFieldBytes : 0 let originalSizeFieldBytes = isCompressed ? lengthFieldBytes : 0
let payloadDataSize = payload.count + originalSizeFieldBytes let payloadDataSize = routeLength + payload.count + originalSizeFieldBytes
if version == 1 && payloadDataSize > Int(UInt16.max) { return nil } if version == 1 && payloadDataSize > Int(UInt16.max) { return nil }
if version == 2 && payloadDataSize > Int(UInt32.max) { return nil } if version == 2 && payloadDataSize > Int(UInt32.max) { return nil }
@@ -185,6 +199,7 @@ struct BinaryProtocol {
if packet.recipientID != nil { flags |= Flags.hasRecipient } if packet.recipientID != nil { flags |= Flags.hasRecipient }
if packet.signature != nil { flags |= Flags.hasSignature } if packet.signature != nil { flags |= Flags.hasSignature }
if isCompressed { flags |= Flags.isCompressed } if isCompressed { flags |= Flags.isCompressed }
if hasRoute { flags |= Flags.hasRoute }
data.append(flags) data.append(flags)
if version == 2 { if version == 2 {
@@ -212,6 +227,13 @@ struct BinaryProtocol {
} }
} }
if hasRoute {
data.append(UInt8(sanitizedRoute.count))
for hop in sanitizedRoute {
data.append(hop)
}
}
if isCompressed, let originalSize = originalPayloadSize { if isCompressed, let originalSize = originalPayloadSize {
if version == 2 { if version == 2 {
let value = UInt32(originalSize) let value = UInt32(originalSize)
@@ -321,9 +343,27 @@ struct BinaryProtocol {
if recipientID == nil { return nil } if recipientID == nil { return nil }
} }
var route: [Data]? = nil
var remainingPayloadBytes = payloadLength
if (flags & Flags.hasRoute) != 0 {
guard remainingPayloadBytes >= 1, let routeCount = read8() else { return nil }
remainingPayloadBytes -= 1
if routeCount > 0 {
var hops: [Data] = []
for _ in 0..<Int(routeCount) {
guard remainingPayloadBytes >= senderIDSize,
let hop = readData(senderIDSize) else { return nil }
remainingPayloadBytes -= senderIDSize
hops.append(hop)
}
route = hops
}
}
let payload: Data let payload: Data
if isCompressed { if isCompressed {
guard payloadLength >= lengthFieldBytes else { return nil } guard remainingPayloadBytes >= lengthFieldBytes else { return nil }
let originalSize: Int let originalSize: Int
if version == 2 { if version == 2 {
guard let rawSize = read32() else { return nil } guard let rawSize = read32() else { return nil }
@@ -332,15 +372,12 @@ struct BinaryProtocol {
guard let rawSize = read16() else { return nil } guard let rawSize = read16() else { return nil }
originalSize = Int(rawSize) originalSize = Int(rawSize)
} }
// Guard to keep decompression bounded to sane BLE payload limits remainingPayloadBytes -= lengthFieldBytes
guard originalSize >= 0 && originalSize <= FileTransferLimits.maxPayloadBytes else { return nil } guard originalSize >= 0 && originalSize <= FileTransferLimits.maxFramedFileBytes else { return nil }
let compressedSize = payloadLength - lengthFieldBytes let compressedSize = remainingPayloadBytes
guard compressedSize >= 0, let compressed = readData(compressedSize) else { return nil } guard compressedSize > 0, let compressed = readData(compressedSize) else { return nil }
remainingPayloadBytes = 0
// Validate compression ratio to prevent zip bomb attacks
// Primary protection: originalSize capped at 1MB (line 336)
// Defense-in-depth: reject extreme ratios (prevents DoS via memory allocation)
guard compressedSize > 0 else { return nil }
let compressionRatio = Double(originalSize) / Double(compressedSize) let compressionRatio = Double(originalSize) / Double(compressedSize)
guard compressionRatio <= 50_000.0 else { guard compressionRatio <= 50_000.0 else {
SecureLogger.warning("🚫 Suspicious compression ratio: \(String(format: "%.0f", compressionRatio)):1", category: .security) SecureLogger.warning("🚫 Suspicious compression ratio: \(String(format: "%.0f", compressionRatio)):1", category: .security)
@@ -351,7 +388,9 @@ struct BinaryProtocol {
decompressed.count == originalSize else { return nil } decompressed.count == originalSize else { return nil }
payload = decompressed payload = decompressed
} else { } else {
guard let rawPayload = readData(payloadLength) else { return nil } guard remainingPayloadBytes >= 0,
let rawPayload = readData(remainingPayloadBytes) else { return nil }
remainingPayloadBytes = 0
payload = rawPayload payload = rawPayload
} }
@@ -371,7 +410,8 @@ struct BinaryProtocol {
payload: payload, payload: payload,
signature: signature, signature: signature,
ttl: ttl, ttl: ttl,
version: version version: version,
route: route
) )
} }
} }
+2 -2
View File
@@ -178,7 +178,7 @@ protocol BitchatDelegate: AnyObject {
// Bluetooth state updates for user notifications // Bluetooth state updates for user notifications
func didUpdateBluetoothState(_ state: CBManagerState) func didUpdateBluetoothState(_ state: CBManagerState)
func didReceivePublicMessage(from peerID: PeerID, nickname: String, content: String, timestamp: Date) func didReceivePublicMessage(from peerID: PeerID, nickname: String, content: String, timestamp: Date, messageID: String?)
} }
// Provide default implementation to make it effectively optional // Provide default implementation to make it effectively optional
@@ -195,7 +195,7 @@ extension BitchatDelegate {
// Default empty implementation // Default empty implementation
} }
func didReceivePublicMessage(from peerID: PeerID, nickname: String, content: String, timestamp: Date) { func didReceivePublicMessage(from peerID: PeerID, nickname: String, content: String, timestamp: Date, messageID: String?) {
// Default empty implementation // Default empty implementation
} }
} }
+53
View File
@@ -119,4 +119,57 @@ enum Geohash {
} }
return (latInterval.0, latInterval.1, lonInterval.0, lonInterval.1) return (latInterval.0, latInterval.1, lonInterval.0, lonInterval.1)
} }
/// Returns all 8 neighboring geohash cells at the same precision.
/// - Parameter geohash: Base32 geohash string.
/// - Returns: Array of 8 neighboring geohashes (N, NE, E, SE, S, SW, W, NW order).
static func neighbors(of geohash: String) -> [String] {
guard !geohash.isEmpty else { return [] }
let precision = geohash.count
let bounds = decodeBounds(geohash)
let center = decodeCenter(geohash)
// Calculate cell dimensions
let latHeight = bounds.latMax - bounds.latMin
let lonWidth = bounds.lonMax - bounds.lonMin
// Helper to wrap longitude around ±180
func wrapLongitude(_ lon: Double) -> Double {
var wrapped = lon
while wrapped > 180.0 { wrapped -= 360.0 }
while wrapped < -180.0 { wrapped += 360.0 }
return wrapped
}
// Helper to clamp latitude to ±90
func clampLatitude(_ lat: Double) -> Double {
return max(-90.0, min(90.0, lat))
}
// Calculate 8 neighbor centers
let neighbors: [(lat: Double, lon: Double)] = [
(center.lat + latHeight, center.lon), // N
(center.lat + latHeight, center.lon + lonWidth), // NE
(center.lat, center.lon + lonWidth), // E
(center.lat - latHeight, center.lon + lonWidth), // SE
(center.lat - latHeight, center.lon), // S
(center.lat - latHeight, center.lon - lonWidth), // SW
(center.lat, center.lon - lonWidth), // W
(center.lat + latHeight, center.lon - lonWidth) // NW
]
// Encode each neighbor, handling boundary conditions
return neighbors.compactMap { neighbor in
let lat = clampLatitude(neighbor.lat)
let lon = wrapLongitude(neighbor.lon)
// Skip if we've crossed a pole (latitude clamped to boundary)
if (neighbor.lat > 90.0 || neighbor.lat < -90.0) {
return nil
}
return encode(latitude: lat, longitude: lon, precision: precision)
}
}
} }
+14
View File
@@ -116,4 +116,18 @@ enum ChannelID: Equatable, Codable {
case .location(let ch): return ch.geohash case .location(let ch): return ch.geohash
} }
} }
var isMesh: Bool {
switch self {
case .mesh: true
case .location: false
}
}
var isLocation: Bool {
switch self {
case .mesh: false
case .location: true
}
}
} }
+26 -1
View File
@@ -6,11 +6,13 @@ struct AnnouncementPacket {
let nickname: String let nickname: String
let noisePublicKey: Data // Noise static public key (Curve25519.KeyAgreement) let noisePublicKey: Data // Noise static public key (Curve25519.KeyAgreement)
let signingPublicKey: Data // Ed25519 public key for signing let signingPublicKey: Data // Ed25519 public key for signing
let directNeighbors: [Data]? // 8-byte peer IDs
private enum TLVType: UInt8 { private enum TLVType: UInt8 {
case nickname = 0x01 case nickname = 0x01
case noisePublicKey = 0x02 case noisePublicKey = 0x02
case signingPublicKey = 0x03 case signingPublicKey = 0x03
case directNeighbors = 0x04
} }
func encode() -> Data? { func encode() -> Data? {
@@ -35,6 +37,16 @@ struct AnnouncementPacket {
data.append(TLVType.signingPublicKey.rawValue) data.append(TLVType.signingPublicKey.rawValue)
data.append(UInt8(signingPublicKey.count)) data.append(UInt8(signingPublicKey.count))
data.append(signingPublicKey) data.append(signingPublicKey)
// TLV for direct neighbors (optional)
if let neighbors = directNeighbors, !neighbors.isEmpty {
let neighborsData = neighbors.prefix(10).reduce(Data()) { $0 + $1 }
if !neighborsData.isEmpty && neighborsData.count % 8 == 0 {
data.append(TLVType.directNeighbors.rawValue)
data.append(UInt8(neighborsData.count))
data.append(neighborsData)
}
}
return data return data
} }
@@ -44,6 +56,7 @@ struct AnnouncementPacket {
var nickname: String? var nickname: String?
var noisePublicKey: Data? var noisePublicKey: Data?
var signingPublicKey: Data? var signingPublicKey: Data?
var directNeighbors: [Data]?
while offset + 2 <= data.count { while offset + 2 <= data.count {
let typeRaw = data[offset] let typeRaw = data[offset]
@@ -63,6 +76,17 @@ struct AnnouncementPacket {
noisePublicKey = Data(value) noisePublicKey = Data(value)
case .signingPublicKey: case .signingPublicKey:
signingPublicKey = Data(value) signingPublicKey = Data(value)
case .directNeighbors:
if length > 0 && length % 8 == 0 {
var neighbors = [Data]()
let count = length / 8
for i in 0..<count {
let start = value.startIndex + i * 8
let end = start + 8
neighbors.append(Data(value[start..<end]))
}
directNeighbors = neighbors
}
} }
} else { } else {
// Unknown TLV; skip (tolerant decoder for forward compatibility) // Unknown TLV; skip (tolerant decoder for forward compatibility)
@@ -74,7 +98,8 @@ struct AnnouncementPacket {
return AnnouncementPacket( return AnnouncementPacket(
nickname: nickname, nickname: nickname,
noisePublicKey: noisePublicKey, noisePublicKey: noisePublicKey,
signingPublicKey: signingPublicKey signingPublicKey: signingPublicKey,
directNeighbors: directNeighbors
) )
} }
} }
File diff suppressed because it is too large Load Diff
+195
View File
@@ -0,0 +1,195 @@
//
// MimeType.swift
// bitchat
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import UniformTypeIdentifiers
// MARK: - Extensions for missing UTTypes
extension UTType {
static let webP = UTType(importedAs: "image/webp")
static let aac = UTType(importedAs: "audio/aac")
static let m4a = UTType(importedAs: "audio/m4a")
static let ogg = UTType(importedAs: "audio/ogg")
}
// MARK: - MimeType Enum
enum MimeType: CaseIterable, Hashable {
case jpeg
case jpg
case png
case gif
case webp
case mp4Audio
case m4a
case aac
case mpeg
case mp3
case wav
case xWav
case ogg
case pdf
case octetStream
var utType: UTType {
switch self {
case .jpeg, .jpg: .jpeg
case .png: .png
case .gif: .gif
case .webp: .webP
case .aac: .aac
case .m4a: .m4a
case .mp4Audio: .mpeg4Audio
case .mp3, .mpeg: .mp3
case .wav, .xWav: .wav
case .ogg: .ogg
case .pdf: .pdf
case .octetStream: .data
}
}
var category: Category {
switch self {
case .jpeg, .jpg, .png, .gif, .webp:
return .image
case .aac, .m4a, .mp4Audio, .mpeg, .mp3, .wav, .xWav, .ogg:
return .audio
case .pdf, .octetStream:
return .file
}
}
var mimeString: String {
switch self {
case .jpeg, .jpg: "image/jpeg"
case .png: "image/png"
case .gif: "image/gif"
case .webp: "image/webp"
case .mp4Audio: "audio/mp4"
case .m4a: "audio/m4a"
case .aac: "audio/aac"
case .mpeg: "audio/mpeg"
case .mp3: "audio/mp3"
case .wav: "audio/wav"
case .xWav: "audio/x-wav"
case .ogg: "audio/ogg"
case .pdf: "application/pdf"
case .octetStream: "application/octet-stream"
}
}
var defaultExtension: String {
switch self {
case .jpeg, .jpg: "jpg"
case .png: "png"
case .webp: "webp"
case .gif: "gif"
case .mp4Audio, .m4a, .aac: "m4a"
case .mpeg, .mp3: "mp3"
case .wav, .xWav: "wav"
case .ogg: "ogg"
case .pdf: "pdf"
case .octetStream: "bin"
}
}
static var allowed: Set<MimeType> = [
.jpeg, .jpg, .png, .gif, .webp,
.mp4Audio, .m4a, .aac, .mpeg, .mp3,
.wav, .xWav, .ogg,
.pdf, .octetStream
]
var isAllowed: Bool {
Self.allowed.contains(self)
}
// MARK: - Byte signature validation
func matches(data: Data) -> Bool {
guard !data.isEmpty else { return false }
// Generic type skip validation
if self == .octetStream { return true }
switch self {
case .jpeg, .jpg:
return data.count >= 3 && data[0] == 0xFF && data[1] == 0xD8 && data[2] == 0xFF
case .png:
return data.count >= 8 &&
data[0] == 0x89 && data[1] == 0x50 && data[2] == 0x4E && data[3] == 0x47 &&
data[4] == 0x0D && data[5] == 0x0A && data[6] == 0x1A && data[7] == 0x0A
case .gif:
return data.count >= 6 && data[0] == 0x47 && data[1] == 0x49 && data[2] == 0x46 &&
data[3] == 0x38 && (data[4] == 0x37 || data[4] == 0x39) && data[5] == 0x61
case .webp:
return data.count >= 12 &&
data[0] == 0x52 && data[1] == 0x49 && data[2] == 0x46 && data[3] == 0x46 &&
data[8] == 0x57 && data[9] == 0x45 && data[10] == 0x42 && data[11] == 0x50
case .m4a, .mp4Audio, .aac:
// AVAudioRecorder output varies by platform - be lenient
// Security: size already capped + sandboxed execution
return data.count > 100
case .mpeg, .mp3:
if data.count >= 3 && data[0] == 0x49 && data[1] == 0x44 && data[2] == 0x33 {
return true // ID3 header
}
return data.count >= 2 && data[0] == 0xFF && (data[1] & 0xE0) == 0xE0
case .wav, .xWav:
return data.count >= 12 &&
data[0] == 0x52 && data[1] == 0x49 && data[2] == 0x46 && data[3] == 0x46 &&
data[8] == 0x57 && data[9] == 0x41 && data[10] == 0x56 && data[11] == 0x45
case .ogg:
return data.count >= 4 &&
data[0] == 0x4F && data[1] == 0x67 && data[2] == 0x67 && data[3] == 0x53
case .pdf:
return data.count >= 4 &&
data[0] == 0x25 && data[1] == 0x50 && data[2] == 0x44 && data[3] == 0x46
default:
return false
}
}
// MARK: - Convenience Initializers
init?(_ mimeString: String?) {
guard let mimeString else { return nil }
let normalized = mimeString.lowercased()
// Direct match with our canonical list
if let match = MimeType.allCases.first(where: { $0.mimeString == normalized }) {
self = match
return
}
// Let UTType normalize aliases like "image/jpg", "audio/x-wav", etc.
if let type = UTType(mimeType: normalized),
let match = MimeType.allCases.first(where: { type.conforms(to: $0.utType) }) {
self = match
return
}
return nil
}
}
extension MimeType {
enum Category: String {
case audio, image, file
}
}
+6 -24
View File
@@ -65,14 +65,11 @@ final class CommandProcessor {
case "/unfav": case "/unfav":
if inGeoPublic || inGeoDM { return .error(message: "favorites are only for mesh peers in #mesh") } if inGeoPublic || inGeoDM { return .error(message: "favorites are only for mesh peers in #mesh") }
return handleFavorite(args, add: false) return handleFavorite(args, add: false)
//
case "/help", "/h":
return .error(message: "unknown command: \(cmd)")
default: default:
return .error(message: "unknown command: \(cmd)") return .error(message: "unknown command: \(cmd)")
} }
} }
// MARK: - Command Handlers // MARK: - Command Handlers
private func handleMessage(_ args: String) -> CommandResult { private func handleMessage(_ args: String) -> CommandResult {
@@ -148,9 +145,9 @@ final class CommandProcessor {
if chatViewModel?.selectedPrivateChatPeer != nil { if chatViewModel?.selectedPrivateChatPeer != nil {
// In private chat // In private chat
if let peerNickname = meshService?.peerNickname(peerID: PeerID(str: targetPeerID)) { if let peerNickname = meshService?.peerNickname(peerID: targetPeerID) {
let personalMessage = "* \(emoji) \(myNickname) \(action) you\(suffix) *" let personalMessage = "* \(emoji) \(myNickname) \(action) you\(suffix) *"
meshService?.sendPrivateMessage(personalMessage, to: PeerID(str: targetPeerID), meshService?.sendPrivateMessage(personalMessage, to: targetPeerID,
recipientNickname: peerNickname, recipientNickname: peerNickname,
messageID: UUID().uuidString) messageID: UUID().uuidString)
// Also add a local system message so the sender sees a natural-language confirmation // Also add a local system message so the sender sees a natural-language confirmation
@@ -214,7 +211,7 @@ final class CommandProcessor {
let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName
if let peerID = chatViewModel?.getPeerIDForNickname(nickname), if let peerID = chatViewModel?.getPeerIDForNickname(nickname),
let fingerprint = meshService?.getFingerprint(for: PeerID(str: peerID)) { let fingerprint = meshService?.getFingerprint(for: peerID) {
if identityManager.isBlocked(fingerprint: fingerprint) { if identityManager.isBlocked(fingerprint: fingerprint) {
return .success(message: "\(nickname) is already blocked") return .success(message: "\(nickname) is already blocked")
} }
@@ -258,7 +255,7 @@ final class CommandProcessor {
let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName
if let peerID = chatViewModel?.getPeerIDForNickname(nickname), if let peerID = chatViewModel?.getPeerIDForNickname(nickname),
let fingerprint = meshService?.getFingerprint(for: PeerID(str: peerID)) { let fingerprint = meshService?.getFingerprint(for: peerID) {
if !identityManager.isBlocked(fingerprint: fingerprint) { if !identityManager.isBlocked(fingerprint: fingerprint) {
return .success(message: "\(nickname) is not blocked") return .success(message: "\(nickname) is not blocked")
} }
@@ -285,7 +282,7 @@ final class CommandProcessor {
let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName let nickname = targetName.hasPrefix("@") ? String(targetName.dropFirst()) : targetName
guard let peerID = chatViewModel?.getPeerIDForNickname(nickname), guard let peerID = chatViewModel?.getPeerIDForNickname(nickname),
let noisePublicKey = Data(hexString: peerID) else { let noisePublicKey = Data(hexString: peerID.id) else {
return .error(message: "can't find peer: \(nickname)") return .error(message: "can't find peer: \(nickname)")
} }
@@ -311,19 +308,4 @@ final class CommandProcessor {
} }
} }
private func handleHelp() -> CommandResult {
let helpText = """
commands:
/msg @name - start private chat
/who - list who's online
/clear - clear messages
/hug @name - send a hug
/slap @name - slap with a trout
/fav @name - add to favorites
/unfav @name - remove from favorites
/block @name - block
/unblock @name - unblock
"""
return .success(message: helpText)
}
} }
@@ -216,15 +216,4 @@ final class GeohashBookmarksStore: ObservableObject {
} }
} }
#endif #endif
#if DEBUG
/// Testing-only reset helper
func _resetForTesting() {
bookmarks.removeAll()
membership.removeAll()
bookmarkNames.removeAll()
persist()
persistNames()
}
#endif
} }
-28
View File
@@ -27,34 +27,6 @@ final class KeychainManager: KeychainManagerProtocol {
private let service = BitchatApp.bundleID private let service = BitchatApp.bundleID
private let appGroup = "group.\(BitchatApp.bundleID)" private let appGroup = "group.\(BitchatApp.bundleID)"
private func isSandboxed() -> Bool {
#if os(macOS)
// More robust sandbox detection using multiple methods
// Method 1: Check environment variable (can be spoofed)
let environment = ProcessInfo.processInfo.environment
let hasEnvVar = environment["APP_SANDBOX_CONTAINER_ID"] != nil
// Method 2: Check if we can access a path outside sandbox
let homeDir = FileManager.default.homeDirectoryForCurrentUser
let testPath = homeDir.appendingPathComponent("../../../tmp/bitchat_sandbox_test_\(UUID().uuidString)")
let canWriteOutsideSandbox = FileManager.default.createFile(atPath: testPath.path, contents: nil, attributes: nil)
if canWriteOutsideSandbox {
try? FileManager.default.removeItem(at: testPath)
}
// Method 3: Check container path
let containerPath = FileManager.default.urls(for: .libraryDirectory, in: .userDomainMask).first?.path ?? ""
let hasContainerPath = containerPath.contains("/Containers/")
// If any method indicates sandbox, we consider it sandboxed
return hasEnvVar || !canWriteOutsideSandbox || hasContainerPath
#else
// iOS is always sandboxed
return true
#endif
}
// MARK: - Identity Keys // MARK: - Identity Keys
func saveIdentityKey(_ keyData: Data, forKey key: String) -> Bool { func saveIdentityKey(_ keyData: Data, forKey key: String) -> Bool {
@@ -64,7 +64,9 @@ final class LocationChannelManager: NSObject, CLLocationManagerDelegate, Observa
switch status { switch status {
case .authorizedAlways, .authorizedWhenInUse, .authorized: case .authorizedAlways, .authorizedWhenInUse, .authorized:
break // will compute from location break // will compute from location
default: case .notDetermined, .restricted, .denied:
fallthrough
@unknown default:
if case .location(let ch) = selectedChannel { if case .location(let ch) = selectedChannel {
teleported = teleportedSet.contains(ch.geohash) teleported = teleportedSet.contains(ch.geohash)
} }
-104
View File
@@ -1,104 +0,0 @@
import BitLogger
import Foundation
struct LocationNotesCounterDependencies {
typealias RelayLookup = @MainActor (_ geohash: String, _ count: Int) -> [String]
typealias Subscribe = @MainActor (_ filter: NostrFilter, _ id: String, _ relays: [String], _ handler: @escaping (NostrEvent) -> Void, _ onEOSE: (() -> Void)?) -> Void
typealias Unsubscribe = @MainActor (_ id: String) -> Void
var relayLookup: RelayLookup
var subscribe: Subscribe
var unsubscribe: Unsubscribe
static let live = LocationNotesCounterDependencies(
relayLookup: { geohash, count in
GeoRelayDirectory.shared.closestRelays(toGeohash: geohash, count: count)
},
subscribe: { filter, id, relays, handler, onEOSE in
NostrRelayManager.shared.subscribe(
filter: filter,
id: id,
relayUrls: relays,
handler: handler,
onEOSE: onEOSE
)
},
unsubscribe: { id in
NostrRelayManager.shared.unsubscribe(id: id)
}
)
}
/// Lightweight background counter for location notes (kind 1) at building-level geohash (8 chars).
@MainActor
final class LocationNotesCounter: ObservableObject {
static let shared = LocationNotesCounter()
@Published private(set) var geohash: String? = nil
@Published private(set) var count: Int? = 0
@Published private(set) var initialLoadComplete: Bool = false
@Published private(set) var relayAvailable: Bool = true
private var subscriptionID: String? = nil
private var noteIDs = Set<String>()
private let dependencies: LocationNotesCounterDependencies
private init(dependencies: LocationNotesCounterDependencies = .live) {
self.dependencies = dependencies
}
init(testDependencies: LocationNotesCounterDependencies) {
self.dependencies = testDependencies
}
func subscribe(geohash gh: String) {
let norm = gh.lowercased()
if geohash == norm, subscriptionID != nil { return }
// Validate geohash (building-level precision: 8 chars)
guard Geohash.isValidBuildingGeohash(norm) else {
SecureLogger.warning("LocationNotesCounter: rejecting invalid geohash '\(norm)' (expected 8 valid base32 chars)", category: .session)
return
}
// Unsubscribe previous without clearing count to avoid flicker
if let sub = subscriptionID { dependencies.unsubscribe(sub) }
subscriptionID = nil
geohash = norm
noteIDs.removeAll()
initialLoadComplete = false
relayAvailable = true
// Subscribe only to the building geohash (precision 8)
let subID = "locnotes-count-\(norm)-\(UUID().uuidString.prefix(6))"
let relays = dependencies.relayLookup(norm, TransportConfig.nostrGeoRelayCount)
guard !relays.isEmpty else {
relayAvailable = false
initialLoadComplete = true
count = 0
SecureLogger.warning("LocationNotesCounter: no geo relays for geohash=\(norm)", category: .session)
return
}
subscriptionID = subID
let filter = NostrFilter.geohashNotes(norm, since: nil, limit: 200)
dependencies.subscribe(filter, subID, relays, { [weak self] event in
guard let self = self else { return }
guard event.kind == NostrProtocol.EventKind.textNote.rawValue else { return }
guard event.tags.contains(where: { $0.count >= 2 && $0[0].lowercased() == "g" && $0[1].lowercased() == norm }) else { return }
if !self.noteIDs.contains(event.id) {
self.noteIDs.insert(event.id)
self.count = self.noteIDs.count
}
}, { [weak self] in
self?.initialLoadComplete = true
})
}
func cancel() {
if let sub = subscriptionID { dependencies.unsubscribe(sub) }
subscriptionID = nil
geohash = nil
count = 0
noteIDs.removeAll()
relayAvailable = true
}
}
+12 -4
View File
@@ -163,14 +163,22 @@ final class LocationNotesManager: ObservableObject {
subscriptionID = subID subscriptionID = subID
initialLoadComplete = false initialLoadComplete = false
// For persistent notes, allow relays to return recent history without an aggressive time cutoff
let filter = NostrFilter.geohashNotes(geohash, since: nil, limit: 200) // Subscribe to center + 8 neighbors (± 1 grid)
let neighbors = Geohash.neighbors(of: geohash)
let allGeohashes = [geohash] + neighbors
let filter = NostrFilter.geohashNotes(allGeohashes, since: nil, limit: 200)
// Build a set of valid geohashes for tag matching (includes all 9 cells)
let validGeohashes = Set(allGeohashes.map { $0.lowercased() })
dependencies.subscribe(filter, subID, relays, { [weak self] event in dependencies.subscribe(filter, subID, relays, { [weak self] event in
guard let self = self else { return } guard let self = self else { return }
guard event.kind == NostrProtocol.EventKind.textNote.rawValue else { return } guard event.kind == NostrProtocol.EventKind.textNote.rawValue else { return }
// Ensure matching tag // Ensure matching tag - accept any of our 9 geohashes
guard event.tags.contains(where: { $0.count >= 2 && $0[0].lowercased() == "g" && $0[1].lowercased() == self.geohash }) else { return } guard event.tags.contains(where: { tag in
tag.count >= 2 && tag[0].lowercased() == "g" && validGeohashes.contains(tag[1].lowercased())
}) else { return }
guard !self.noteIDs.contains(event.id) else { return } guard !self.noteIDs.contains(event.id) else { return }
self.noteIDs.insert(event.id) self.noteIDs.insert(event.id)
let nick = event.tags.first(where: { $0.first?.lowercased() == "n" && $0.count >= 2 })?.dropFirst().first let nick = event.tags.first(where: { $0.first?.lowercased() == "n" && $0.count >= 2 })?.dropFirst().first
+120
View File
@@ -0,0 +1,120 @@
import Foundation
/// Tracks observed mesh topology and computes hop-by-hop routes.
final class MeshTopologyTracker {
private typealias RoutingID = Data
private let queue = DispatchQueue(label: "mesh.topology", attributes: .concurrent)
private let hopSize = 8
private var adjacency: [RoutingID: Set<RoutingID>] = [:]
func reset() {
queue.sync(flags: .barrier) {
self.adjacency.removeAll()
}
}
func recordDirectLink(between a: Data?, and b: Data?) {
guard let left = sanitize(a), let right = sanitize(b), left != right else { return }
queue.sync(flags: .barrier) {
var setA = self.adjacency[left] ?? []
setA.insert(right)
self.adjacency[left] = setA
var setB = self.adjacency[right] ?? []
setB.insert(left)
self.adjacency[right] = setB
}
}
func removeDirectLink(between a: Data?, and b: Data?) {
guard let left = sanitize(a), let right = sanitize(b), left != right else { return }
queue.sync(flags: .barrier) {
if var setA = self.adjacency[left] {
setA.remove(right)
self.adjacency[left] = setA.isEmpty ? nil : setA
}
if var setB = self.adjacency[right] {
setB.remove(left)
self.adjacency[right] = setB.isEmpty ? nil : setB
}
}
}
func removePeer(_ data: Data?) {
guard let peer = sanitize(data) else { return }
queue.sync(flags: .barrier) {
guard let neighbors = self.adjacency.removeValue(forKey: peer) else { return }
for neighbor in neighbors {
if var set = self.adjacency[neighbor] {
set.remove(peer)
self.adjacency[neighbor] = set.isEmpty ? nil : set
}
}
}
}
func recordRoute(_ hops: [Data]) {
let sanitized = hops.compactMap { sanitize($0) }
guard sanitized.count >= 2 else { return }
queue.sync(flags: .barrier) {
for idx in 0..<(sanitized.count - 1) {
let left = sanitized[idx]
let right = sanitized[idx + 1]
guard left != right else { continue }
var setA = self.adjacency[left] ?? []
setA.insert(right)
self.adjacency[left] = setA
var setB = self.adjacency[right] ?? []
setB.insert(left)
self.adjacency[right] = setB
}
}
}
func computeRoute(from start: Data?, to goal: Data?, maxHops: Int = 255) -> [Data]? {
guard let source = sanitize(start), let target = sanitize(goal) else { return nil }
if source == target { return [source] }
let graph = queue.sync { adjacency }
guard graph[source] != nil, graph[target] != nil else { return nil }
var visited: Set<RoutingID> = [source]
var queuePaths: [[RoutingID]] = [[source]]
var index = 0
while index < queuePaths.count {
let path = queuePaths[index]
index += 1
guard path.count <= maxHops else { continue }
guard let last = path.last, let neighbors = graph[last] else { continue }
for neighbor in neighbors {
if visited.contains(neighbor) { continue }
var nextPath = path
nextPath.append(neighbor)
if neighbor == target { return nextPath }
if nextPath.count <= maxHops {
queuePaths.append(nextPath)
}
visited.insert(neighbor)
}
}
return nil
}
// MARK: - Helpers
private func sanitize(_ data: Data?) -> Data? {
guard var value = data, !value.isEmpty else { return nil }
if value.count > hopSize {
value = Data(value.prefix(hopSize))
} else if value.count < hopSize {
value.append(Data(repeating: 0, count: hopSize - value.count))
}
return value
}
}
@@ -177,18 +177,18 @@ final class NoiseEncryptionService {
private let rekeyCheckInterval: TimeInterval = 60.0 // Check every minute private let rekeyCheckInterval: TimeInterval = 60.0 // Check every minute
// Callbacks // Callbacks
private var onPeerAuthenticatedHandlers: [((String, String) -> Void)] = [] // Array of handlers for peer authentication private var onPeerAuthenticatedHandlers: [((PeerID, String) -> Void)] = [] // Array of handlers for peer authentication
var onHandshakeRequired: ((PeerID) -> Void)? // peerID needs handshake var onHandshakeRequired: ((PeerID) -> Void)? // peerID needs handshake
// Add a handler for peer authentication // Add a handler for peer authentication
func addOnPeerAuthenticatedHandler(_ handler: @escaping (String, String) -> Void) { func addOnPeerAuthenticatedHandler(_ handler: @escaping (PeerID, String) -> Void) {
serviceQueue.async(flags: .barrier) { [weak self] in serviceQueue.async(flags: .barrier) { [weak self] in
self?.onPeerAuthenticatedHandlers.append(handler) self?.onPeerAuthenticatedHandlers.append(handler)
} }
} }
// Legacy support - setting this will add to the handlers array // Legacy support - setting this will add to the handlers array
var onPeerAuthenticated: ((String, String) -> Void)? { var onPeerAuthenticated: ((PeerID, String) -> Void)? {
get { nil } // Always return nil for backward compatibility get { nil } // Always return nil for backward compatibility
set { set {
if let handler = newValue { if let handler = newValue {
@@ -546,7 +546,7 @@ final class NoiseEncryptionService {
// Notify all handlers about authentication // Notify all handlers about authentication
serviceQueue.async { [weak self] in serviceQueue.async { [weak self] in
self?.onPeerAuthenticatedHandlers.forEach { handler in self?.onPeerAuthenticatedHandlers.forEach { handler in
handler(peerID.id, fingerprint) handler(peerID, fingerprint)
} }
} }
} }
+7 -7
View File
@@ -82,7 +82,7 @@ final class NostrTransport: Transport {
SecureLogger.error("NostrTransport: failed to decode npub -> hex: \(error)", category: .session) SecureLogger.error("NostrTransport: failed to decode npub -> hex: \(error)", category: .session)
return return
} }
guard let embedded = NostrEmbeddedBitChat.encodePMForNostr(content: content, messageID: messageID, recipientPeerID: peerID.id, senderPeerID: senderPeerID.id) else { guard let embedded = NostrEmbeddedBitChat.encodePMForNostr(content: content, messageID: messageID, recipientPeerID: peerID, senderPeerID: senderPeerID) else {
SecureLogger.error("NostrTransport: failed to embed PM packet", category: .session) SecureLogger.error("NostrTransport: failed to embed PM packet", category: .session)
return return
} }
@@ -114,7 +114,7 @@ final class NostrTransport: Transport {
guard hrp == "npub" else { return } guard hrp == "npub" else { return }
recipientHex = data.hexEncodedString() recipientHex = data.hexEncodedString()
} catch { return } } catch { return }
guard let embedded = NostrEmbeddedBitChat.encodePMForNostr(content: content, messageID: UUID().uuidString, recipientPeerID: peerID.id, senderPeerID: senderPeerID.id) else { guard let embedded = NostrEmbeddedBitChat.encodePMForNostr(content: content, messageID: UUID().uuidString, recipientPeerID: peerID, senderPeerID: senderPeerID) else {
SecureLogger.error("NostrTransport: failed to embed favorite notification", category: .session) SecureLogger.error("NostrTransport: failed to embed favorite notification", category: .session)
return return
} }
@@ -139,7 +139,7 @@ final class NostrTransport: Transport {
guard hrp == "npub" else { return } guard hrp == "npub" else { return }
recipientHex = data.hexEncodedString() recipientHex = data.hexEncodedString()
} catch { return } } catch { return }
guard let ack = NostrEmbeddedBitChat.encodeAckForNostr(type: .delivered, messageID: messageID, recipientPeerID: peerID.id, senderPeerID: senderPeerID.id) else { guard let ack = NostrEmbeddedBitChat.encodeAckForNostr(type: .delivered, messageID: messageID, recipientPeerID: peerID, senderPeerID: senderPeerID) else {
SecureLogger.error("NostrTransport: failed to embed DELIVERED ack", category: .session) SecureLogger.error("NostrTransport: failed to embed DELIVERED ack", category: .session)
return return
} }
@@ -161,7 +161,7 @@ extension NostrTransport {
func sendDeliveryAckGeohash(for messageID: String, toRecipientHex recipientHex: String, from identity: NostrIdentity) { func sendDeliveryAckGeohash(for messageID: String, toRecipientHex recipientHex: String, from identity: NostrIdentity) {
Task { @MainActor in Task { @MainActor in
SecureLogger.debug("GeoDM: send DELIVERED -> recip=\(recipientHex.prefix(8))… mid=\(messageID.prefix(8))… from=\(identity.publicKeyHex.prefix(8))", category: .session) SecureLogger.debug("GeoDM: send DELIVERED -> recip=\(recipientHex.prefix(8))… mid=\(messageID.prefix(8))… from=\(identity.publicKeyHex.prefix(8))", category: .session)
guard let embedded = NostrEmbeddedBitChat.encodeAckForNostrNoRecipient(type: .delivered, messageID: messageID, senderPeerID: senderPeerID.id) else { return } guard let embedded = NostrEmbeddedBitChat.encodeAckForNostrNoRecipient(type: .delivered, messageID: messageID, senderPeerID: senderPeerID) else { return }
guard let event = try? NostrProtocol.createPrivateMessage(content: embedded, recipientPubkey: recipientHex, senderIdentity: identity) else { return } guard let event = try? NostrProtocol.createPrivateMessage(content: embedded, recipientPubkey: recipientHex, senderIdentity: identity) else { return }
NostrRelayManager.registerPendingGiftWrap(id: event.id) NostrRelayManager.registerPendingGiftWrap(id: event.id)
NostrRelayManager.shared.sendEvent(event) NostrRelayManager.shared.sendEvent(event)
@@ -171,7 +171,7 @@ extension NostrTransport {
func sendReadReceiptGeohash(_ messageID: String, toRecipientHex recipientHex: String, from identity: NostrIdentity) { func sendReadReceiptGeohash(_ messageID: String, toRecipientHex recipientHex: String, from identity: NostrIdentity) {
Task { @MainActor in Task { @MainActor in
SecureLogger.debug("GeoDM: send READ -> recip=\(recipientHex.prefix(8))… mid=\(messageID.prefix(8))… from=\(identity.publicKeyHex.prefix(8))", category: .session) SecureLogger.debug("GeoDM: send READ -> recip=\(recipientHex.prefix(8))… mid=\(messageID.prefix(8))… from=\(identity.publicKeyHex.prefix(8))", category: .session)
guard let embedded = NostrEmbeddedBitChat.encodeAckForNostrNoRecipient(type: .readReceipt, messageID: messageID, senderPeerID: senderPeerID.id) else { return } guard let embedded = NostrEmbeddedBitChat.encodeAckForNostrNoRecipient(type: .readReceipt, messageID: messageID, senderPeerID: senderPeerID) else { return }
guard let event = try? NostrProtocol.createPrivateMessage(content: embedded, recipientPubkey: recipientHex, senderIdentity: identity) else { return } guard let event = try? NostrProtocol.createPrivateMessage(content: embedded, recipientPubkey: recipientHex, senderIdentity: identity) else { return }
NostrRelayManager.registerPendingGiftWrap(id: event.id) NostrRelayManager.registerPendingGiftWrap(id: event.id)
NostrRelayManager.shared.sendEvent(event) NostrRelayManager.shared.sendEvent(event)
@@ -184,7 +184,7 @@ extension NostrTransport {
guard !recipientHex.isEmpty else { return } guard !recipientHex.isEmpty else { return }
SecureLogger.debug("GeoDM: send PM -> recip=\(recipientHex.prefix(8))… mid=\(messageID.prefix(8))… from=\(identity.publicKeyHex.prefix(8))", category: .session) SecureLogger.debug("GeoDM: send PM -> recip=\(recipientHex.prefix(8))… mid=\(messageID.prefix(8))… from=\(identity.publicKeyHex.prefix(8))", category: .session)
// Build embedded BitChat packet without recipient peer ID // Build embedded BitChat packet without recipient peer ID
guard let embedded = NostrEmbeddedBitChat.encodePMForNostrNoRecipient(content: content, messageID: messageID, senderPeerID: senderPeerID.id) else { guard let embedded = NostrEmbeddedBitChat.encodePMForNostrNoRecipient(content: content, messageID: messageID, senderPeerID: senderPeerID) else {
SecureLogger.error("NostrTransport: failed to embed geohash PM packet", category: .session) SecureLogger.error("NostrTransport: failed to embed geohash PM packet", category: .session)
return return
} }
@@ -223,7 +223,7 @@ extension NostrTransport {
guard hrp == "npub" else { scheduleNextReadAck(); return } guard hrp == "npub" else { scheduleNextReadAck(); return }
recipientHex = data.hexEncodedString() recipientHex = data.hexEncodedString()
} catch { scheduleNextReadAck(); return } } catch { scheduleNextReadAck(); return }
guard let ack = NostrEmbeddedBitChat.encodeAckForNostr(type: .readReceipt, messageID: item.receipt.originalMessageID, recipientPeerID: item.peerID.id, senderPeerID: senderPeerID.id) else { guard let ack = NostrEmbeddedBitChat.encodeAckForNostr(type: .readReceipt, messageID: item.receipt.originalMessageID, recipientPeerID: item.peerID, senderPeerID: senderPeerID) else {
SecureLogger.error("NostrTransport: failed to embed READ ack", category: .session) SecureLogger.error("NostrTransport: failed to embed READ ack", category: .session)
scheduleNextReadAck(); return scheduleNextReadAck(); return
} }
+32 -43
View File
@@ -29,28 +29,30 @@ final class NotificationService {
} }
} }
func sendLocalNotification(title: String, body: String, identifier: String, userInfo: [String: Any]? = nil) { func sendLocalNotification(
// For now, skip app state check entirely to avoid thread issues title: String,
// The NotificationDelegate will handle foreground presentation body: String,
DispatchQueue.main.async { identifier: String,
let content = UNMutableNotificationContent() userInfo: [String: Any]? = nil,
content.title = title interruptionLevel: UNNotificationInterruptionLevel = .active
content.body = body ) {
content.sound = .default let content = UNMutableNotificationContent()
if let userInfo = userInfo { content.title = title
content.userInfo = userInfo content.body = body
} content.sound = .default
content.interruptionLevel = interruptionLevel
let request = UNNotificationRequest(
identifier: identifier, if let userInfo = userInfo {
content: content, content.userInfo = userInfo
trigger: nil // Deliver immediately
)
UNUserNotificationCenter.current().add(request) { _ in
// Notification added
}
} }
let request = UNNotificationRequest(
identifier: identifier,
content: content,
trigger: nil // Deliver immediately
)
UNUserNotificationCenter.current().add(request)
} }
func sendMentionNotification(from sender: String, message: String) { func sendMentionNotification(from sender: String, message: String) {
@@ -61,11 +63,11 @@ final class NotificationService {
sendLocalNotification(title: title, body: body, identifier: identifier) sendLocalNotification(title: title, body: body, identifier: identifier)
} }
func sendPrivateMessageNotification(from sender: String, message: String, peerID: String) { func sendPrivateMessageNotification(from sender: String, message: String, peerID: PeerID) {
let title = "🔒 DM from \(sender)" let title = "🔒 DM from \(sender)"
let body = message let body = message
let identifier = "private-\(UUID().uuidString)" let identifier = "private-\(UUID().uuidString)"
let userInfo = ["peerID": peerID, "senderName": sender] let userInfo = ["peerID": peerID.id, "senderName": sender]
sendLocalNotification(title: title, body: body, identifier: identifier, userInfo: userInfo) sendLocalNotification(title: title, body: body, identifier: identifier, userInfo: userInfo)
} }
@@ -83,25 +85,12 @@ final class NotificationService {
let title = "👥 bitchatters nearby!" let title = "👥 bitchatters nearby!"
let body = peerCount == 1 ? "1 person around" : "\(peerCount) people around" let body = peerCount == 1 ? "1 person around" : "\(peerCount) people around"
let identifier = "network-available-\(Date().timeIntervalSince1970)" let identifier = "network-available-\(Date().timeIntervalSince1970)"
// For network notifications, we want to show them even in foreground sendLocalNotification(
// No app state check - let the notification delegate handle presentation title: title,
DispatchQueue.main.async { body: body,
let content = UNMutableNotificationContent() identifier: identifier,
content.title = title interruptionLevel: .timeSensitive
content.body = body )
content.sound = .default
content.interruptionLevel = .timeSensitive // Make it more prominent
let request = UNNotificationRequest(
identifier: identifier,
content: content,
trigger: nil // Deliver immediately
)
UNUserNotificationCenter.current().add(request) { _ in
// Notification added
}
}
} }
} }
@@ -6,10 +6,19 @@
// For more information, see <https://unlicense.org> // For more information, see <https://unlicense.org>
// //
import BitLogger
import Foundation import Foundation
struct NotificationStreamAssembler { struct NotificationStreamAssembler {
private var buffer = Data() private var buffer = Data()
private var pendingFrameStartedAt: DispatchTime?
private var pendingFrameExpectedLength: Int = 0
private mutating func resetState() {
buffer.removeAll(keepingCapacity: false)
pendingFrameStartedAt = nil
pendingFrameExpectedLength = 0
}
mutating func append(_ chunk: Data) -> (frames: [Data], droppedPrefixes: [UInt8], reset: Bool) { mutating func append(_ chunk: Data) -> (frames: [Data], droppedPrefixes: [UInt8], reset: Bool) {
guard !chunk.isEmpty else { return ([], [], false) } guard !chunk.isEmpty else { return ([], [], false) }
@@ -18,64 +27,107 @@ struct NotificationStreamAssembler {
var frames: [Data] = [] var frames: [Data] = []
var dropped: [UInt8] = [] var dropped: [UInt8] = []
var reset = false var didReset = false
let maxFrameLength = TransportConfig.blePendingWriteBufferCapBytes let now = DispatchTime.now()
let maxFrameLength = TransportConfig.bleNotificationAssemblerHardCapBytes
let minimumFramePrefix = BinaryProtocol.v1HeaderSize + BinaryProtocol.senderIDSize
let minHeaderBytes = 14 // version + type + ttl + timestamp(8) + flags + length(2) if buffer.count > TransportConfig.bleNotificationAssemblerHardCapBytes {
let minFramePrefix = minHeaderBytes + BinaryProtocol.senderIDSize SecureLogger.error("❌ Notification assembler overflow (\(buffer.count) bytes); dropping partial frame", category: .session)
resetState()
return ([], [], true)
}
while buffer.count >= minFramePrefix { while buffer.count >= minimumFramePrefix {
guard let first = buffer.first else { break } guard let version = buffer.first else { break }
if first != 1 { guard version == 1 || version == 2 else {
dropped.append(buffer.removeFirst()) dropped.append(buffer.removeFirst())
pendingFrameStartedAt = nil
pendingFrameExpectedLength = 0
continue continue
} }
guard buffer.count >= minHeaderBytes else { break } guard let headerSize = BinaryProtocol.headerSize(for: version) else {
dropped.append(buffer.removeFirst())
pendingFrameStartedAt = nil
pendingFrameExpectedLength = 0
continue
}
let framePrefix = headerSize + BinaryProtocol.senderIDSize
guard buffer.count >= framePrefix else { break }
let headerBytes = Array(buffer.prefix(minFramePrefix)) let flagsIndex = buffer.startIndex + BinaryProtocol.Offsets.flags
guard headerBytes.count == minFramePrefix else { break } guard flagsIndex < buffer.endIndex else { break }
let flags = buffer[flagsIndex]
let flags = headerBytes[11]
let hasRecipient = (flags & BinaryProtocol.Flags.hasRecipient) != 0 let hasRecipient = (flags & BinaryProtocol.Flags.hasRecipient) != 0
let hasSignature = (flags & BinaryProtocol.Flags.hasSignature) != 0 let hasSignature = (flags & BinaryProtocol.Flags.hasSignature) != 0
let payloadLen = (Int(headerBytes[12]) << 8) | Int(headerBytes[13]) let isCompressed = (flags & BinaryProtocol.Flags.isCompressed) != 0
var frameLength = minFramePrefix + payloadLen let lengthOffset = 12
let payloadLength: Int
if version == 2 {
let lengthIndex = buffer.startIndex + lengthOffset
payloadLength =
(Int(buffer[lengthIndex]) << 24) |
(Int(buffer[lengthIndex + 1]) << 16) |
(Int(buffer[lengthIndex + 2]) << 8) |
Int(buffer[lengthIndex + 3])
} else {
let lengthIndex = buffer.startIndex + lengthOffset
payloadLength = (Int(buffer[lengthIndex]) << 8) | Int(buffer[lengthIndex + 1])
}
var frameLength = framePrefix + payloadLength
if hasRecipient { frameLength += BinaryProtocol.recipientIDSize } if hasRecipient { frameLength += BinaryProtocol.recipientIDSize }
if hasSignature { frameLength += BinaryProtocol.signatureSize } if hasSignature { frameLength += BinaryProtocol.signatureSize }
if isCompressed {
let rawLengthFieldBytes = (version == 2) ? 4 : 2
if payloadLength < rawLengthFieldBytes {
SecureLogger.error("❌ Invalid compressed payload length (\(payloadLength))", category: .session)
resetState()
didReset = true
break
}
}
guard frameLength > 0, frameLength <= maxFrameLength else { guard frameLength > 0, frameLength <= maxFrameLength else {
buffer.removeAll() SecureLogger.error("❌ Notification frame length \(frameLength) invalid (cap=\(maxFrameLength)); resetting stream", category: .session)
reset = true resetState()
didReset = true
break break
} }
if buffer.count < frameLength { if buffer.count < frameLength {
// Check if a new frame start exists within the incomplete buffer; if so, drop leading partial bytes. let remaining = frameLength - buffer.count
if let nextStart = buffer.dropFirst().firstIndex(of: 1) { if pendingFrameStartedAt == nil || frameLength != pendingFrameExpectedLength {
let dropCount = buffer.distance(from: buffer.startIndex, to: nextStart) pendingFrameStartedAt = now
if dropCount > 0 { pendingFrameExpectedLength = frameLength
buffer.removeFirst(dropCount) } else if let started = pendingFrameStartedAt {
dropped.append(1) // treat as dropped partial start let elapsed = now.uptimeNanoseconds - started.uptimeNanoseconds
let threshold = UInt64(TransportConfig.bleAssemblerStallResetMs) * 1_000_000
if elapsed >= threshold {
SecureLogger.debug("📉 Resetting notification assembler after waiting \(remaining)B for \(TransportConfig.bleAssemblerStallResetMs)ms", category: .session)
resetState()
didReset = true
} else {
SecureLogger.debug("⌛ Waiting for remaining \(remaining)B to complete BLE frame", category: .session)
} }
} }
break break
} }
pendingFrameStartedAt = nil
pendingFrameExpectedLength = 0
let frame = Data(buffer.prefix(frameLength)) let frame = Data(buffer.prefix(frameLength))
frames.append(frame) frames.append(frame)
buffer.removeFirst(frameLength) buffer.removeFirst(frameLength)
} }
if !buffer.isEmpty, buffer.allSatisfy({ $0 == 0 }) { if !buffer.isEmpty, buffer.allSatisfy({ $0 == 0 }) {
buffer.removeAll(keepingCapacity: false) resetState()
} }
return (frames, dropped, reset) return (frames, dropped, didReset)
}
mutating func reset() {
buffer.removeAll(keepingCapacity: false)
} }
} }
+1 -1
View File
@@ -105,7 +105,7 @@ final class PrivateChatManager: ObservableObject {
// Create read receipt using the simplified method // Create read receipt using the simplified method
let receipt = ReadReceipt( let receipt = ReadReceipt(
originalMessageID: message.id, originalMessageID: message.id,
readerID: meshService?.myPeerID.id ?? "", readerID: meshService?.myPeerID ?? PeerID(str: ""),
readerNickname: meshService?.myNickname ?? "" readerNickname: meshService?.myNickname ?? ""
) )
+11
View File
@@ -13,6 +13,7 @@ struct RelayController {
senderIsSelf: Bool, senderIsSelf: Bool,
isEncrypted: Bool, isEncrypted: Bool,
isDirectedEncrypted: Bool, isDirectedEncrypted: Bool,
isFragment: Bool,
isDirectedFragment: Bool, isDirectedFragment: Bool,
isHandshake: Bool, isHandshake: Bool,
isAnnounce: Bool, isAnnounce: Bool,
@@ -36,6 +37,16 @@ struct RelayController {
return RelayDecision(shouldRelay: true, newTTL: newTTL, delayMs: delayMs) return RelayDecision(shouldRelay: true, newTTL: newTTL, delayMs: delayMs)
} }
if isFragment {
let ttlLimit = min(ttlCap, TransportConfig.bleFragmentRelayTtlCap)
guard ttlLimit > 1 else {
return RelayDecision(shouldRelay: false, newTTL: ttlLimit, delayMs: 0)
}
let newTTL = ttlLimit &- 1
let delayMs = Int.random(in: TransportConfig.bleFragmentRelayMinDelayMs...TransportConfig.bleFragmentRelayMaxDelayMs)
return RelayDecision(shouldRelay: true, newTTL: newTTL, delayMs: delayMs)
}
// TTL clamping for broadcast // TTL clamping for broadcast
// - Dense graphs: keep lower but still allow multi-hop bridging // - Dense graphs: keep lower but still allow multi-hop bridging
// - Announces get a bit more headroom // - Announces get a bit more headroom
+5
View File
@@ -45,6 +45,7 @@ protocol Transport: AnyObject {
// Messaging // Messaging
func sendMessage(_ content: String, mentions: [String]) func sendMessage(_ content: String, mentions: [String])
func sendMessage(_ content: String, mentions: [String], messageID: String, timestamp: Date)
func sendPrivateMessage(_ content: String, to peerID: PeerID, recipientNickname: String, messageID: String) func sendPrivateMessage(_ content: String, to peerID: PeerID, recipientNickname: String, messageID: String)
func sendReadReceipt(_ receipt: ReadReceipt, to peerID: PeerID) func sendReadReceipt(_ receipt: ReadReceipt, to peerID: PeerID)
func sendFavoriteNotification(to peerID: PeerID, isFavorite: Bool) func sendFavoriteNotification(to peerID: PeerID, isFavorite: Bool)
@@ -65,6 +66,10 @@ extension Transport {
func sendFileBroadcast(_ packet: BitchatFilePacket, transferId: String) {} func sendFileBroadcast(_ packet: BitchatFilePacket, transferId: String) {}
func sendFilePrivate(_ packet: BitchatFilePacket, to peerID: PeerID, transferId: String) {} func sendFilePrivate(_ packet: BitchatFilePacket, to peerID: PeerID, transferId: String) {}
func cancelTransfer(_ transferId: String) {} func cancelTransfer(_ transferId: String) {}
func sendMessage(_ content: String, mentions: [String], messageID: String, timestamp: Date) {
sendMessage(content, mentions: mentions)
}
} }
protocol TransportPeerEventsDelegate: AnyObject { protocol TransportPeerEventsDelegate: AnyObject {
+8
View File
@@ -8,6 +8,10 @@ enum TransportConfig {
static let messageTTLDefault: UInt8 = 7 // Default TTL for mesh flooding static let messageTTLDefault: UInt8 = 7 // Default TTL for mesh flooding
static let bleMaxInFlightAssemblies: Int = 128 // Cap concurrent fragment assemblies static let bleMaxInFlightAssemblies: Int = 128 // Cap concurrent fragment assemblies
static let bleHighDegreeThreshold: Int = 6 // For adaptive TTL/probabilistic relays static let bleHighDegreeThreshold: Int = 6 // For adaptive TTL/probabilistic relays
static let bleMaxConcurrentTransfers: Int = 2 // Limit simultaneous large media sends
static let bleFragmentRelayMinDelayMs: Int = 8 // Faster forwarding for media fragments
static let bleFragmentRelayMaxDelayMs: Int = 25 // Upper jitter bound for fragment relays
static let bleFragmentRelayTtlCap: UInt8 = 5 // Clamp fragment TTL to contain floods
// UI / Storage Caps // UI / Storage Caps
static let privateChatCap: Int = 1337 static let privateChatCap: Int = 1337
@@ -66,6 +70,7 @@ enum TransportConfig {
static let uiAnimationMediumSeconds: TimeInterval = 0.2 static let uiAnimationMediumSeconds: TimeInterval = 0.2
static let uiAnimationSidebarSeconds: TimeInterval = 0.25 static let uiAnimationSidebarSeconds: TimeInterval = 0.25
static let uiRecentCutoffFiveMinutesSeconds: TimeInterval = 5 * 60 static let uiRecentCutoffFiveMinutesSeconds: TimeInterval = 5 * 60
static let uiMeshEmptyConfirmationSeconds: TimeInterval = 30.0
// BLE maintenance & thresholds // BLE maintenance & thresholds
static let bleMaintenanceInterval: TimeInterval = 5.0 static let bleMaintenanceInterval: TimeInterval = 5.0
@@ -145,6 +150,9 @@ enum TransportConfig {
// Geo relay directory // Geo relay directory
static let geoRelayFetchIntervalSeconds: TimeInterval = 60 * 60 * 24 static let geoRelayFetchIntervalSeconds: TimeInterval = 60 * 60 * 24
static let geoRelayRefreshCheckIntervalSeconds: TimeInterval = 60 * 60
static let geoRelayRetryInitialSeconds: TimeInterval = 60
static let geoRelayRetryMaxSeconds: TimeInterval = 60 * 60
// BLE operational delays // BLE operational delays
static let bleInitialAnnounceDelaySeconds: TimeInterval = 0.6 static let bleInitialAnnounceDelaySeconds: TimeInterval = 0.6
+3 -3
View File
@@ -235,10 +235,10 @@ final class UnifiedPeerService: ObservableObject, TransportPeerEventsDelegate {
} }
/// Get peer ID for nickname /// Get peer ID for nickname
func getPeerID(for nickname: String) -> String? { func getPeerID(for nickname: String) -> PeerID? {
for peer in peers { for peer in peers {
if peer.displayName == nickname || peer.nickname == nickname { if peer.displayName == nickname || peer.nickname == nickname {
return peer.peerID.id return peer.peerID
} }
} }
return nil return nil
@@ -347,7 +347,7 @@ final class UnifiedPeerService: ObservableObject, TransportPeerEventsDelegate {
// MARK: - Compatibility Methods (for easy migration) // MARK: - Compatibility Methods (for easy migration)
var allPeers: [BitchatPeer] { peers } var allPeers: [BitchatPeer] { peers }
var connectedPeers: [PeerID] { Array(connectedPeerIDs) } var connectedPeers: Set<PeerID> { connectedPeerIDs }
var favoritePeers: Set<String> { var favoritePeers: Set<String> {
Set(favorites.compactMap { getFingerprint(for: $0.peerID) }) Set(favorites.compactMap { getFingerprint(for: $0.peerID) })
} }
+204 -99
View File
@@ -8,6 +8,55 @@ final class GossipSyncManager {
func signPacketForBroadcast(_ packet: BitchatPacket) -> BitchatPacket func signPacketForBroadcast(_ packet: BitchatPacket) -> BitchatPacket
} }
private struct PacketStore {
private(set) var packets: [String: BitchatPacket] = [:]
private(set) var order: [String] = []
mutating func insert(idHex: String, packet: BitchatPacket, capacity: Int) {
guard capacity > 0 else { return }
if packets[idHex] != nil {
packets[idHex] = packet
return
}
packets[idHex] = packet
order.append(idHex)
while order.count > capacity {
let victim = order.removeFirst()
packets.removeValue(forKey: victim)
}
}
func allPackets(isFresh: (BitchatPacket) -> Bool) -> [BitchatPacket] {
order.compactMap { key in
guard let packet = packets[key], isFresh(packet) else { return nil }
return packet
}
}
mutating func remove(where shouldRemove: (BitchatPacket) -> Bool) {
var nextOrder: [String] = []
for key in order {
guard let packet = packets[key] else { continue }
if shouldRemove(packet) {
packets.removeValue(forKey: key)
} else {
nextOrder.append(key)
}
}
order = nextOrder
}
mutating func removeExpired(isFresh: (BitchatPacket) -> Bool) {
remove { !isFresh($0) }
}
}
private struct SyncSchedule {
let types: SyncTypeFlags
let interval: TimeInterval
var lastSent: Date
}
struct Config { struct Config {
var seenCapacity: Int = 1000 // max packets per sync (cap across types) var seenCapacity: Int = 1000 // max packets per sync (cap across types)
var gcsMaxBytes: Int = 400 // filter size budget (128..1024) var gcsMaxBytes: Int = 400 // filter size budget (128..1024)
@@ -16,25 +65,43 @@ final class GossipSyncManager {
var maintenanceIntervalSeconds: TimeInterval = 30.0 var maintenanceIntervalSeconds: TimeInterval = 30.0
var stalePeerCleanupIntervalSeconds: TimeInterval = 60.0 var stalePeerCleanupIntervalSeconds: TimeInterval = 60.0
var stalePeerTimeoutSeconds: TimeInterval = 60.0 var stalePeerTimeoutSeconds: TimeInterval = 60.0
var fragmentCapacity: Int = 600
var fileTransferCapacity: Int = 200
var fragmentSyncIntervalSeconds: TimeInterval = 30.0
var fileTransferSyncIntervalSeconds: TimeInterval = 60.0
var messageSyncIntervalSeconds: TimeInterval = 15.0
} }
private let myPeerID: PeerID private let myPeerID: PeerID
private let config: Config private let config: Config
weak var delegate: Delegate? weak var delegate: Delegate?
// Storage: broadcast messages (ordered by insert), and latest announce per sender // Storage: broadcast packets by type, and latest announce per sender
private var messages: [String: BitchatPacket] = [:] // idHex -> packet private var messages = PacketStore()
private var messageOrder: [String] = [] private var fragments = PacketStore()
private var latestAnnouncementByPeer: [String: (id: String, packet: BitchatPacket)] = [:] private var fileTransfers = PacketStore()
private var latestAnnouncementByPeer: [PeerID: (id: String, packet: BitchatPacket)] = [:]
// Timer // Timer
private var periodicTimer: DispatchSourceTimer? private var periodicTimer: DispatchSourceTimer?
private let queue = DispatchQueue(label: "mesh.sync", qos: .utility) private let queue = DispatchQueue(label: "mesh.sync", qos: .utility)
private var lastStalePeerCleanup: Date = .distantPast private var lastStalePeerCleanup: Date = .distantPast
private var syncSchedules: [SyncSchedule] = []
init(myPeerID: PeerID, config: Config = Config()) { init(myPeerID: PeerID, config: Config = Config()) {
self.myPeerID = myPeerID self.myPeerID = myPeerID
self.config = config self.config = config
var schedules: [SyncSchedule] = []
if config.seenCapacity > 0 && config.messageSyncIntervalSeconds > 0 {
schedules.append(SyncSchedule(types: .publicMessages, interval: config.messageSyncIntervalSeconds, lastSent: .distantPast))
}
if config.fragmentCapacity > 0 && config.fragmentSyncIntervalSeconds > 0 {
schedules.append(SyncSchedule(types: .fragment, interval: config.fragmentSyncIntervalSeconds, lastSent: .distantPast))
}
if config.fileTransferCapacity > 0 && config.fileTransferSyncIntervalSeconds > 0 {
schedules.append(SyncSchedule(types: .fileTransfer, interval: config.fileTransferSyncIntervalSeconds, lastSent: .distantPast))
}
syncSchedules = schedules
} }
func start() { func start() {
@@ -55,7 +122,18 @@ final class GossipSyncManager {
func scheduleInitialSyncToPeer(_ peerID: PeerID, delaySeconds: TimeInterval = 5.0) { func scheduleInitialSyncToPeer(_ peerID: PeerID, delaySeconds: TimeInterval = 5.0) {
queue.asyncAfter(deadline: .now() + delaySeconds) { [weak self] in queue.asyncAfter(deadline: .now() + delaySeconds) { [weak self] in
self?.sendRequestSync(to: peerID) guard let self = self else { return }
self.sendRequestSync(to: peerID, types: .publicMessages)
if self.config.fragmentCapacity > 0 && self.config.fragmentSyncIntervalSeconds > 0 {
self.queue.asyncAfter(deadline: .now() + 0.5) { [weak self] in
self?.sendRequestSync(to: peerID, types: .fragment)
}
}
if self.config.fileTransferCapacity > 0 && self.config.fileTransferSyncIntervalSeconds > 0 {
self.queue.asyncAfter(deadline: .now() + 1.0) { [weak self] in
self?.sendRequestSync(to: peerID, types: .fileTransfer)
}
}
} }
} }
@@ -87,47 +165,45 @@ final class GossipSyncManager {
} }
private func _onPublicPacketSeen(_ packet: BitchatPacket) { private func _onPublicPacketSeen(_ packet: BitchatPacket) {
let mt = MessageType(rawValue: packet.type) guard let messageType = MessageType(rawValue: packet.type) else { return }
let isBroadcastRecipient: Bool = { let isBroadcastRecipient: Bool = {
guard let r = packet.recipientID else { return true } guard let r = packet.recipientID else { return true }
return r.count == 8 && r.allSatisfy { $0 == 0xFF } return r.count == 8 && r.allSatisfy { $0 == 0xFF }
}() }()
let isBroadcastMessage = (mt == .message && isBroadcastRecipient)
let isAnnounce = (mt == .announce)
guard isBroadcastMessage || isAnnounce else { return }
// Reject expired packets to prevent ghost peers and old messages switch messageType {
guard isPacketFresh(packet) else { return } case .announce:
guard isPacketFresh(packet) else { return }
if isAnnounce {
guard isAnnouncementFresh(packet) else { guard isAnnouncementFresh(packet) else {
let sender = packet.senderID.hexEncodedString().lowercased() let sender = PeerID(hexData: packet.senderID)
removeState(forNormalizedPeerID: sender) removeState(for: sender)
return return
} }
} let idHex = PacketIdUtil.computeId(packet).hexEncodedString()
let sender = PeerID(hexData: packet.senderID)
let idHex = PacketIdUtil.computeId(packet).hexEncodedString()
if isBroadcastMessage {
if messages[idHex] == nil {
messages[idHex] = packet
messageOrder.append(idHex)
// Enforce capacity
let cap = max(1, config.seenCapacity)
while messageOrder.count > cap {
let victim = messageOrder.removeFirst()
messages.removeValue(forKey: victim)
}
}
} else if isAnnounce {
let sender = packet.senderID.hexEncodedString().lowercased()
latestAnnouncementByPeer[sender] = (id: idHex, packet: packet) latestAnnouncementByPeer[sender] = (id: idHex, packet: packet)
case .message:
guard isBroadcastRecipient else { return }
guard isPacketFresh(packet) else { return }
let idHex = PacketIdUtil.computeId(packet).hexEncodedString()
messages.insert(idHex: idHex, packet: packet, capacity: max(1, config.seenCapacity))
case .fragment:
guard isBroadcastRecipient else { return }
guard isPacketFresh(packet) else { return }
let idHex = PacketIdUtil.computeId(packet).hexEncodedString()
fragments.insert(idHex: idHex, packet: packet, capacity: max(1, config.fragmentCapacity))
case .fileTransfer:
guard isBroadcastRecipient else { return }
guard isPacketFresh(packet) else { return }
let idHex = PacketIdUtil.computeId(packet).hexEncodedString()
fileTransfers.insert(idHex: idHex, packet: packet, capacity: max(1, config.fileTransferCapacity))
default:
break
} }
} }
private func sendRequestSync() { private func sendRequestSync(for types: SyncTypeFlags) {
let payload = buildGcsPayload() let payload = buildGcsPayload(for: types)
let pkt = BitchatPacket( let pkt = BitchatPacket(
type: MessageType.requestSync.rawValue, type: MessageType.requestSync.rawValue,
senderID: Data(hexString: myPeerID.id) ?? Data(), senderID: Data(hexString: myPeerID.id) ?? Data(),
@@ -141,8 +217,8 @@ final class GossipSyncManager {
delegate?.sendPacket(signed) delegate?.sendPacket(signed)
} }
private func sendRequestSync(to peerID: PeerID) { private func sendRequestSync(to peerID: PeerID, types: SyncTypeFlags) {
let payload = buildGcsPayload() let payload = buildGcsPayload(for: types)
var recipient = Data() var recipient = Data()
var temp = peerID.id var temp = peerID.id
while temp.count >= 2 && recipient.count < 8 { while temp.count >= 2 && recipient.count < 8 {
@@ -170,6 +246,7 @@ final class GossipSyncManager {
} }
private func _handleRequestSync(from peerID: PeerID, request: RequestSyncPacket) { private func _handleRequestSync(from peerID: PeerID, request: RequestSyncPacket) {
let requestedTypes = (request.types ?? .publicMessages)
// Decode GCS into sorted set and prepare membership checker // Decode GCS into sorted set and prepare membership checker
let sorted = GCSFilter.decodeToSortedSet(p: request.p, m: request.m, data: request.data) let sorted = GCSFilter.decodeToSortedSet(p: request.p, m: request.m, data: request.data)
func mightContain(_ id: Data) -> Bool { func mightContain(_ id: Data) -> Bool {
@@ -177,60 +254,100 @@ final class GossipSyncManager {
return GCSFilter.contains(sortedValues: sorted, candidate: bucket) return GCSFilter.contains(sortedValues: sorted, candidate: bucket)
} }
// 1) Announcements: send latest per peer if requester lacks them (and not expired) if requestedTypes.contains(.announce) {
for (_, pair) in latestAnnouncementByPeer { for (_, pair) in latestAnnouncementByPeer {
let (idHex, pkt) = pair let (idHex, pkt) = pair
guard isPacketFresh(pkt) else { continue } guard isPacketFresh(pkt) else { continue }
let idBytes = Data(hexString: idHex) ?? Data() let idBytes = Data(hexString: idHex) ?? Data()
if !mightContain(idBytes) { if !mightContain(idBytes) {
var toSend = pkt var toSend = pkt
toSend.ttl = 0 toSend.ttl = 0
delegate?.sendPacket(to: peerID, packet: toSend) delegate?.sendPacket(to: peerID, packet: toSend)
}
} }
} }
// 2) Broadcast messages: send all missing (and not expired) if requestedTypes.contains(.message) {
let toSendMsgs = messageOrder.compactMap { messages[$0] } let toSendMsgs = messages.allPackets(isFresh: isPacketFresh)
for pkt in toSendMsgs { for pkt in toSendMsgs {
guard isPacketFresh(pkt) else { continue } let idBytes = PacketIdUtil.computeId(pkt)
let idBytes = PacketIdUtil.computeId(pkt) if !mightContain(idBytes) {
if !mightContain(idBytes) { var toSend = pkt
var toSend = pkt toSend.ttl = 0
toSend.ttl = 0 delegate?.sendPacket(to: peerID, packet: toSend)
delegate?.sendPacket(to: peerID, packet: toSend) }
}
}
if requestedTypes.contains(.fragment) {
let frags = fragments.allPackets(isFresh: isPacketFresh)
for pkt in frags {
let idBytes = PacketIdUtil.computeId(pkt)
if !mightContain(idBytes) {
var toSend = pkt
toSend.ttl = 0
delegate?.sendPacket(to: peerID, packet: toSend)
}
}
}
if requestedTypes.contains(.fileTransfer) {
let files = fileTransfers.allPackets(isFresh: isPacketFresh)
for pkt in files {
let idBytes = PacketIdUtil.computeId(pkt)
if !mightContain(idBytes) {
var toSend = pkt
toSend.ttl = 0
delegate?.sendPacket(to: peerID, packet: toSend)
}
} }
} }
} }
// Build REQUEST_SYNC payload using current candidates and GCS params // Build REQUEST_SYNC payload using current candidates and GCS params
private func buildGcsPayload() -> Data { private func buildGcsPayload(for types: SyncTypeFlags) -> Data {
// Collect candidates: latest announce per peer + broadcast messages (only fresh)
var candidates: [BitchatPacket] = [] var candidates: [BitchatPacket] = []
candidates.reserveCapacity(latestAnnouncementByPeer.count + messageOrder.count) if types.contains(.announce) {
for (_, pair) in latestAnnouncementByPeer { for (_, pair) in latestAnnouncementByPeer where isPacketFresh(pair.packet) {
if isPacketFresh(pair.packet) {
candidates.append(pair.packet) candidates.append(pair.packet)
} }
} }
for id in messageOrder { if types.contains(.message) {
if let p = messages[id], isPacketFresh(p) { candidates.append(contentsOf: messages.allPackets(isFresh: isPacketFresh))
candidates.append(p)
}
} }
if types.contains(.fragment) {
candidates.append(contentsOf: fragments.allPackets(isFresh: isPacketFresh))
}
if types.contains(.fileTransfer) {
candidates.append(contentsOf: fileTransfers.allPackets(isFresh: isPacketFresh))
}
if candidates.isEmpty {
let p = GCSFilter.deriveP(targetFpr: config.gcsTargetFpr)
let req = RequestSyncPacket(p: p, m: 1, data: Data(), types: types)
return req.encode()
}
// Sort by timestamp desc // Sort by timestamp desc
candidates.sort { $0.timestamp > $1.timestamp } candidates.sort { $0.timestamp > $1.timestamp }
let p = GCSFilter.deriveP(targetFpr: config.gcsTargetFpr) let p = GCSFilter.deriveP(targetFpr: config.gcsTargetFpr)
let nMax = GCSFilter.estimateMaxElements(sizeBytes: config.gcsMaxBytes, p: p) let nMax = GCSFilter.estimateMaxElements(sizeBytes: config.gcsMaxBytes, p: p)
let cap = max(1, config.seenCapacity) let cap: Int
if types == .fragment {
cap = max(1, config.fragmentCapacity)
} else if types == .fileTransfer {
cap = max(1, config.fileTransferCapacity)
} else {
cap = max(1, config.seenCapacity)
}
let takeN = min(candidates.count, min(nMax, cap)) let takeN = min(candidates.count, min(nMax, cap))
if takeN <= 0 { if takeN <= 0 {
let req = RequestSyncPacket(p: p, m: 1, data: Data()) let req = RequestSyncPacket(p: p, m: 1, data: Data(), types: types)
return req.encode() return req.encode()
} }
let ids: [Data] = candidates.prefix(takeN).map { PacketIdUtil.computeId($0) } let ids: [Data] = candidates.prefix(takeN).map { PacketIdUtil.computeId($0) }
let params = GCSFilter.buildFilter(ids: ids, maxBytes: config.gcsMaxBytes, targetFpr: config.gcsTargetFpr) let params = GCSFilter.buildFilter(ids: ids, maxBytes: config.gcsMaxBytes, targetFpr: config.gcsTargetFpr)
let req = RequestSyncPacket(p: params.p, m: params.m, data: params.data) let req = RequestSyncPacket(p: params.p, m: params.m, data: params.data, types: types)
return req.encode() return req.encode()
} }
@@ -241,20 +358,21 @@ final class GossipSyncManager {
isPacketFresh(pair.packet) isPacketFresh(pair.packet)
} }
// Remove expired messages messages.removeExpired(isFresh: isPacketFresh)
let expiredMessageIds = messages.compactMap { id, pkt in fragments.removeExpired(isFresh: isPacketFresh)
isPacketFresh(pkt) ? nil : id fileTransfers.removeExpired(isFresh: isPacketFresh)
}
for id in expiredMessageIds {
messages.removeValue(forKey: id)
messageOrder.removeAll { $0 == id }
}
} }
private func performPeriodicMaintenance(now: Date = Date()) { private func performPeriodicMaintenance(now: Date = Date()) {
cleanupExpiredMessages() cleanupExpiredMessages()
cleanupStaleAnnouncementsIfNeeded(now: now) cleanupStaleAnnouncementsIfNeeded(now: now)
sendRequestSync() for index in syncSchedules.indices {
guard syncSchedules[index].interval > 0 else { continue }
if syncSchedules[index].lastSent == .distantPast || now.timeIntervalSince(syncSchedules[index].lastSent) >= syncSchedules[index].interval {
syncSchedules[index].lastSent = now
sendRequestSync(for: syncSchedules[index].types)
}
}
} }
private func cleanupStaleAnnouncementsIfNeeded(now: Date) { private func cleanupStaleAnnouncementsIfNeeded(now: Date) {
@@ -270,40 +388,27 @@ final class GossipSyncManager {
let nowMs = UInt64(now.timeIntervalSince1970 * 1000) let nowMs = UInt64(now.timeIntervalSince1970 * 1000)
guard nowMs >= timeoutMs else { return } guard nowMs >= timeoutMs else { return }
let cutoff = nowMs - timeoutMs let cutoff = nowMs - timeoutMs
let stalePeerIDs = latestAnnouncementByPeer.compactMap { (peerHex, pair) -> String? in let stalePeerIDs = latestAnnouncementByPeer.compactMap { peerID, pair in
pair.packet.timestamp < cutoff ? peerHex.lowercased() : nil pair.packet.timestamp < cutoff ? peerID : nil
} }
guard !stalePeerIDs.isEmpty else { return } guard !stalePeerIDs.isEmpty else { return }
for peerKey in stalePeerIDs { for peerKey in stalePeerIDs {
removeState(forNormalizedPeerID: peerKey) removeState(for: peerKey)
} }
} }
// Explicit removal hook for LEAVE/stale peer // Explicit removal hook for LEAVE/stale peer
func removeAnnouncementForPeer(_ peerID: PeerID) { func removeAnnouncementForPeer(_ peerID: PeerID) {
queue.async { [weak self] in queue.async { [weak self] in
self?._removeAnnouncementForPeer(peerID) self?.removeState(for: peerID)
} }
} }
private func _removeAnnouncementForPeer(_ peerID: PeerID) { private func removeState(for peerID: PeerID) {
let normalizedPeerID = peerID.id.lowercased() _ = latestAnnouncementByPeer.removeValue(forKey: peerID)
removeState(forNormalizedPeerID: normalizedPeerID) messages.remove { PeerID(hexData: $0.senderID) == peerID }
} fragments.remove { PeerID(hexData: $0.senderID) == peerID }
fileTransfers.remove { PeerID(hexData: $0.senderID) == peerID }
private func removeState(forNormalizedPeerID normalizedPeerID: String) {
_ = latestAnnouncementByPeer.removeValue(forKey: normalizedPeerID)
// Remove messages from this peer
// Collect IDs to remove first to avoid concurrent modification
let messageIdsToRemove = messages.compactMap { (id, message) -> String? in
message.senderID.hexEncodedString().lowercased() == normalizedPeerID ? id : nil
}
// Remove messages and update messageOrder
for id in messageIdsToRemove {
messages.removeValue(forKey: id)
messageOrder.removeAll { $0 == id }
}
} }
} }
@@ -317,13 +422,13 @@ extension GossipSyncManager {
func _hasAnnouncement(for peerID: PeerID) -> Bool { func _hasAnnouncement(for peerID: PeerID) -> Bool {
queue.sync { queue.sync {
latestAnnouncementByPeer[peerID.id.lowercased()] != nil latestAnnouncementByPeer[peerID] != nil
} }
} }
func _messageCount(for peerID: PeerID) -> Int { func _messageCount(for peerID: PeerID) -> Int {
queue.sync { queue.sync {
messages.values.filter { $0.senderID.hexEncodedString().lowercased() == peerID.id.lowercased() }.count messages.allPackets { _ in true }.filter { PeerID(hexData: $0.senderID) == peerID }.count
} }
} }
} }
+104
View File
@@ -0,0 +1,104 @@
import Foundation
/// Bitfield describing which message types are covered by a REQUEST_SYNC round.
/// Matches the Android mapping (bit index -> message type).
struct SyncTypeFlags: OptionSet {
let rawValue: UInt64
init(rawValue: UInt64) {
self.rawValue = rawValue & 0x00FF_FFFF_FFFF_FFFF // Trim to max 8 bytes
}
private static func bitIndex(for type: MessageType) -> Int? {
switch type {
case .announce: return 0
case .message: return 1
case .leave: return 2
case .noiseHandshake: return 3
case .noiseEncrypted: return 4
case .fragment: return 5
case .requestSync: return 6
case .fileTransfer: return 7
}
}
private static func type(forBit index: Int) -> MessageType? {
switch index {
case 0: return .announce
case 1: return .message
case 2: return .leave
case 3: return .noiseHandshake
case 4: return .noiseEncrypted
case 5: return .fragment
case 6: return .requestSync
case 7: return .fileTransfer
default:
return nil
}
}
static let announce = SyncTypeFlags(messageTypes: [.announce])
static let message = SyncTypeFlags(messageTypes: [.message])
static let fragment = SyncTypeFlags(messageTypes: [.fragment])
static let fileTransfer = SyncTypeFlags(messageTypes: [.fileTransfer])
static let publicMessages = SyncTypeFlags(messageTypes: [.announce, .message])
init(messageTypes: [MessageType]) {
var raw: UInt64 = 0
for type in messageTypes {
guard let bit = SyncTypeFlags.bitIndex(for: type) else { continue }
raw |= (1 << UInt64(bit))
}
self.init(rawValue: raw)
}
func contains(_ type: MessageType) -> Bool {
guard let bit = SyncTypeFlags.bitIndex(for: type) else { return false }
return contains(SyncTypeFlags(rawValue: 1 << UInt64(bit)))
}
func union(_ other: SyncTypeFlags) -> SyncTypeFlags {
SyncTypeFlags(rawValue: rawValue | other.rawValue)
}
func intersection(_ other: SyncTypeFlags) -> SyncTypeFlags {
SyncTypeFlags(rawValue: rawValue & other.rawValue)
}
func toMessageTypes() -> [MessageType] {
guard rawValue != 0 else { return [] }
var types: [MessageType] = []
for bit in 0..<64 {
guard (rawValue & (1 << UInt64(bit))) != 0 else { continue }
if let type = SyncTypeFlags.type(forBit: bit) {
types.append(type)
}
}
return types
}
func toData() -> Data? {
guard rawValue != 0 else { return nil }
var value = rawValue
var bytes: [UInt8] = []
while value > 0 && bytes.count < 8 {
bytes.append(UInt8(value & 0xFF))
value >>= 8
}
while let last = bytes.last, last == 0 {
bytes.removeLast()
}
guard !bytes.isEmpty, bytes.count <= 8 else { return nil }
return Data(bytes)
}
static func decode(_ data: Data) -> SyncTypeFlags? {
guard (1...8).contains(data.count) else { return nil }
var raw: UInt64 = 0
for (index, byte) in data.enumerated() {
raw |= UInt64(byte) << UInt64(index * 8)
}
return SyncTypeFlags(rawValue: raw)
}
}
+7 -9
View File
@@ -61,15 +61,13 @@ struct CompressionUtil {
// 1. Data is too small // 1. Data is too small
// 2. Data appears to be already compressed (high entropy) // 2. Data appears to be already compressed (high entropy)
guard data.count >= compressionThreshold else { return false } guard data.count >= compressionThreshold else { return false }
// Simple entropy check - count unique bytes // Quick uniqueness check a high diversity of bytes usually means the
var byteFrequency = [UInt8: Int]() // payload is already compressed. We only need to know how many unique
for byte in data { // values exist rather than keeping full frequency counts.
byteFrequency[byte, default: 0] += 1 let uniqueByteCount = Set(data).count
} let sampleSize = min(data.count, 256)
let uniqueByteRatio = Double(uniqueByteCount) / Double(sampleSize)
// If we have very high byte diversity, data is likely already compressed
let uniqueByteRatio = Double(byteFrequency.count) / Double(min(data.count, 256))
return uniqueByteRatio < 0.9 // Compress if less than 90% unique bytes return uniqueByteRatio < 0.9 // Compress if less than 90% unique bytes
} }
} }
+12 -2
View File
@@ -5,9 +5,19 @@ enum FileTransferLimits {
/// Absolute ceiling enforced for any file payload (voice, image, other). /// Absolute ceiling enforced for any file payload (voice, image, other).
static let maxPayloadBytes: Int = 1 * 1024 * 1024 // 1 MiB static let maxPayloadBytes: Int = 1 * 1024 * 1024 // 1 MiB
/// Voice notes stay small for low-latency relays. /// Voice notes stay small for low-latency relays.
static let maxVoiceNoteBytes: Int = 1 * 1024 * 1024 // 1 MiB static let maxVoiceNoteBytes: Int = 512 * 1024 // 512 KiB
/// Compressed images after downscaling should comfortably fit under this budget. /// Compressed images after downscaling should comfortably fit under this budget.
static let maxImageBytes: Int = 1 * 1024 * 1024 // 1 MiB static let maxImageBytes: Int = 512 * 1024 // 512 KiB
/// Worst-case size once TLV metadata and binary packet framing are included for the largest payloads.
static let maxFramedFileBytes: Int = {
let maxMetadataBytes = Int(UInt16.max) * 2 // fileName + mimeType TLVs
let tlvEnvelopeOverhead = 18 + maxMetadataBytes // TLV tags + lengths + metadata bytes
let binaryEnvelopeOverhead = BinaryProtocol.v2HeaderSize
+ BinaryProtocol.senderIDSize
+ BinaryProtocol.recipientIDSize
+ BinaryProtocol.signatureSize
return maxPayloadBytes + tlvEnvelopeOverhead + binaryEnvelopeOverhead
}()
static func isValidPayload(_ size: Int) -> Bool { static func isValidPayload(_ size: Int) -> Bool {
size <= maxPayloadBytes size <= maxPayloadBytes
+17 -17
View File
@@ -1,4 +1,5 @@
import Foundation import Foundation
import BitLogger
/// Comprehensive input validation for BitChat protocol /// Comprehensive input validation for BitChat protocol
/// Prevents injection attacks, buffer overflows, and malformed data /// Prevents injection attacks, buffer overflows, and malformed data
@@ -16,29 +17,28 @@ struct InputValidator {
// MARK: - String Content Validation // MARK: - String Content Validation
/// Validates and sanitizes user-provided strings used in UI /// Validates and sanitizes user-provided strings used in UI
///
/// Rejects strings containing control characters to prevent potential security issues
/// and UI rendering problems. This strict approach ensures data integrity at input time.
static func validateUserString(_ string: String, maxLength: Int) -> String? { static func validateUserString(_ string: String, maxLength: Int) -> String? {
// Check empty
guard !string.isEmpty else { return nil }
// Trim whitespace
let trimmed = string.trimmingCharacters(in: .whitespacesAndNewlines) let trimmed = string.trimmingCharacters(in: .whitespacesAndNewlines)
guard !trimmed.isEmpty else { return nil } guard !trimmed.isEmpty else { return nil }
// Check length
guard trimmed.count <= maxLength else { return nil } guard trimmed.count <= maxLength else { return nil }
// Remove control characters // Reject control characters outright instead of rewriting the string.
// This prevents injection attacks and ensures consistent UI rendering.
let controlChars = CharacterSet.controlCharacters let controlChars = CharacterSet.controlCharacters
let cleaned = trimmed.components(separatedBy: controlChars).joined() if !trimmed.unicodeScalars.allSatisfy({ !controlChars.contains($0) }) {
// Log rejection for monitoring, without exposing actual content for privacy
// Ensure valid UTF-8 (should already be, but double-check) let controlCharCount = trimmed.unicodeScalars.filter { controlChars.contains($0) }.count
guard cleaned.data(using: .utf8) != nil else { return nil } SecureLogger.debug(
"Input validation rejected string (length: \(trimmed.count), control chars: \(controlCharCount))",
// Prevent zero-width characters and other invisible unicode category: .security
let invisibleChars = CharacterSet(charactersIn: "\u{200B}\u{200C}\u{200D}\u{FEFF}") )
let visible = cleaned.components(separatedBy: invisibleChars).joined() return nil
}
return visible.isEmpty ? nil : visible
return trimmed
} }
/// Validates nickname /// Validates nickname
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,118 @@
//
// GeoChannelCoordinator.swift
// bitchat
//
// Centralizes Combine wiring for location channel selection and sampling.
//
import Combine
import Foundation
import Tor
@MainActor
final class GeoChannelCoordinator {
private let locationManager: LocationChannelManager
private let bookmarksStore: GeohashBookmarksStore
private let torManager: TorManager
private let onChannelSwitch: (ChannelID) -> Void
private let beginSampling: ([String]) -> Void
private let endSampling: () -> Void
private var cancellables = Set<AnyCancellable>()
private var regionalGeohashes: [String] = []
private var bookmarkedGeohashes: [String] = []
init(
locationManager: LocationChannelManager? = nil,
bookmarksStore: GeohashBookmarksStore? = nil,
torManager: TorManager? = nil,
onChannelSwitch: @escaping (ChannelID) -> Void,
beginSampling: @escaping ([String]) -> Void,
endSampling: @escaping () -> Void
) {
self.locationManager = locationManager ?? Self.defaultLocationManager()
self.bookmarksStore = bookmarksStore ?? GeohashBookmarksStore.shared
self.torManager = torManager ?? Self.defaultTorManager()
self.onChannelSwitch = onChannelSwitch
self.beginSampling = beginSampling
self.endSampling = endSampling
start()
}
func start() {
regionalGeohashes = locationManager.availableChannels.map { $0.geohash }
bookmarkedGeohashes = bookmarksStore.bookmarks
locationManager.$selectedChannel
.receive(on: DispatchQueue.main)
.sink { [weak self] channel in
guard let self else { return }
Task { @MainActor in
self.onChannelSwitch(channel)
}
}
.store(in: &cancellables)
locationManager.$availableChannels
.receive(on: DispatchQueue.main)
.sink { [weak self] channels in
guard let self else { return }
self.regionalGeohashes = channels.map { $0.geohash }
self.updateSampling()
}
.store(in: &cancellables)
bookmarksStore.$bookmarks
.receive(on: DispatchQueue.main)
.sink { [weak self] bookmarks in
guard let self else { return }
self.bookmarkedGeohashes = bookmarks
self.updateSampling()
}
.store(in: &cancellables)
locationManager.$permissionState
.receive(on: DispatchQueue.main)
.sink { [weak self] state in
guard let self, state == .authorized else { return }
Task { @MainActor [weak self] in
self?.locationManager.refreshChannels()
}
}
.store(in: &cancellables)
Task { @MainActor in
self.onChannelSwitch(self.locationManager.selectedChannel)
}
updateSampling()
}
private func updateSampling() {
let union = Array(Set(regionalGeohashes).union(bookmarkedGeohashes))
Task { @MainActor in
guard !union.isEmpty else {
endSampling()
return
}
if torManager.isForeground() {
beginSampling(union)
} else {
endSampling()
}
}
}
func refreshSampling() {
updateSampling()
}
private static func defaultLocationManager() -> LocationChannelManager {
LocationChannelManager.shared
}
@MainActor
private static func defaultTorManager() -> TorManager {
TorManager.shared
}
}
@@ -0,0 +1,77 @@
//
// MessageRateLimiter.swift
// bitchat
//
// Handles per-sender and per-content token buckets for public message intake.
//
import Foundation
struct MessageRateLimiter {
private struct TokenBucket {
var capacity: Double
var tokens: Double
var refillPerSec: Double
var lastRefill: Date
mutating func allow(cost: Double = 1.0, now: Date = Date()) -> Bool {
let dt = now.timeIntervalSince(lastRefill)
if dt > 0 {
tokens = min(capacity, tokens + dt * refillPerSec)
lastRefill = now
}
if tokens >= cost {
tokens -= cost
return true
}
return false
}
}
private var senderBuckets: [String: TokenBucket] = [:]
private var contentBuckets: [String: TokenBucket] = [:]
private let senderCapacity: Double
private let senderRefill: Double
private let contentCapacity: Double
private let contentRefill: Double
init(
senderCapacity: Double,
senderRefillPerSec: Double,
contentCapacity: Double,
contentRefillPerSec: Double
) {
self.senderCapacity = senderCapacity
self.senderRefill = senderRefillPerSec
self.contentCapacity = contentCapacity
self.contentRefill = contentRefillPerSec
}
mutating func allow(senderKey: String, contentKey: String, now: Date = Date()) -> Bool {
var senderBucket = senderBuckets[senderKey] ?? TokenBucket(
capacity: senderCapacity,
tokens: senderCapacity,
refillPerSec: senderRefill,
lastRefill: now
)
let senderAllowed = senderBucket.allow(now: now)
senderBuckets[senderKey] = senderBucket
var contentBucket = contentBuckets[contentKey] ?? TokenBucket(
capacity: contentCapacity,
tokens: contentCapacity,
refillPerSec: contentRefill,
lastRefill: now
)
let contentAllowed = contentBucket.allow(now: now)
contentBuckets[contentKey] = contentBucket
return senderAllowed && contentAllowed
}
mutating func reset() {
senderBuckets.removeAll()
contentBuckets.removeAll()
}
}
@@ -0,0 +1,210 @@
//
// MinimalDistancePalette.swift
// bitchat
//
// Lightweight palette generator that keeps peer colors evenly spaced.
//
import Foundation
import SwiftUI
final class MinimalDistancePalette {
struct Config {
let slotCount: Int
let avoidCenterHue: Double
let avoidHueDelta: Double
let saturationLight: Double
let saturationDark: Double
let baseBrightnessLight: Double
let baseBrightnessDark: Double
let ringBrightnessDeltaLight: Double
let ringBrightnessDeltaDark: Double
let preferredBiasWeight: Double
let goldenStep: Int
init(
slotCount: Int,
avoidCenterHue: Double,
avoidHueDelta: Double,
saturationLight: Double,
saturationDark: Double,
baseBrightnessLight: Double,
baseBrightnessDark: Double,
ringBrightnessDeltaLight: Double,
ringBrightnessDeltaDark: Double,
preferredBiasWeight: Double = 0.05,
goldenStep: Int = 7
) {
self.slotCount = slotCount
self.avoidCenterHue = avoidCenterHue
self.avoidHueDelta = avoidHueDelta
self.saturationLight = saturationLight
self.saturationDark = saturationDark
self.baseBrightnessLight = baseBrightnessLight
self.baseBrightnessDark = baseBrightnessDark
self.ringBrightnessDeltaLight = ringBrightnessDeltaLight
self.ringBrightnessDeltaDark = ringBrightnessDeltaDark
self.preferredBiasWeight = preferredBiasWeight
self.goldenStep = goldenStep
}
}
private struct Entry {
let slot: Int
let ring: Int
let hue: Double
}
private let config: Config
private var currentSeeds: [String: String] = [:]
private var entries: [String: Entry] = [:]
private var previousEntries: [String: Entry] = [:]
init(config: Config) {
self.config = config
}
@MainActor
func ensurePalette(for seeds: [String: String]) {
guard seeds != currentSeeds || entries.count != seeds.count else { return }
previousEntries = entries
currentSeeds = seeds
rebuildEntries()
}
@MainActor
func color(for identifier: String, isDark: Bool) -> Color? {
guard let entry = entries[identifier] else { return nil }
let saturation = isDark ? config.saturationDark : config.saturationLight
let baseBrightness = isDark ? config.baseBrightnessDark : config.baseBrightnessLight
let ringDelta = isDark ? config.ringBrightnessDeltaDark : config.ringBrightnessDeltaLight
let brightness = min(1.0, max(0.0, baseBrightness + ringDelta * Double(entry.ring)))
return Color(hue: entry.hue, saturation: saturation, brightness: brightness)
}
@MainActor
func reset() {
currentSeeds.removeAll()
entries.removeAll()
previousEntries.removeAll()
}
@MainActor
private func rebuildEntries() {
guard !currentSeeds.isEmpty else {
entries.removeAll()
return
}
let slotCount = max(8, config.slotCount)
var slots: [Double] = []
for idx in 0..<slotCount {
let hue = Double(idx) / Double(slotCount)
if abs(hue - config.avoidCenterHue) < config.avoidHueDelta {
continue
}
slots.append(hue)
}
if slots.isEmpty {
for idx in 0..<slotCount {
slots.append(Double(idx) / Double(slotCount))
}
}
func circularDistance(_ a: Double, _ b: Double) -> Double {
let diff = abs(a - b)
return diff > 0.5 ? 1.0 - diff : diff
}
let peerIDs = currentSeeds.keys.sorted()
let preferredIndex: [String: Int] = Dictionary(uniqueKeysWithValues: peerIDs.map { id in
let seed = currentSeeds[id] ?? id
let hash = seed.djb2()
let index = Int(hash % UInt64(slots.count))
return (id, index)
})
var mapping: [String: Entry] = [:]
var usedSlots = Set<Int>()
var usedHues: [Double] = []
let prior = entries.isEmpty ? previousEntries : entries
for (id, entry) in prior {
guard currentSeeds.keys.contains(id), entry.slot < slots.count else { continue }
let hue = slots[entry.slot]
mapping[id] = Entry(slot: entry.slot, ring: entry.ring, hue: hue)
usedSlots.insert(entry.slot)
usedHues.append(hue)
}
let unassigned = peerIDs.filter { mapping[$0] == nil }
for id in unassigned {
let preferred = preferredIndex[id] ?? 0
if !usedSlots.contains(preferred), preferred < slots.count {
let hue = slots[preferred]
mapping[id] = Entry(slot: preferred, ring: 0, hue: hue)
usedSlots.insert(preferred)
usedHues.append(hue)
continue
}
var bestSlot: Int?
var bestScore = -Double.infinity
for slot in 0..<slots.count where !usedSlots.contains(slot) {
let hue = slots[slot]
let minDistance = usedHues.isEmpty ? 1.0 : usedHues.map { circularDistance(hue, $0) }.min() ?? 1.0
let bias = 1.0 - (Double((abs(slot - (preferredIndex[id] ?? 0)) % slots.count)) / Double(slots.count))
let score = minDistance + config.preferredBiasWeight * bias
if score > bestScore {
bestScore = score
bestSlot = slot
}
}
if let slot = bestSlot {
let hue = slots[slot]
mapping[id] = Entry(slot: slot, ring: 0, hue: hue)
usedSlots.insert(slot)
usedHues.append(hue)
}
}
let remaining = peerIDs.filter { mapping[$0] == nil }
if !remaining.isEmpty {
for (index, id) in remaining.enumerated() {
let preferred = preferredIndex[id] ?? 0
let slot = (preferred + index * config.goldenStep) % slots.count
let hue = slots[slot]
mapping[id] = Entry(slot: slot, ring: 1, hue: hue)
}
}
entries = mapping
}
}
extension MinimalDistancePalette.Config {
static let mesh = MinimalDistancePalette.Config(
slotCount: TransportConfig.uiPeerPaletteSlots,
avoidCenterHue: 30.0 / 360.0,
avoidHueDelta: TransportConfig.uiColorHueAvoidanceDelta,
saturationLight: 0.70,
saturationDark: 0.80,
baseBrightnessLight: 0.45,
baseBrightnessDark: 0.75,
ringBrightnessDeltaLight: TransportConfig.uiPeerPaletteRingBrightnessDeltaLight,
ringBrightnessDeltaDark: TransportConfig.uiPeerPaletteRingBrightnessDeltaDark
)
static let nostr = MinimalDistancePalette.Config(
slotCount: TransportConfig.uiPeerPaletteSlots,
avoidCenterHue: 30.0 / 360.0,
avoidHueDelta: TransportConfig.uiColorHueAvoidanceDelta,
saturationLight: 0.70,
saturationDark: 0.80,
baseBrightnessLight: 0.45,
baseBrightnessDark: 0.75,
ringBrightnessDeltaLight: TransportConfig.uiPeerPaletteRingBrightnessDeltaLight,
ringBrightnessDeltaDark: TransportConfig.uiPeerPaletteRingBrightnessDeltaDark
)
}
@@ -0,0 +1,190 @@
//
// PublicMessagePipeline.swift
// bitchat
//
// Handles batching and deduplication of public chat messages before surfacing them to the UI.
//
import Foundation
@MainActor
protocol PublicMessagePipelineDelegate: AnyObject {
func pipelineCurrentMessages(_ pipeline: PublicMessagePipeline) -> [BitchatMessage]
func pipeline(_ pipeline: PublicMessagePipeline, setMessages messages: [BitchatMessage])
func pipeline(_ pipeline: PublicMessagePipeline, normalizeContent content: String) -> String
func pipeline(_ pipeline: PublicMessagePipeline, contentTimestampForKey key: String) -> Date?
func pipeline(_ pipeline: PublicMessagePipeline, recordContentKey key: String, timestamp: Date)
func pipelineTrimMessages(_ pipeline: PublicMessagePipeline)
func pipelinePrewarmMessage(_ pipeline: PublicMessagePipeline, message: BitchatMessage)
func pipelineSetBatchingState(_ pipeline: PublicMessagePipeline, isBatching: Bool)
}
@MainActor
final class PublicMessagePipeline {
weak var delegate: PublicMessagePipelineDelegate?
private var buffer: [BitchatMessage] = []
private var timer: Timer?
private let baseFlushInterval: TimeInterval
private var dynamicFlushInterval: TimeInterval
private var recentBatchSizes: [Int] = []
private let maxRecentBatchSamples: Int
private let dedupWindow: TimeInterval
private var activeChannel: ChannelID = .mesh
init(
baseFlushInterval: TimeInterval = TransportConfig.basePublicFlushInterval,
maxRecentBatchSamples: Int = 10,
dedupWindow: TimeInterval = 1.0
) {
self.baseFlushInterval = baseFlushInterval
self.dynamicFlushInterval = baseFlushInterval
self.maxRecentBatchSamples = maxRecentBatchSamples
self.dedupWindow = dedupWindow
}
deinit {
timer?.invalidate()
}
func updateActiveChannel(_ channel: ChannelID) {
activeChannel = channel
}
func enqueue(_ message: BitchatMessage) {
buffer.append(message)
scheduleFlush()
}
func flushIfNeeded() {
flushBuffer()
}
func reset() {
timer?.invalidate()
timer = nil
buffer.removeAll(keepingCapacity: false)
}
}
private extension PublicMessagePipeline {
func scheduleFlush() {
guard timer == nil else { return }
timer = Timer.scheduledTimer(withTimeInterval: dynamicFlushInterval, repeats: false) { [weak self] _ in
guard let self else { return }
Task { @MainActor in
self.flushBuffer()
}
}
}
func flushBuffer() {
timer?.invalidate()
timer = nil
guard !buffer.isEmpty else { return }
guard let delegate = delegate else {
buffer.removeAll(keepingCapacity: false)
return
}
delegate.pipelineSetBatchingState(self, isBatching: true)
var existingIDs = Set(delegate.pipelineCurrentMessages(self).map { $0.id })
var pending: [(message: BitchatMessage, contentKey: String)] = []
var batchContentLatest: [String: Date] = [:]
for message in buffer {
if existingIDs.contains(message.id) { continue }
let contentKey = delegate.pipeline(self, normalizeContent: message.content)
if let ts = delegate.pipeline(self, contentTimestampForKey: contentKey),
abs(ts.timeIntervalSince(message.timestamp)) < dedupWindow {
continue
}
if let ts = batchContentLatest[contentKey],
abs(ts.timeIntervalSince(message.timestamp)) < dedupWindow {
continue
}
existingIDs.insert(message.id)
pending.append((message, contentKey))
batchContentLatest[contentKey] = message.timestamp
}
buffer.removeAll(keepingCapacity: true)
guard !pending.isEmpty else {
delegate.pipelineSetBatchingState(self, isBatching: false)
if !buffer.isEmpty { scheduleFlush() }
return
}
pending.sort { $0.message.timestamp < $1.message.timestamp }
var messages = delegate.pipelineCurrentMessages(self)
let threshold = lateInsertThreshold(for: activeChannel)
let lastTimestamp = messages.last?.timestamp ?? .distantPast
for item in pending {
let message = item.message
if threshold == 0 || message.timestamp < lastTimestamp.addingTimeInterval(-threshold) {
let index = insertionIndex(for: message.timestamp, in: messages)
if index >= messages.count {
messages.append(message)
} else {
messages.insert(message, at: index)
}
} else {
messages.append(message)
}
delegate.pipeline(self, recordContentKey: item.contentKey, timestamp: message.timestamp)
}
delegate.pipeline(self, setMessages: messages)
delegate.pipelineTrimMessages(self)
updateFlushInterval(withBatchSize: pending.count)
for item in pending {
delegate.pipelinePrewarmMessage(self, message: item.message)
}
delegate.pipelineSetBatchingState(self, isBatching: false)
if !buffer.isEmpty {
scheduleFlush()
}
}
func updateFlushInterval(withBatchSize size: Int) {
recentBatchSizes.append(size)
if recentBatchSizes.count > maxRecentBatchSamples {
recentBatchSizes.removeFirst(recentBatchSizes.count - maxRecentBatchSamples)
}
let avg = recentBatchSizes.isEmpty
? 0.0
: Double(recentBatchSizes.reduce(0, +)) / Double(recentBatchSizes.count)
dynamicFlushInterval = avg > 100.0 ? 0.12 : baseFlushInterval
}
func lateInsertThreshold(for channel: ChannelID) -> TimeInterval {
switch channel {
case .mesh:
return TransportConfig.uiLateInsertThreshold
case .location:
return TransportConfig.uiLateInsertThresholdGeo
}
}
func insertionIndex(for timestamp: Date, in messages: [BitchatMessage]) -> Int {
var low = 0
var high = messages.count
while low < high {
let mid = (low + high) / 2
if messages[mid].timestamp < timestamp {
low = mid + 1
} else {
high = mid
}
}
return low
}
}
@@ -0,0 +1,124 @@
//
// PublicTimelineStore.swift
// bitchat
//
// Maintains mesh and geohash public timelines with simple caps and helpers.
//
import Foundation
struct PublicTimelineStore {
private var meshTimeline: [BitchatMessage] = []
private var geohashTimelines: [String: [BitchatMessage]] = [:]
private var pendingGeohashSystemMessages: [String] = []
private let meshCap: Int
private let geohashCap: Int
init(meshCap: Int, geohashCap: Int) {
self.meshCap = meshCap
self.geohashCap = geohashCap
}
mutating func append(_ message: BitchatMessage, to channel: ChannelID) {
switch channel {
case .mesh:
guard !meshTimeline.contains(where: { $0.id == message.id }) else { return }
meshTimeline.append(message)
trimMeshTimelineIfNeeded()
case .location(let channel):
append(message, toGeohash: channel.geohash)
}
}
mutating func append(_ message: BitchatMessage, toGeohash geohash: String) {
var timeline = geohashTimelines[geohash] ?? []
guard !timeline.contains(where: { $0.id == message.id }) else { return }
timeline.append(message)
trimGeohashTimelineIfNeeded(&timeline)
geohashTimelines[geohash] = timeline
}
/// Append message if absent, returning true when stored.
mutating func appendIfAbsent(_ message: BitchatMessage, toGeohash geohash: String) -> Bool {
var timeline = geohashTimelines[geohash] ?? []
guard !timeline.contains(where: { $0.id == message.id }) else { return false }
timeline.append(message)
trimGeohashTimelineIfNeeded(&timeline)
geohashTimelines[geohash] = timeline
return true
}
mutating func messages(for channel: ChannelID) -> [BitchatMessage] {
switch channel {
case .mesh:
return meshTimeline
case .location(let channel):
let cleaned = geohashTimelines[channel.geohash]?.cleanedAndDeduped() ?? []
geohashTimelines[channel.geohash] = cleaned
return cleaned
}
}
mutating func clear(channel: ChannelID) {
switch channel {
case .mesh:
meshTimeline.removeAll()
case .location(let channel):
geohashTimelines[channel.geohash] = []
}
}
@discardableResult
mutating func removeMessage(withID id: String) -> BitchatMessage? {
if let index = meshTimeline.firstIndex(where: { $0.id == id }) {
return meshTimeline.remove(at: index)
}
for key in Array(geohashTimelines.keys) {
var timeline = geohashTimelines[key] ?? []
if let index = timeline.firstIndex(where: { $0.id == id }) {
let removed = timeline.remove(at: index)
geohashTimelines[key] = timeline.isEmpty ? nil : timeline
return removed
}
}
return nil
}
mutating func removeMessages(in geohash: String, where predicate: (BitchatMessage) -> Bool) {
var timeline = geohashTimelines[geohash] ?? []
timeline.removeAll(where: predicate)
geohashTimelines[geohash] = timeline.isEmpty ? nil : timeline
}
mutating func mutateGeohash(_ geohash: String, _ transform: (inout [BitchatMessage]) -> Void) {
var timeline = geohashTimelines[geohash] ?? []
transform(&timeline)
geohashTimelines[geohash] = timeline.isEmpty ? nil : timeline
}
mutating func queueGeohashSystemMessage(_ content: String) {
pendingGeohashSystemMessages.append(content)
}
mutating func drainPendingGeohashSystemMessages() -> [String] {
defer { pendingGeohashSystemMessages.removeAll(keepingCapacity: false) }
return pendingGeohashSystemMessages
}
func geohashKeys() -> [String] {
Array(geohashTimelines.keys)
}
private mutating func trimMeshTimelineIfNeeded() {
guard meshTimeline.count > meshCap else { return }
meshTimeline = Array(meshTimeline.suffix(meshCap))
}
private func trimGeohashTimelineIfNeeded(_ timeline: inout [BitchatMessage]) {
guard timeline.count > geohashCap else { return }
timeline = Array(timeline.suffix(geohashCap))
}
}
@@ -0,0 +1,90 @@
//
// CommandSuggestionsView.swift
// bitchat
//
// Created by Islam on 29/10/2025.
//
import SwiftUI
struct CommandSuggestionsView: View {
@EnvironmentObject private var viewModel: ChatViewModel
@ObservedObject private var locationManager = LocationChannelManager.shared
@Binding var messageText: String
let textColor: Color
let backgroundColor: Color
let secondaryTextColor: Color
private var filteredCommands: [CommandInfo] {
guard messageText.hasPrefix("/") && !messageText.contains(" ") else { return [] }
let isGeoPublic = locationManager.selectedChannel.isLocation
let isGeoDM = viewModel.selectedPrivateChatPeer?.isGeoDM == true
return CommandInfo.all(isGeoPublic: isGeoPublic, isGeoDM: isGeoDM).filter { command in
command.alias.starts(with: messageText.lowercased())
}
}
var body: some View {
VStack(alignment: .leading, spacing: 0) {
ForEach(filteredCommands) { command in
Button {
messageText = command.alias + " "
} label: {
buttonRow(for: command)
}
.buttonStyle(.plain)
.background(Color.gray.opacity(0.1))
}
}
.background(backgroundColor)
.overlay(
RoundedRectangle(cornerRadius: 4)
.stroke(secondaryTextColor.opacity(0.3), lineWidth: 1)
)
}
private func buttonRow(for command: CommandInfo) -> some View {
HStack {
Text(command.alias)
.font(.bitchatSystem(size: 11, design: .monospaced))
.foregroundColor(textColor)
.fontWeight(.medium)
if let placeholder = command.placeholder {
Text(placeholder)
.font(.bitchatSystem(size: 10, design: .monospaced))
.foregroundColor(secondaryTextColor.opacity(0.8))
}
Spacer()
Text(command.description)
.font(.bitchatSystem(size: 10, design: .monospaced))
.foregroundColor(secondaryTextColor)
}
.padding(.horizontal, 12)
.padding(.vertical, 3)
.frame(maxWidth: .infinity, alignment: .leading)
}
}
@available(iOS 17, macOS 14, *)
#Preview {
@Previewable @State var messageText: String = "/"
let keychain = KeychainManager()
let viewModel = ChatViewModel(
keychain: keychain,
idBridge: NostrIdentityBridge(),
identityManager: SecureIdentityStateManager(keychain)
)
CommandSuggestionsView(
messageText: $messageText,
textColor: .green,
backgroundColor: .primary,
secondaryTextColor: .secondary
)
.environmentObject(viewModel)
}
+351 -324
View File
@@ -15,9 +15,6 @@ import AppKit
#endif #endif
import UniformTypeIdentifiers import UniformTypeIdentifiers
import BitLogger import BitLogger
#if canImport(PhotosUI)
import PhotosUI
#endif
// MARK: - Supporting Types // MARK: - Supporting Types
@@ -38,7 +35,6 @@ struct ContentView: View {
@EnvironmentObject var viewModel: ChatViewModel @EnvironmentObject var viewModel: ChatViewModel
@ObservedObject private var locationManager = LocationChannelManager.shared @ObservedObject private var locationManager = LocationChannelManager.shared
@ObservedObject private var bookmarks = GeohashBookmarksStore.shared @ObservedObject private var bookmarks = GeohashBookmarksStore.shared
@ObservedObject private var notesCounter = LocationNotesCounter.shared
@State private var messageText = "" @State private var messageText = ""
@FocusState private var isTextFieldFocused: Bool @FocusState private var isTextFieldFocused: Bool
@Environment(\.colorScheme) var colorScheme @Environment(\.colorScheme) var colorScheme
@@ -47,11 +43,9 @@ struct ContentView: View {
@State private var showPeerList = false @State private var showPeerList = false
@State private var showSidebar = false @State private var showSidebar = false
@State private var showAppInfo = false @State private var showAppInfo = false
@State private var showCommandSuggestions = false
@State private var commandSuggestions: [String] = []
@State private var showMessageActions = false @State private var showMessageActions = false
@State private var selectedMessageSender: String? @State private var selectedMessageSender: String?
@State private var selectedMessageSenderID: String? @State private var selectedMessageSenderID: PeerID?
@FocusState private var isNicknameFieldFocused: Bool @FocusState private var isNicknameFieldFocused: Bool
@State private var isAtBottomPublic: Bool = true @State private var isAtBottomPublic: Bool = true
@State private var isAtBottomPrivate: Bool = true @State private var isAtBottomPrivate: Bool = true
@@ -72,19 +66,19 @@ struct ContentView: View {
@State private var recordingDuration: TimeInterval = 0 @State private var recordingDuration: TimeInterval = 0
@State private var recordingTimer: Timer? @State private var recordingTimer: Timer?
@State private var recordingStartDate: Date? @State private var recordingStartDate: Date?
@State private var showFileImporter = false
#if os(iOS) #if os(iOS)
@State private var showPhotoPicker = false @State private var showImagePicker = false
@State private var selectedPhotoPickerItem: PhotosPickerItem? @State private var imagePickerSourceType: UIImagePickerController.SourceType = .camera
#else
@State private var showMacImagePicker = false
#endif #endif
@State private var showAttachmentActions = false
@ScaledMetric(relativeTo: .body) private var headerHeight: CGFloat = 44 @ScaledMetric(relativeTo: .body) private var headerHeight: CGFloat = 44
@ScaledMetric(relativeTo: .subheadline) private var headerPeerIconSize: CGFloat = 11 @ScaledMetric(relativeTo: .subheadline) private var headerPeerIconSize: CGFloat = 11
@ScaledMetric(relativeTo: .subheadline) private var headerPeerCountFontSize: CGFloat = 12 @ScaledMetric(relativeTo: .subheadline) private var headerPeerCountFontSize: CGFloat = 12
// Timer-based refresh removed; use LocationChannelManager live updates instead // Timer-based refresh removed; use LocationChannelManager live updates instead
// Window sizes for rendering (infinite scroll up) // Window sizes for rendering (infinite scroll up)
@State private var windowCountPublic: Int = 300 @State private var windowCountPublic: Int = 300
@State private var windowCountPrivate: [String: Int] = [:] @State private var windowCountPrivate: [PeerID: Int] = [:]
// MARK: - Computed Properties // MARK: - Computed Properties
@@ -128,7 +122,7 @@ struct ContentView: View {
private struct PrivateHeaderContext { private struct PrivateHeaderContext {
let headerPeerID: String let headerPeerID: PeerID
let peer: BitchatPeer? let peer: BitchatPeer?
let displayName: String let displayName: String
let isNostrAvailable: Bool let isNostrAvailable: Bool
@@ -192,10 +186,6 @@ struct ContentView: View {
) )
) { ) {
peopleSheetView peopleSheetView
#if os(iOS)
.presentationDetents([.large])
.presentationDragIndicator(.visible)
#endif
} }
.sheet(isPresented: $showAppInfo) { .sheet(isPresented: $showAppInfo) {
AppInfoView() AppInfoView()
@@ -211,15 +201,60 @@ struct ContentView: View {
} }
} }
#if os(iOS) #if os(iOS)
.photosPicker(isPresented: $showPhotoPicker, selection: $selectedPhotoPickerItem, matching: .images) // Only present image picker from main view when NOT in a sheet
.onChange(of: selectedPhotoPickerItem) { newItem in .fullScreenCover(isPresented: Binding(
guard let item = newItem else { return } get: { showImagePicker && !showSidebar && viewModel.selectedPrivateChatPeer == nil },
Task { await handlePhotoSelection(item) } set: { newValue in
if !newValue {
showImagePicker = false
}
}
)) {
ImagePickerView(sourceType: imagePickerSourceType) { image in
showImagePicker = false
if let image = image {
Task {
do {
let processedURL = try ImageUtils.processImage(image)
await MainActor.run {
viewModel.sendImage(from: processedURL)
}
} catch {
SecureLogger.error("Image processing failed: \(error)", category: .session)
}
}
}
}
.ignoresSafeArea()
} }
#endif #endif
.fileImporter(isPresented: $showFileImporter, allowedContentTypes: [.data], allowsMultipleSelection: false) { result in #if os(macOS)
handleImportResult(result, handler: handleImportedFile) // Only present Mac image picker from main view when NOT in a sheet
.sheet(isPresented: Binding(
get: { showMacImagePicker && !showSidebar && viewModel.selectedPrivateChatPeer == nil },
set: { newValue in
if !newValue {
showMacImagePicker = false
}
}
)) {
MacImagePickerView { url in
showMacImagePicker = false
if let url = url {
Task {
do {
let processedURL = try ImageUtils.processImage(at: url)
await MainActor.run {
viewModel.sendImage(from: processedURL)
}
} catch {
SecureLogger.error("Image processing failed: \(error)", category: .session)
}
}
}
}
} }
#endif
.sheet(isPresented: Binding( .sheet(isPresented: Binding(
get: { imagePreviewURL != nil }, get: { imagePreviewURL != nil },
set: { presenting in if !presenting { imagePreviewURL = nil } } set: { presenting in if !presenting { imagePreviewURL = nil } }
@@ -228,19 +263,6 @@ struct ContentView: View {
ImagePreviewView(url: url) ImagePreviewView(url: url)
} }
} }
.confirmationDialog("Attach", isPresented: $showAttachmentActions, titleVisibility: .visible) {
#if os(iOS)
Button("Image") {
showAttachmentActions = false
DispatchQueue.main.async { showPhotoPicker = true }
}
#endif
Button("File") {
showAttachmentActions = false
DispatchQueue.main.async { showFileImporter = true }
}
Button("Cancel", role: .cancel) {}
}
.alert("Recording Error", isPresented: $showRecordingAlert, actions: { .alert("Recording Error", isPresented: $showRecordingAlert, actions: {
Button("OK", role: .cancel) {} Button("OK", role: .cancel) {}
}, message: { }, message: {
@@ -261,7 +283,7 @@ struct ContentView: View {
Button("content.actions.direct_message") { Button("content.actions.direct_message") {
if let peerID = selectedMessageSenderID { if let peerID = selectedMessageSenderID {
if peerID.hasPrefix("nostr:") { if peerID.isGeoChat {
if let full = viewModel.fullNostrHex(forSenderPeerID: peerID) { if let full = viewModel.fullNostrHex(forSenderPeerID: peerID) {
viewModel.startGeohashDM(withPubkeyHex: full) viewModel.startGeohashDM(withPubkeyHex: full)
} }
@@ -288,7 +310,7 @@ struct ContentView: View {
Button("content.actions.block", role: .destructive) { Button("content.actions.block", role: .destructive) {
// Prefer direct geohash block when we have a Nostr sender ID // Prefer direct geohash block when we have a Nostr sender ID
if let peerID = selectedMessageSenderID, peerID.hasPrefix("nostr:"), if let peerID = selectedMessageSenderID, peerID.isGeoChat,
let full = viewModel.fullNostrHex(forSenderPeerID: peerID), let full = viewModel.fullNostrHex(forSenderPeerID: peerID),
let sender = selectedMessageSender { let sender = selectedMessageSender {
viewModel.blockGeohashUser(pubkeyHexLowercased: full, displayName: sender) viewModel.blockGeohashUser(pubkeyHexLowercased: full, displayName: sender)
@@ -320,10 +342,10 @@ struct ContentView: View {
// MARK: - Message List View // MARK: - Message List View
private func messagesView(privatePeer: String?, isAtBottom: Binding<Bool>) -> some View { private func messagesView(privatePeer: PeerID?, isAtBottom: Binding<Bool>) -> some View {
let messages: [BitchatMessage] = { let messages: [BitchatMessage] = {
if let privatePeer = privatePeer { if let peerID = privatePeer {
return viewModel.getPrivateChatMessages(for: privatePeer) return viewModel.getPrivateChatMessages(for: peerID)
} }
return viewModel.messages return viewModel.messages
}() }()
@@ -462,7 +484,7 @@ struct ContentView: View {
} }
.onChange(of: viewModel.privateChats) { _ in .onChange(of: viewModel.privateChats) { _ in
if let peerID = privatePeer, if let peerID = privatePeer,
let messages = viewModel.privateChats[PeerID(str: peerID)], let messages = viewModel.privateChats[peerID],
!messages.isEmpty { !messages.isEmpty {
// If the newest private message is from me, always scroll // If the newest private message is from me, always scroll
let lastMsg = messages.last! let lastMsg = messages.last!
@@ -581,77 +603,12 @@ struct ContentView: View {
.padding(.horizontal, 12) .padding(.horizontal, 12)
} }
// Command suggestions CommandSuggestionsView(
if showCommandSuggestions && !commandSuggestions.isEmpty { messageText: $messageText,
VStack(alignment: .leading, spacing: 0) { textColor: textColor,
// Define commands with aliases and syntax backgroundColor: backgroundColor,
let baseInfo: [(commands: [String], syntax: String?, description: String)] = [ secondaryTextColor: secondaryTextColor
(["/block"], "[nickname]", "block or list blocked peers"), )
(["/clear"], nil, "clear chat messages"),
(["/hug"], "<nickname>", "send someone a warm hug"),
(["/m", "/msg"], "<nickname> [message]", "send private message"),
(["/slap"], "<nickname>", "slap someone with a trout"),
(["/unblock"], "<nickname>", "unblock a peer"),
(["/w"], nil, "see who's online")
]
let isGeoPublic: Bool = { if case .location = locationManager.selectedChannel { return true }; return false }()
let isGeoDM = viewModel.selectedPrivateChatPeer?.isGeoDM == true
let favInfo: [(commands: [String], syntax: String?, description: String)] = [
(["/fav"], "<nickname>", "add to favorites"),
(["/unfav"], "<nickname>", "remove from favorites")
]
let commandInfo = baseInfo + ((isGeoPublic || isGeoDM) ? [] : favInfo)
// Build the display
let allCommands = commandInfo
// Show matching commands
ForEach(commandSuggestions, id: \.self) { command in
// Find the command info for this suggestion
if let info = allCommands.first(where: { $0.commands.contains(command) }) {
Button(action: {
// Replace current text with selected command
messageText = command + " "
showCommandSuggestions = false
commandSuggestions = []
}) {
HStack {
// Show all aliases together
Text(info.commands.joined(separator: ", "))
.font(.bitchatSystem(size: 11, design: .monospaced))
.foregroundColor(textColor)
.fontWeight(.medium)
// Show syntax if any
if let syntax = info.syntax {
Text(syntax)
.font(.bitchatSystem(size: 10, design: .monospaced))
.foregroundColor(secondaryTextColor.opacity(0.8))
}
Spacer()
// Show description
Text(info.description)
.font(.bitchatSystem(size: 10, design: .monospaced))
.foregroundColor(secondaryTextColor)
}
.padding(.horizontal, 12)
.padding(.vertical, 3)
.frame(maxWidth: .infinity, alignment: .leading)
}
.buttonStyle(.plain)
.background(Color.gray.opacity(0.1))
}
}
}
.background(backgroundColor)
.overlay(
RoundedRectangle(cornerRadius: 4)
.stroke(secondaryTextColor.opacity(0.3), lineWidth: 1)
)
.padding(.horizontal, 12)
}
// Recording indicator // Recording indicator
if isPreparingVoiceNote || isRecordingVoiceNote { if isPreparingVoiceNote || isRecordingVoiceNote {
@@ -685,68 +642,11 @@ struct ContentView: View {
) )
.frame(maxWidth: .infinity, alignment: .leading) .frame(maxWidth: .infinity, alignment: .leading)
.onChange(of: messageText) { newValue in .onChange(of: messageText) { newValue in
// Cancel previous debounce timer
autocompleteDebounceTimer?.invalidate() autocompleteDebounceTimer?.invalidate()
// Debounce autocomplete updates to reduce calls during rapid typing
autocompleteDebounceTimer = Timer.scheduledTimer(withTimeInterval: 0.15, repeats: false) { _ in autocompleteDebounceTimer = Timer.scheduledTimer(withTimeInterval: 0.15, repeats: false) { _ in
// Get cursor position (approximate - end of text for now)
let cursorPosition = newValue.count let cursorPosition = newValue.count
viewModel.updateAutocomplete(for: newValue, cursorPosition: cursorPosition) viewModel.updateAutocomplete(for: newValue, cursorPosition: cursorPosition)
} }
// Check for command autocomplete (instant, no debounce needed)
if newValue.hasPrefix("/") && newValue.count >= 1 {
// Build context-aware command list
let isGeoPublic: Bool = {
if case .location = locationManager.selectedChannel { return true }
return false
}()
let isGeoDM = viewModel.selectedPrivateChatPeer?.isGeoDM == true
var commandDescriptions = [
("/block", String(localized: "content.commands.block", comment: "Description for /block command")),
("/clear", String(localized: "content.commands.clear", comment: "Description for /clear command")),
("/hug", String(localized: "content.commands.hug", comment: "Description for /hug command")),
("/m", String(localized: "content.commands.message", comment: "Description for /m command")),
("/slap", String(localized: "content.commands.slap", comment: "Description for /slap command")),
("/unblock", String(localized: "content.commands.unblock", comment: "Description for /unblock command")),
("/w", String(localized: "content.commands.who", comment: "Description for /w command"))
]
// Only show favorites commands when not in geohash context
if !(isGeoPublic || isGeoDM) {
commandDescriptions.append(("/fav", String(localized: "content.commands.favorite", comment: "Description for /fav command")))
commandDescriptions.append(("/unfav", String(localized: "content.commands.unfavorite", comment: "Description for /unfav command")))
}
let input = newValue.lowercased()
// Map of aliases to primary commands
let aliases: [String: String] = [
"/join": "/j",
"/msg": "/m"
]
// Filter commands, but convert aliases to primary
commandSuggestions = commandDescriptions
.filter { $0.0.starts(with: input) }
.map { $0.0 }
// Also check if input matches an alias
for (alias, primary) in aliases {
if alias.starts(with: input) && !commandSuggestions.contains(primary) {
if commandDescriptions.contains(where: { $0.0 == primary }) {
commandSuggestions.append(primary)
}
}
}
// Remove duplicates and sort
commandSuggestions = Array(Set(commandSuggestions)).sorted()
showCommandSuggestions = !commandSuggestions.isEmpty
} else {
showCommandSuggestions = false
commandSuggestions = []
}
} }
HStack(alignment: .center, spacing: 4) { HStack(alignment: .center, spacing: 4) {
@@ -763,33 +663,62 @@ struct ContentView: View {
.padding(.bottom, 8) .padding(.bottom, 8)
.background(backgroundColor.opacity(0.95)) .background(backgroundColor.opacity(0.95))
} }
private func handleOpenURL(_ url: URL) { private func handleOpenURL(_ url: URL) {
guard url.scheme == "bitchat", url.host == "user" else { return } guard url.scheme == "bitchat" else { return }
let id = url.path.trimmingCharacters(in: CharacterSet(charactersIn: "/")) switch url.host {
let peerID = id.removingPercentEncoding ?? id case "user":
selectedMessageSenderID = peerID let id = url.path.trimmingCharacters(in: CharacterSet(charactersIn: "/"))
let peerID = PeerID(str: id.removingPercentEncoding ?? id)
selectedMessageSenderID = peerID
if peerID.hasPrefix("nostr") { if peerID.isGeoDM || peerID.isGeoChat {
selectedMessageSender = viewModel.geohashDisplayName(for: peerID) selectedMessageSender = viewModel.geohashDisplayName(for: peerID)
} else { } else if let name = viewModel.meshService.peerNickname(peerID: peerID) {
if let name = viewModel.meshService.peerNickname(peerID: PeerID(str: peerID)) {
selectedMessageSender = name selectedMessageSender = name
} else { } else {
selectedMessageSender = viewModel.messages.last(where: { $0.senderPeerID == peerID && $0.sender != "system" })?.sender selectedMessageSender = viewModel.messages.last(where: { $0.senderPeerID == peerID && $0.sender != "system" })?.sender
} }
}
if viewModel.isSelfSender(peerID: selectedMessageSenderID, displayName: selectedMessageSender) { if viewModel.isSelfSender(peerID: peerID, displayName: selectedMessageSender) {
selectedMessageSender = nil selectedMessageSender = nil
selectedMessageSenderID = nil selectedMessageSenderID = nil
} else { } else {
showMessageActions = true showMessageActions = true
}
case "geohash":
let gh = url.path.trimmingCharacters(in: CharacterSet(charactersIn: "/")).lowercased()
let allowed = Set("0123456789bcdefghjkmnpqrstuvwxyz")
guard (2...12).contains(gh.count), gh.allSatisfy({ allowed.contains($0) }) else { return }
func levelForLength(_ len: Int) -> GeohashChannelLevel {
switch len {
case 0...2: return .region
case 3...4: return .province
case 5: return .city
case 6: return .neighborhood
case 7: return .block
default: return .block
}
}
let level = levelForLength(gh.count)
let channel = GeohashChannel(level: level, geohash: gh)
let inRegional = LocationChannelManager.shared.availableChannels.contains { $0.geohash == gh }
if !inRegional && !LocationChannelManager.shared.availableChannels.isEmpty {
LocationChannelManager.shared.markTeleported(for: gh, true)
}
LocationChannelManager.shared.select(ChannelID.location(channel))
default:
return
} }
} }
private func scrollToBottom(on proxy: ScrollViewProxy, private func scrollToBottom(on proxy: ScrollViewProxy,
privatePeer: String?, privatePeer: PeerID?,
isAtBottom: Binding<Bool>) { isAtBottom: Binding<Bool>) {
let targetID: String? = { let targetID: String? = {
if let peer = privatePeer, if let peer = privatePeer,
@@ -802,17 +731,41 @@ struct ContentView: View {
case .location(let ch): return "geo:\(ch.geohash)" case .location(let ch): return "geo:\(ch.geohash)"
} }
}() }()
if let last = viewModel.messages.suffix(300).last?.id { return "\(contextKey)|\(last)" } if let last = viewModel.messages.suffix(300).last?.id {
return "\(contextKey)|\(last)"
}
return nil return nil
}() }()
isAtBottom.wrappedValue = true isAtBottom.wrappedValue = true
guard let target = targetID else { return }
DispatchQueue.main.async { DispatchQueue.main.async {
proxy.scrollTo(target, anchor: .bottom) if let targetID {
proxy.scrollTo(targetID, anchor: .bottom)
}
} }
DispatchQueue.main.asyncAfter(deadline: .now() + 0.1) {
proxy.scrollTo(target, anchor: .bottom) DispatchQueue.main.asyncAfter(deadline: .now() + 0.05) {
let secondTarget: String? = {
if let peer = privatePeer,
let last = viewModel.getPrivateChatMessages(for: peer).suffix(300).last?.id {
return "dm:\(peer)|\(last)"
}
let contextKey: String = {
switch locationManager.selectedChannel {
case .mesh: return "mesh"
case .location(let ch): return "geo:\(ch.geohash)"
}
}()
if let last = viewModel.messages.suffix(300).last?.id {
return "\(contextKey)|\(last)"
}
return nil
}()
if let secondTarget {
proxy.scrollTo(secondTarget, anchor: .bottom)
}
} }
} }
// MARK: - Actions // MARK: - Actions
@@ -845,6 +798,53 @@ struct ContentView: View {
#if os(macOS) #if os(macOS)
.frame(minWidth: 420, minHeight: 520) .frame(minWidth: 420, minHeight: 520)
#endif #endif
// Present image picker from sheet context when IN a sheet (parent-child pattern)
#if os(iOS)
.fullScreenCover(isPresented: Binding(
get: { showImagePicker && (showSidebar || viewModel.selectedPrivateChatPeer != nil) },
set: { newValue in
if !newValue {
showImagePicker = false
}
}
)) {
ImagePickerView(sourceType: imagePickerSourceType) { image in
showImagePicker = false
if let image = image {
Task {
do {
let processedURL = try ImageUtils.processImage(image)
await MainActor.run {
viewModel.sendImage(from: processedURL)
}
} catch {
SecureLogger.error("Image processing failed: \(error)", category: .session)
}
}
}
}
.ignoresSafeArea()
}
#endif
#if os(macOS)
.sheet(isPresented: $showMacImagePicker) {
MacImagePickerView { url in
showMacImagePicker = false
if let url = url {
Task {
do {
let processedURL = try ImageUtils.processImage(at: url)
await MainActor.run {
viewModel.sendImage(from: processedURL)
}
} catch {
SecureLogger.error("Image processing failed: \(error)", category: .session)
}
}
}
}
}
#endif
} }
// MARK: - People Sheet Views // MARK: - People Sheet Views
@@ -953,7 +953,7 @@ struct ContentView: View {
private var privateChatSheetView: some View { private var privateChatSheetView: some View {
VStack(spacing: 0) { VStack(spacing: 0) {
if let privatePeerID = viewModel.selectedPrivateChatPeer?.id { if let privatePeerID = viewModel.selectedPrivateChatPeer {
let headerContext = makePrivateHeaderContext(for: privatePeerID) let headerContext = makePrivateHeaderContext(for: privatePeerID)
HStack(spacing: 12) { HStack(spacing: 12) {
@@ -977,18 +977,19 @@ struct ContentView: View {
HStack(spacing: 8) { HStack(spacing: 8) {
privateHeaderInfo(context: headerContext, privatePeerID: privatePeerID) privateHeaderInfo(context: headerContext, privatePeerID: privatePeerID)
let isFavorite = viewModel.isFavorite(peerID: headerContext.headerPeerID)
if !privatePeerID.hasPrefix("nostr_") { if !privatePeerID.isGeoDM {
Button(action: { Button(action: {
viewModel.toggleFavorite(peerID: headerContext.headerPeerID) viewModel.toggleFavorite(peerID: headerContext.headerPeerID)
}) { }) {
Image(systemName: viewModel.isFavorite(peerID: headerContext.headerPeerID) ? "star.fill" : "star") Image(systemName: isFavorite ? "star.fill" : "star")
.font(.bitchatSystem(size: 14)) .font(.bitchatSystem(size: 14))
.foregroundColor(viewModel.isFavorite(peerID: headerContext.headerPeerID) ? Color.yellow : textColor) .foregroundColor(isFavorite ? Color.yellow : textColor)
} }
.buttonStyle(.plain) .buttonStyle(.plain)
.accessibilityLabel( .accessibilityLabel(
viewModel.isFavorite(peerID: headerContext.headerPeerID) isFavorite
? String(localized: "content.accessibility.remove_favorite", comment: "Accessibility label to remove a favorite") ? String(localized: "content.accessibility.remove_favorite", comment: "Accessibility label to remove a favorite")
: String(localized: "content.accessibility.add_favorite", comment: "Accessibility label to add a favorite") : String(localized: "content.accessibility.add_favorite", comment: "Accessibility label to add a favorite")
) )
@@ -1019,7 +1020,7 @@ struct ContentView: View {
.background(backgroundColor) .background(backgroundColor)
} }
messagesView(privatePeer: viewModel.selectedPrivateChatPeer?.id, isAtBottom: $isAtBottomPrivate) messagesView(privatePeer: viewModel.selectedPrivateChatPeer, isAtBottom: $isAtBottomPrivate)
.background(backgroundColor) .background(backgroundColor)
.frame(maxWidth: .infinity, maxHeight: .infinity) .frame(maxWidth: .infinity, maxHeight: .infinity)
Divider() Divider()
@@ -1041,7 +1042,7 @@ struct ContentView: View {
) )
} }
private func privateHeaderInfo(context: PrivateHeaderContext, privatePeerID: String) -> some View { private func privateHeaderInfo(context: PrivateHeaderContext, privatePeerID: PeerID) -> some View {
Button(action: { Button(action: {
viewModel.showFingerprint(for: context.headerPeerID) viewModel.showFingerprint(for: context.headerPeerID)
}) { }) {
@@ -1066,7 +1067,7 @@ struct ContentView: View {
case .offline: case .offline:
EmptyView() EmptyView()
} }
} else if viewModel.meshService.isPeerReachable(PeerID(str: context.headerPeerID)) { } else if viewModel.meshService.isPeerReachable(context.headerPeerID) {
Image(systemName: "point.3.filled.connected.trianglepath.dotted") Image(systemName: "point.3.filled.connected.trianglepath.dotted")
.font(.bitchatSystem(size: 14)) .font(.bitchatSystem(size: 14))
.foregroundColor(textColor) .foregroundColor(textColor)
@@ -1076,7 +1077,7 @@ struct ContentView: View {
.font(.bitchatSystem(size: 14)) .font(.bitchatSystem(size: 14))
.foregroundColor(.purple) .foregroundColor(.purple)
.accessibilityLabel(String(localized: "content.accessibility.available_nostr", comment: "Accessibility label for Nostr-available peer indicator")) .accessibilityLabel(String(localized: "content.accessibility.available_nostr", comment: "Accessibility label for Nostr-available peer indicator"))
} else if viewModel.meshService.isPeerConnected(PeerID(str: context.headerPeerID)) || viewModel.connectedPeers.contains(context.headerPeerID) { } else if viewModel.meshService.isPeerConnected(context.headerPeerID) || viewModel.connectedPeers.contains(context.headerPeerID) {
Image(systemName: "dot.radiowaves.left.and.right") Image(systemName: "dot.radiowaves.left.and.right")
.font(.bitchatSystem(size: 14)) .font(.bitchatSystem(size: 14))
.foregroundColor(textColor) .foregroundColor(textColor)
@@ -1087,13 +1088,8 @@ struct ContentView: View {
.font(.bitchatSystem(size: 16, weight: .medium, design: .monospaced)) .font(.bitchatSystem(size: 16, weight: .medium, design: .monospaced))
.foregroundColor(textColor) .foregroundColor(textColor)
if !privatePeerID.hasPrefix("nostr_") { if !privatePeerID.isGeoDM {
let statusPeerID: String = { let statusPeerID = viewModel.getShortIDForNoiseKey(privatePeerID)
if privatePeerID.count == 64, let short = viewModel.getShortIDForNoiseKey(privatePeerID) {
return short
}
return context.headerPeerID
}()
let encryptionStatus = viewModel.getEncryptionStatus(for: statusPeerID) let encryptionStatus = viewModel.getEncryptionStatus(for: statusPeerID)
if let icon = encryptionStatus.icon { if let icon = encryptionStatus.icon {
Image(systemName: icon) Image(systemName: icon)
@@ -1126,33 +1122,27 @@ struct ContentView: View {
.frame(height: headerHeight) .frame(height: headerHeight)
} }
private func makePrivateHeaderContext(for privatePeerID: String) -> PrivateHeaderContext { private func makePrivateHeaderContext(for privatePeerID: PeerID) -> PrivateHeaderContext {
let headerPeerID: String = { let headerPeerID = viewModel.getShortIDForNoiseKey(privatePeerID)
if privatePeerID.count == 64, let short = viewModel.getShortIDForNoiseKey(privatePeerID) {
return short
}
return privatePeerID
}()
let peer = viewModel.getPeer(byID: headerPeerID) let peer = viewModel.getPeer(byID: headerPeerID)
let displayName: String = { let displayName: String = {
if privatePeerID.hasPrefix("nostr_"), case .location(let ch) = locationManager.selectedChannel { if privatePeerID.isGeoDM, case .location(let ch) = locationManager.selectedChannel {
let disp = viewModel.geohashDisplayName(for: privatePeerID) let disp = viewModel.geohashDisplayName(for: privatePeerID)
return "#\(ch.geohash)/@\(disp)" return "#\(ch.geohash)/@\(disp)"
} }
if let name = peer?.displayName { return name } if let name = peer?.displayName { return name }
if let name = viewModel.meshService.peerNickname(peerID: PeerID(str: headerPeerID)) { return name } if let name = viewModel.meshService.peerNickname(peerID: headerPeerID) { return name }
if let fav = FavoritesPersistenceService.shared.getFavoriteStatus(for: Data(hexString: headerPeerID) ?? Data()), if let fav = FavoritesPersistenceService.shared.getFavoriteStatus(for: Data(hexString: headerPeerID.id) ?? Data()),
!fav.peerNickname.isEmpty { return fav.peerNickname } !fav.peerNickname.isEmpty { return fav.peerNickname }
if headerPeerID.count == 16 { if headerPeerID.id.count == 16 {
let candidates = viewModel.identityManager.getCryptoIdentitiesByPeerIDPrefix(PeerID(str: headerPeerID)) let candidates = viewModel.identityManager.getCryptoIdentitiesByPeerIDPrefix(headerPeerID)
if let id = candidates.first, if let id = candidates.first,
let social = viewModel.identityManager.getSocialIdentity(for: id.fingerprint) { let social = viewModel.identityManager.getSocialIdentity(for: id.fingerprint) {
if let pet = social.localPetname, !pet.isEmpty { return pet } if let pet = social.localPetname, !pet.isEmpty { return pet }
if !social.claimedNickname.isEmpty { return social.claimedNickname } if !social.claimedNickname.isEmpty { return social.claimedNickname }
} }
} else if headerPeerID.count == 64, let keyData = Data(hexString: headerPeerID) { } else if let keyData = headerPeerID.noiseKey {
let fp = keyData.sha256Fingerprint() let fp = keyData.sha256Fingerprint()
if let social = viewModel.identityManager.getSocialIdentity(for: fp) { if let social = viewModel.identityManager.getSocialIdentity(for: fp) {
if let pet = social.localPetname, !pet.isEmpty { return pet } if let pet = social.localPetname, !pet.isEmpty { return pet }
@@ -1164,7 +1154,7 @@ struct ContentView: View {
let isNostrAvailable: Bool = { let isNostrAvailable: Bool = {
guard let connectionState = peer?.connectionState else { guard let connectionState = peer?.connectionState else {
if let noiseKey = Data(hexString: headerPeerID), if let noiseKey = Data(hexString: headerPeerID.id),
let favoriteStatus = FavoritesPersistenceService.shared.getFavoriteStatus(for: noiseKey), let favoriteStatus = FavoritesPersistenceService.shared.getFavoriteStatus(for: noiseKey),
favoriteStatus.isMutual { favoriteStatus.isMutual {
return true return true
@@ -1294,10 +1284,9 @@ struct ContentView: View {
showLocationNotes = true showLocationNotes = true
}) { }) {
HStack(alignment: .center, spacing: 4) { HStack(alignment: .center, spacing: 4) {
let hasNotes = (notesCounter.count ?? 0) > 0 Image(systemName: "note.text")
Image(systemName: "long.text.page.and.pencil")
.font(.bitchatSystem(size: 12)) .font(.bitchatSystem(size: 12))
.foregroundColor(hasNotes ? textColor : Color.gray) .foregroundColor(Color.orange.opacity(0.8))
.padding(.top, 1) .padding(.top, 1)
} }
.fixedSize(horizontal: true, vertical: false) .fixedSize(horizontal: true, vertical: false)
@@ -1399,7 +1388,7 @@ struct ContentView: View {
}) { }) {
Group { Group {
if let gh = notesGeohash ?? LocationChannelManager.shared.availableChannels.first(where: { $0.level == .building })?.geohash { if let gh = notesGeohash ?? LocationChannelManager.shared.availableChannels.first(where: { $0.level == .building })?.geohash {
LocationNotesView(geohash: gh, onNotesCountChanged: { cnt in sheetNotesCount = cnt }) LocationNotesView(geohash: gh)
.environmentObject(viewModel) .environmentObject(viewModel)
} else { } else {
VStack(spacing: 12) { VStack(spacing: 12) {
@@ -1456,7 +1445,6 @@ struct ContentView: View {
} }
} }
.onAppear { .onAppear {
updateNotesCounterSubscription()
if case .mesh = locationManager.selectedChannel, if case .mesh = locationManager.selectedChannel,
locationManager.permissionState == .authorized, locationManager.permissionState == .authorized,
LocationChannelManager.shared.availableChannels.isEmpty { LocationChannelManager.shared.availableChannels.isEmpty {
@@ -1464,16 +1452,13 @@ struct ContentView: View {
} }
} }
.onChange(of: locationManager.selectedChannel) { _ in .onChange(of: locationManager.selectedChannel) { _ in
updateNotesCounterSubscription()
if case .mesh = locationManager.selectedChannel, if case .mesh = locationManager.selectedChannel,
locationManager.permissionState == .authorized, locationManager.permissionState == .authorized,
LocationChannelManager.shared.availableChannels.isEmpty { LocationChannelManager.shared.availableChannels.isEmpty {
LocationChannelManager.shared.refreshChannels() LocationChannelManager.shared.refreshChannels()
} }
} }
.onChange(of: locationManager.availableChannels) { _ in updateNotesCounterSubscription() }
.onChange(of: locationManager.permissionState) { _ in .onChange(of: locationManager.permissionState) { _ in
updateNotesCounterSubscription()
if case .mesh = locationManager.selectedChannel, if case .mesh = locationManager.selectedChannel,
locationManager.permissionState == .authorized, locationManager.permissionState == .authorized,
LocationChannelManager.shared.availableChannels.isEmpty { LocationChannelManager.shared.availableChannels.isEmpty {
@@ -1490,34 +1475,6 @@ struct ContentView: View {
} }
// MARK: - Notes Counter Subscription Helper
extension ContentView {
private func updateNotesCounterSubscription() {
switch locationManager.selectedChannel {
case .mesh:
// Ensure we have a fresh one-shot location fix so building geohash is current
if locationManager.permissionState == .authorized {
LocationChannelManager.shared.refreshChannels()
}
if locationManager.permissionState == .authorized {
if let building = LocationChannelManager.shared.availableChannels.first(where: { $0.level == .building })?.geohash {
LocationNotesCounter.shared.subscribe(geohash: building)
} else {
// Keep existing subscription if we had one to avoid flicker
// Only cancel if we have no known geohash
if LocationNotesCounter.shared.geohash == nil {
LocationNotesCounter.shared.cancel()
}
}
} else {
LocationNotesCounter.shared.cancel()
}
case .location:
LocationNotesCounter.shared.cancel()
}
}
}
// MARK: - Helper Views // MARK: - Helper Views
// Rounded payment chip button // Rounded payment chip button
@@ -1526,11 +1483,10 @@ extension ContentView {
private enum MessageMedia { private enum MessageMedia {
case voice(URL) case voice(URL)
case image(URL) case image(URL)
case file(URL)
var url: URL { var url: URL {
switch self { switch self {
case .voice(let url), .image(let url), .file(let url): case .voice(let url), .image(let url):
return url return url
} }
} }
@@ -1568,13 +1524,6 @@ private extension ContentView {
let url = baseDirectory.appendingPathComponent(subdir, isDirectory: true).appendingPathComponent(filename) let url = baseDirectory.appendingPathComponent(subdir, isDirectory: true).appendingPathComponent(filename)
return .image(url) return .image(url)
} }
if message.content.hasPrefix("[file] ") {
let filename = String(message.content.dropFirst("[file] ".count)).trimmingCharacters(in: .whitespacesAndNewlines)
guard !filename.isEmpty else { return nil }
let subdir = message.sender == viewModel.nickname ? "files/outgoing" : "files/incoming"
let url = baseDirectory.appendingPathComponent(subdir, isDirectory: true).appendingPathComponent(filename)
return .file(url)
}
return nil return nil
} }
@@ -1591,7 +1540,7 @@ private extension ContentView {
isSending = true isSending = true
progress = Double(reached) / Double(total) progress = Double(reached) / Double(total)
} }
default: case .sent, .read, .delivered, .failed:
break break
} }
} }
@@ -1666,13 +1615,6 @@ private extension ContentView {
} : nil } : nil
) )
.frame(maxWidth: 280) .frame(maxWidth: 280)
case .file(let url):
FileAttachmentView(
url: url,
isSending: state.isSending,
progress: state.progress,
onCancel: cancelAction
)
} }
} }
} }
@@ -1731,7 +1673,7 @@ private extension ContentView {
private func expandWindow(ifNeededFor message: BitchatMessage, private func expandWindow(ifNeededFor message: BitchatMessage,
allMessages: [BitchatMessage], allMessages: [BitchatMessage],
privatePeer: String?, privatePeer: PeerID?,
proxy: ScrollViewProxy) { proxy: ScrollViewProxy) {
let step = TransportConfig.uiWindowStepCount let step = TransportConfig.uiWindowStepCount
let contextKey: String = { let contextKey: String = {
@@ -1791,7 +1733,19 @@ private extension ContentView {
} }
private var shouldShowMediaControls: Bool { private var shouldShowMediaControls: Bool {
if viewModel.selectedPrivateChatPeer != nil { if let peer = viewModel.selectedPrivateChatPeer, !(peer.isGeoDM || peer.isGeoChat) {
return true
}
switch locationManager.selectedChannel {
case .mesh:
return true
case .location:
return false
}
}
private var shouldShowVoiceControl: Bool {
if let peer = viewModel.selectedPrivateChatPeer, !(peer.isGeoDM || peer.isGeoChat) {
return true return true
} }
switch locationManager.selectedChannel { switch locationManager.selectedChannel {
@@ -1807,26 +1761,52 @@ private extension ContentView {
} }
var attachmentButton: some View { var attachmentButton: some View {
Button(action: { showAttachmentActions = true }) { #if os(iOS)
Image(systemName: "paperclip.circle.fill") Image(systemName: "camera.circle.fill")
.font(.bitchatSystem(size: 24))
.foregroundColor(composerAccentColor)
.frame(width: 36, height: 36)
.contentShape(Circle())
.onTapGesture {
// Tap = Photo Library
imagePickerSourceType = .photoLibrary
showImagePicker = true
}
.onLongPressGesture(minimumDuration: 0.3) {
// Long press = Camera
imagePickerSourceType = .camera
showImagePicker = true
}
.accessibilityLabel("Tap for library, long press for camera")
#else
Button(action: { showMacImagePicker = true }) {
Image(systemName: "photo.circle.fill")
.font(.bitchatSystem(size: 24)) .font(.bitchatSystem(size: 24))
.foregroundColor(composerAccentColor) .foregroundColor(composerAccentColor)
.frame(width: 36, height: 36) .frame(width: 36, height: 36)
} }
.buttonStyle(.plain) .buttonStyle(.plain)
.accessibilityLabel("Choose photo")
#endif
} }
@ViewBuilder
var sendOrMicButton: some View { var sendOrMicButton: some View {
let hasText = !trimmedMessageText.isEmpty let hasText = !trimmedMessageText.isEmpty
return ZStack { if shouldShowVoiceControl {
micButtonView ZStack {
.opacity(hasText ? 0 : 1) micButtonView
.allowsHitTesting(!hasText) .opacity(hasText ? 0 : 1)
.allowsHitTesting(!hasText)
sendButtonView(enabled: hasText)
.opacity(hasText ? 1 : 0)
.allowsHitTesting(hasText)
}
.frame(width: 36, height: 36)
} else {
sendButtonView(enabled: hasText) sendButtonView(enabled: hasText)
.opacity(hasText ? 1 : 0) .frame(width: 36, height: 36)
.allowsHitTesting(hasText)
} }
.frame(width: 36, height: 36)
} }
private var micButtonView: some View { private var micButtonView: some View {
@@ -1879,6 +1859,7 @@ private extension ContentView {
} }
func startVoiceRecording() { func startVoiceRecording() {
guard shouldShowVoiceControl else { return }
guard !isRecordingVoiceNote && !isPreparingVoiceNote else { return } guard !isRecordingVoiceNote && !isPreparingVoiceNote else { return }
isPreparingVoiceNote = true isPreparingVoiceNote = true
Task { @MainActor in Task { @MainActor in
@@ -1982,44 +1963,6 @@ private extension ContentView {
} }
} }
#if os(iOS)
func handlePhotoSelection(_ item: PhotosPickerItem) async {
defer { Task { @MainActor in selectedPhotoPickerItem = nil } }
do {
if let data = try await item.loadTransferable(type: Data.self) {
let tempURL = FileManager.default.temporaryDirectory
.appendingPathComponent(UUID().uuidString)
.appendingPathExtension("jpg")
try data.write(to: tempURL, options: Data.WritingOptions.atomic)
await MainActor.run {
viewModel.sendImage(from: tempURL) {
try? FileManager.default.removeItem(at: tempURL)
}
}
}
} catch {
SecureLogger.error("Photo picker load failed: \(error)", category: .session)
}
}
#endif
func handleImportedFile(url: URL) async {
do {
let fileManager = FileManager.default
let tempDir = fileManager.temporaryDirectory
let fileName = url.lastPathComponent.isEmpty ? "attachment" : url.lastPathComponent
let destination = tempDir.appendingPathComponent(UUID().uuidString + "_" + fileName)
if fileManager.fileExists(atPath: destination.path) {
try fileManager.removeItem(at: destination)
}
try fileManager.copyItem(at: url, to: destination)
await MainActor.run {
viewModel.sendFileAttachment(from: destination)
}
} catch {
SecureLogger.error("File copy failed before send: \(error)", category: .session)
}
}
func applicationFilesDirectory() -> URL? { func applicationFilesDirectory() -> URL? {
// Cache the directory lookup to avoid repeated FileManager calls during view rendering // Cache the directory lookup to avoid repeated FileManager calls during view rendering
@@ -2163,3 +2106,87 @@ struct ImagePreviewView: View {
} }
#endif #endif
} }
#if os(iOS)
// MARK: - Image Picker (Camera or Photo Library)
struct ImagePickerView: UIViewControllerRepresentable {
let sourceType: UIImagePickerController.SourceType
let completion: (UIImage?) -> Void
func makeUIViewController(context: Context) -> UIImagePickerController {
let picker = UIImagePickerController()
picker.sourceType = sourceType
picker.delegate = context.coordinator
picker.allowsEditing = false
// Use standard full screen - iOS handles safe areas automatically
picker.modalPresentationStyle = .fullScreen
// Force dark mode to make safe area bars black instead of white
picker.overrideUserInterfaceStyle = .dark
return picker
}
func updateUIViewController(_ uiViewController: UIImagePickerController, context: Context) {}
func makeCoordinator() -> Coordinator {
Coordinator(completion: completion)
}
class Coordinator: NSObject, UIImagePickerControllerDelegate, UINavigationControllerDelegate {
let completion: (UIImage?) -> Void
init(completion: @escaping (UIImage?) -> Void) {
self.completion = completion
}
func imagePickerController(_ picker: UIImagePickerController, didFinishPickingMediaWithInfo info: [UIImagePickerController.InfoKey: Any]) {
let image = info[.originalImage] as? UIImage
completion(image)
}
func imagePickerControllerDidCancel(_ picker: UIImagePickerController) {
completion(nil)
}
}
}
#endif
#if os(macOS)
// MARK: - macOS Image Picker
struct MacImagePickerView: View {
let completion: (URL?) -> Void
@Environment(\.dismiss) private var dismiss
var body: some View {
VStack(spacing: 16) {
Text("Choose an image")
.font(.headline)
Button("Select Image") {
let panel = NSOpenPanel()
panel.allowsMultipleSelection = false
panel.canChooseDirectories = false
panel.canChooseFiles = true
panel.allowedContentTypes = [.image, .png, .jpeg, .heic]
panel.message = "Choose an image to send"
if panel.runModal() == .OK {
completion(panel.url)
} else {
dismiss()
}
}
.buttonStyle(.borderedProminent)
Button("Cancel") {
completion(nil)
}
.buttonStyle(.bordered)
}
.padding(40)
.frame(minWidth: 300, minHeight: 150)
}
}
#endif
+4 -9
View File
@@ -10,7 +10,7 @@ import SwiftUI
struct FingerprintView: View { struct FingerprintView: View {
@ObservedObject var viewModel: ChatViewModel @ObservedObject var viewModel: ChatViewModel
let peerID: String let peerID: PeerID
@Environment(\.dismiss) var dismiss @Environment(\.dismiss) var dismiss
@Environment(\.colorScheme) var colorScheme @Environment(\.colorScheme) var colorScheme
@@ -65,15 +65,12 @@ struct FingerprintView: View {
VStack(alignment: .leading, spacing: 16) { VStack(alignment: .leading, spacing: 16) {
// Prefer short mesh ID for session/encryption status // Prefer short mesh ID for session/encryption status
let statusPeerID: String = { let statusPeerID = viewModel.getShortIDForNoiseKey(peerID)
if peerID.count == 64, let short = viewModel.getShortIDForNoiseKey(peerID) { return short }
return peerID
}()
// Resolve a friendly name // Resolve a friendly name
let peerNickname: String = { let peerNickname: String = {
if let p = viewModel.getPeer(byID: statusPeerID) { return p.displayName } if let p = viewModel.getPeer(byID: statusPeerID) { return p.displayName }
if let name = viewModel.meshService.peerNickname(peerID: PeerID(str: statusPeerID)) { return name } if let name = viewModel.meshService.peerNickname(peerID: statusPeerID) { return name }
if peerID.count == 64, let data = Data(hexString: peerID) { if let data = peerID.noiseKey {
if let fav = FavoritesPersistenceService.shared.getFavoriteStatus(for: data), !fav.peerNickname.isEmpty { return fav.peerNickname } if let fav = FavoritesPersistenceService.shared.getFavoriteStatus(for: data), !fav.peerNickname.isEmpty { return fav.peerNickname }
let fp = data.sha256Fingerprint() let fp = data.sha256Fingerprint()
if let social = viewModel.identityManager.getSocialIdentity(for: fp) { if let social = viewModel.identityManager.getSocialIdentity(for: fp) {
@@ -239,8 +236,6 @@ struct FingerprintView: View {
.padding() .padding()
.frame(maxWidth: .infinity, maxHeight: .infinity) .frame(maxWidth: .infinity, maxHeight: .infinity)
.background(backgroundColor) .background(backgroundColor)
.presentationDetents([.large])
.presentationDragIndicator(.visible)
} }
private func formatFingerprint(_ fingerprint: String) -> String { private func formatFingerprint(_ fingerprint: String) -> String {
+1 -4
View File
@@ -125,9 +125,6 @@ struct LocationChannelsSheet: View {
.navigationTitle("") .navigationTitle("")
#endif #endif
} }
#if os(iOS)
.presentationDetents([.large])
#endif
#if os(macOS) #if os(macOS)
.frame(minWidth: 420, minHeight: 520) .frame(minWidth: 420, minHeight: 520)
#endif #endif
@@ -599,7 +596,7 @@ extension LocationChannelsSheet {
switch level { switch level {
case .region: case .region:
return "" return ""
default: case .building, .block, .neighborhood, .city, .province:
return "~" return "~"
} }
} }
+1 -4
View File
@@ -78,9 +78,6 @@ struct LocationNotesView: View {
.navigationTitle("") .navigationTitle("")
#endif #endif
} }
#if os(iOS)
.presentationDetents([.large])
#endif
.background(backgroundColor) .background(backgroundColor)
.onDisappear { manager.cancel() } .onDisappear { manager.cancel() }
.onChange(of: geohash) { newValue in .onChange(of: geohash) { newValue in
@@ -141,7 +138,7 @@ struct LocationNotesView: View {
String( String(
format: String(localized: "location_notes.header", comment: "Header displaying the geohash and localized note count"), format: String(localized: "location_notes.header", comment: "Header displaying the geohash and localized note count"),
locale: .current, locale: .current,
geohash, count "\(geohash) ± 1", count
) )
} }
@@ -1,118 +0,0 @@
import SwiftUI
struct FileAttachmentView: View {
private let url: URL
private let isSending: Bool
private let progress: Double?
private let onCancel: (() -> Void)?
@Environment(\.colorScheme) private var colorScheme
#if os(iOS)
@State private var showExporter = false
#endif
init(url: URL, isSending: Bool, progress: Double?, onCancel: (() -> Void)?) {
self.url = url
self.isSending = isSending
self.progress = progress
self.onCancel = onCancel
}
private var fileName: String {
url.lastPathComponent
}
private var normalizedProgress: Double? {
guard let progress = progress else { return nil }
return max(0, min(1, progress))
}
var body: some View {
HStack(alignment: .center, spacing: 12) {
Image(systemName: "doc.fill")
.foregroundColor(Color.blue)
.font(.bitchatSystem(size: 24))
VStack(alignment: .leading, spacing: 4) {
Text(fileName)
.font(.bitchatSystem(size: 14, weight: .medium))
.foregroundColor(.primary)
.lineLimit(2)
Text(url.lastPathComponent)
.font(.bitchatSystem(size: 11, design: .monospaced))
.foregroundColor(.secondary)
.lineLimit(1)
if let progress = normalizedProgress {
ProgressView(value: progress)
.progressViewStyle(.linear)
.tint(Color.blue)
}
}
Spacer()
Button(action: openFile) {
Text("open", comment: "Button to open attached file")
.font(.bitchatSystem(size: 13, weight: .semibold))
.padding(.horizontal, 12)
.padding(.vertical, 6)
.background(
Capsule().fill(Color.blue.opacity(0.15))
)
}
.buttonStyle(.plain)
if let onCancel = onCancel, isSending {
Button(action: onCancel) {
Image(systemName: "xmark")
.font(.bitchatSystem(size: 11, weight: .bold))
.frame(width: 26, height: 26)
.background(Circle().fill(Color.red.opacity(0.9)))
.foregroundColor(.white)
}
.buttonStyle(.plain)
}
}
.padding(12)
.background(
RoundedRectangle(cornerRadius: 14)
.fill(colorScheme == .dark ? Color.black.opacity(0.6) : Color.white)
)
.overlay(
RoundedRectangle(cornerRadius: 14)
.stroke(Color.gray.opacity(0.2), lineWidth: 1)
)
#if os(iOS)
.sheet(isPresented: $showExporter) {
FileExportController(url: url)
}
#endif
}
private func openFile() {
#if os(iOS)
showExporter = true
#else
NSWorkspace.shared.open(url)
#endif
}
}
#if os(iOS)
import UniformTypeIdentifiers
import UIKit
private struct FileExportController: UIViewControllerRepresentable {
let url: URL
func makeUIViewController(context: Context) -> UIDocumentPickerViewController {
let controller = UIDocumentPickerViewController(forExporting: [url])
controller.shouldShowFileExtensions = true
return controller
}
func updateUIViewController(_ uiViewController: UIDocumentPickerViewController, context: Context) {}
}
#else
import AppKit
#endif
+11 -11
View File
@@ -4,9 +4,9 @@ struct MeshPeerList: View {
@ObservedObject var viewModel: ChatViewModel @ObservedObject var viewModel: ChatViewModel
let textColor: Color let textColor: Color
let secondaryTextColor: Color let secondaryTextColor: Color
let onTapPeer: (String) -> Void let onTapPeer: (PeerID) -> Void
let onToggleFavorite: (String) -> Void let onToggleFavorite: (PeerID) -> Void
let onShowFingerprint: (String) -> Void let onShowFingerprint: (PeerID) -> Void
@Environment(\.colorScheme) var colorScheme @Environment(\.colorScheme) var colorScheme
@State private var orderedIDs: [String] = [] @State private var orderedIDs: [String] = []
@@ -21,8 +21,8 @@ struct MeshPeerList: View {
let myPeerID = viewModel.meshService.myPeerID let myPeerID = viewModel.meshService.myPeerID
let mapped: [(peer: BitchatPeer, isMe: Bool, hasUnread: Bool, enc: EncryptionStatus)] = viewModel.allPeers.map { peer in let mapped: [(peer: BitchatPeer, isMe: Bool, hasUnread: Bool, enc: EncryptionStatus)] = viewModel.allPeers.map { peer in
let isMe = peer.peerID == myPeerID let isMe = peer.peerID == myPeerID
let hasUnread = viewModel.hasUnreadMessages(for: peer.peerID.id) let hasUnread = viewModel.hasUnreadMessages(for: peer.peerID)
let enc = viewModel.getEncryptionStatus(for: peer.peerID.id) let enc = viewModel.getEncryptionStatus(for: peer.peerID)
return (peer, isMe, hasUnread, enc) return (peer, isMe, hasUnread, enc)
} }
// Stable visual order without mutating state here // Stable visual order without mutating state here
@@ -47,7 +47,7 @@ struct MeshPeerList: View {
let peer = item.peer let peer = item.peer
let isMe = item.isMe let isMe = item.isMe
HStack(spacing: 4) { HStack(spacing: 4) {
let assigned = viewModel.colorForMeshPeer(id: peer.peerID.id, isDark: colorScheme == .dark) let assigned = viewModel.colorForMeshPeer(id: peer.peerID, isDark: colorScheme == .dark)
let baseColor = isMe ? Color.orange : assigned let baseColor = isMe ? Color.orange : assigned
if isMe { if isMe {
Image(systemName: "person.fill") Image(systemName: "person.fill")
@@ -89,7 +89,7 @@ struct MeshPeerList: View {
} }
} }
if !isMe, viewModel.isPeerBlocked(peer.peerID.id) { if !isMe, viewModel.isPeerBlocked(peer.peerID) {
Image(systemName: "nosign") Image(systemName: "nosign")
.font(.bitchatSystem(size: 10)) .font(.bitchatSystem(size: 10))
.foregroundColor(.red) .foregroundColor(.red)
@@ -105,7 +105,7 @@ struct MeshPeerList: View {
} }
} else { } else {
// Offline: prefer showing verified badge from persisted fingerprints // Offline: prefer showing verified badge from persisted fingerprints
if let fp = viewModel.getFingerprint(for: peer.peerID.id), if let fp = viewModel.getFingerprint(for: peer.peerID),
viewModel.verifiedFingerprints.contains(fp) { viewModel.verifiedFingerprints.contains(fp) {
Image(systemName: "checkmark.seal.fill") Image(systemName: "checkmark.seal.fill")
.font(.bitchatSystem(size: 10)) .font(.bitchatSystem(size: 10))
@@ -130,7 +130,7 @@ struct MeshPeerList: View {
} }
if !isMe { if !isMe {
Button(action: { onToggleFavorite(peer.peerID.id) }) { Button(action: { onToggleFavorite(peer.peerID) }) {
Image(systemName: (peer.favoriteStatus?.isFavorite ?? false) ? "star.fill" : "star") Image(systemName: (peer.favoriteStatus?.isFavorite ?? false) ? "star.fill" : "star")
.font(.bitchatSystem(size: 12)) .font(.bitchatSystem(size: 12))
.foregroundColor((peer.favoriteStatus?.isFavorite ?? false) ? .yellow : secondaryTextColor) .foregroundColor((peer.favoriteStatus?.isFavorite ?? false) ? .yellow : secondaryTextColor)
@@ -142,8 +142,8 @@ struct MeshPeerList: View {
.padding(.vertical, 4) .padding(.vertical, 4)
.padding(.top, idx == 0 ? 10 : 0) .padding(.top, idx == 0 ? 10 : 0)
.contentShape(Rectangle()) .contentShape(Rectangle())
.onTapGesture { if !isMe { onTapPeer(peer.peerID.id) } } .onTapGesture { if !isMe { onTapPeer(peer.peerID) } }
.onTapGesture(count: 2) { if !isMe { onShowFingerprint(peer.peerID.id) } } .onTapGesture(count: 2) { if !isMe { onShowFingerprint(peer.peerID) } }
} }
} }
// Seed and update order outside result builder // Seed and update order outside result builder
+1 -5
View File
@@ -373,7 +373,7 @@ struct VerificationSheetView: View {
} }
// Optional: Remove verification for selected peer (if verified) // Optional: Remove verification for selected peer (if verified)
if let pid = viewModel.selectedPrivateChatPeer?.id, if let pid = viewModel.selectedPrivateChatPeer,
let fp = viewModel.getFingerprint(for: pid), let fp = viewModel.getFingerprint(for: pid),
viewModel.verifiedFingerprints.contains(fp) { viewModel.verifiedFingerprints.contains(fp) {
Button(action: { viewModel.unverifyFingerprint(for: pid) }) { Button(action: { viewModel.unverifyFingerprint(for: pid) }) {
@@ -388,10 +388,6 @@ struct VerificationSheetView: View {
.padding(.vertical, 14) .padding(.vertical, 14)
} }
.background(backgroundColor) .background(backgroundColor)
#if os(iOS)
.presentationDetents([.large])
.presentationDragIndicator(.visible)
#endif
.onDisappear { showingScanner = false } .onDisappear { showingScanner = false }
} }
} }
+214 -204
View File
@@ -6,265 +6,275 @@
// For more information, see <https://unlicense.org> // For more information, see <https://unlicense.org>
// //
import XCTest import Testing
import CoreBluetooth import CoreBluetooth
@testable import bitchat @testable import bitchat
final class BLEServiceTests: XCTestCase { struct BLEServiceTests {
private let service: MockBLEService
private let myUUID = UUID()
private let bus = MockBLEBus()
var service: MockBLEService! init() {
service = MockBLEService.init(bus: bus)
override func setUp() { service.myPeerID = PeerID(str: myUUID.uuidString)
super.setUp()
service = MockBLEService()
service.myPeerID = "TEST1234"
service.mockNickname = "TestUser" service.mockNickname = "TestUser"
} }
override func tearDown() {
service = nil
super.tearDown()
}
// MARK: - Basic Functionality Tests // MARK: - Basic Functionality Tests
func testServiceInitialization() { @Test func serviceInitialization() {
XCTAssertNotNil(service) #expect(service.myPeerID == PeerID(str: myUUID.uuidString))
XCTAssertEqual(service.myPeerID, "TEST1234") #expect(service.myNickname == "TestUser")
XCTAssertEqual(service.myNickname, "TestUser")
} }
func testPeerConnection() { @Test func peerConnection() {
// Test connecting a peer let somePeerID = PeerID(str: UUID().uuidString)
service.simulateConnectedPeer("PEER5678")
XCTAssertTrue(service.isPeerConnected("PEER5678"))
XCTAssertEqual(service.getConnectedPeers().count, 1)
// Test disconnecting a peer service.simulateConnectedPeer(somePeerID)
service.simulateDisconnectedPeer("PEER5678") #expect(service.isPeerConnected(somePeerID))
XCTAssertFalse(service.isPeerConnected("PEER5678")) #expect(service.getConnectedPeers().count == 1)
XCTAssertEqual(service.getConnectedPeers().count, 0)
service.simulateDisconnectedPeer(somePeerID)
#expect(!service.isPeerConnected(somePeerID))
#expect(service.getConnectedPeers().count == 0)
} }
func testMultiplePeerConnections() { @Test func multiplePeerConnections() {
service.simulateConnectedPeer("PEER1") let peerID1 = PeerID(str: UUID().uuidString)
service.simulateConnectedPeer("PEER2") let peerID2 = PeerID(str: UUID().uuidString)
service.simulateConnectedPeer("PEER3") let peerID3 = PeerID(str: UUID().uuidString)
service.simulateConnectedPeer(peerID1)
service.simulateConnectedPeer(peerID2)
service.simulateConnectedPeer(peerID3)
XCTAssertEqual(service.getConnectedPeers().count, 3) #expect(service.getConnectedPeers().count == 3)
XCTAssertTrue(service.isPeerConnected("PEER1")) #expect(service.isPeerConnected(peerID1))
XCTAssertTrue(service.isPeerConnected("PEER2")) #expect(service.isPeerConnected(peerID2))
XCTAssertTrue(service.isPeerConnected("PEER3")) #expect(service.isPeerConnected(peerID3))
service.simulateDisconnectedPeer("PEER2") service.simulateDisconnectedPeer(peerID2)
XCTAssertEqual(service.getConnectedPeers().count, 2) #expect(service.getConnectedPeers().count == 2)
XCTAssertFalse(service.isPeerConnected("PEER2")) #expect(!service.isPeerConnected(peerID2))
} }
// MARK: - Message Sending Tests // MARK: - Message Sending Tests
func testSendPublicMessage() { @Test func sendPublicMessage() async throws {
let expectation = XCTestExpectation(description: "Message sent") try await confirmation { receivedPublicMessage in
let delegate = MockBitchatDelegate { message in
let delegate = MockBitchatDelegate { message in #expect(message.content == "Hello, world!")
XCTAssertEqual(message.content, "Hello, world!") #expect(message.sender == "TestUser")
XCTAssertEqual(message.sender, "TestUser") #expect(!message.isPrivate)
XCTAssertFalse(message.isPrivate) receivedPublicMessage()
expectation.fulfill() }
service.delegate = delegate
service.sendMessage("Hello, world!")
// Allow async processing
try await sleep(0.5)
} }
service.delegate = delegate #expect(service.sentMessages.count == 1)
service.sendMessage("Hello, world!")
wait(for: [expectation], timeout: 1.0)
XCTAssertEqual(service.sentMessages.count, 1)
} }
func testSendPrivateMessage() { @Test func sendPrivateMessage() async throws {
let expectation = XCTestExpectation(description: "Private message sent") try await confirmation { receivedPrivateMessage in
let delegate = MockBitchatDelegate { message in
let delegate = MockBitchatDelegate { message in #expect(message.content == "Secret message")
XCTAssertEqual(message.content, "Secret message") #expect(message.sender == "TestUser")
XCTAssertEqual(message.sender, "TestUser") #expect(message.senderPeerID == PeerID(str: myUUID.uuidString))
XCTAssertTrue(message.isPrivate) #expect(message.isPrivate)
XCTAssertEqual(message.recipientNickname, "Bob") #expect(message.recipientNickname == "Bob")
expectation.fulfill() receivedPrivateMessage()
}
service.delegate = delegate
service.sendPrivateMessage(
"Secret message",
to: PeerID(str: UUID().uuidString),
recipientNickname: "Bob",
messageID: "MSG123"
)
// Allow async processing
try await sleep(0.5)
} }
service.delegate = delegate #expect(service.sentMessages.count == 1)
service.sendPrivateMessage("Secret message", to: "PEER5678", recipientNickname: "Bob", messageID: "MSG123")
wait(for: [expectation], timeout: 1.0)
XCTAssertEqual(service.sentMessages.count, 1)
} }
func testSendMessageWithMentions() { @Test func sendMessageWithMentions() async throws {
let expectation = XCTestExpectation(description: "Message with mentions sent") try await confirmation { receivedMessageWithMentions in
let delegate = MockBitchatDelegate { message in
let delegate = MockBitchatDelegate { message in #expect(message.content == "@alice @bob check this out")
XCTAssertEqual(message.content, "@alice @bob check this out") #expect(message.mentions == ["alice", "bob"])
XCTAssertEqual(message.mentions, ["alice", "bob"]) receivedMessageWithMentions()
expectation.fulfill() }
service.delegate = delegate
service.sendMessage("@alice @bob check this out", mentions: ["alice", "bob"])
// Allow async processing
try await sleep(0.5)
} }
service.delegate = delegate
service.sendMessage("@alice @bob check this out", mentions: ["alice", "bob"])
wait(for: [expectation], timeout: 1.0)
} }
// MARK: - Message Reception Tests // MARK: - Message Reception Tests
func testSimulateIncomingMessage() { @Test func simulateIncomingMessage() async throws {
let expectation = XCTestExpectation(description: "Message received") try await confirmation { receiveMessage in
let peerID = PeerID(str: UUID().uuidString)
let delegate = MockBitchatDelegate { message in
XCTAssertEqual(message.content, "Incoming message") let delegate = MockBitchatDelegate { message in
XCTAssertEqual(message.sender, "RemoteUser") #expect(message.content == "Incoming message")
expectation.fulfill() #expect(message.sender == "RemoteUser")
#expect(message.senderPeerID == peerID)
receiveMessage()
}
service.delegate = delegate
let incomingMessage = BitchatMessage(
id: "MSG456",
sender: "RemoteUser",
content: "Incoming message",
timestamp: Date(),
isRelay: false,
originalSender: nil,
isPrivate: false,
recipientNickname: nil,
senderPeerID: peerID,
mentions: nil
)
service.simulateIncomingMessage(incomingMessage)
// Allow async processing
try await sleep(0.5)
} }
service.delegate = delegate
let incomingMessage = BitchatMessage(
id: "MSG456",
sender: "RemoteUser",
content: "Incoming message",
timestamp: Date(),
isRelay: false,
originalSender: nil,
isPrivate: false,
recipientNickname: nil,
senderPeerID: "REMOTE123",
mentions: nil
)
service.simulateIncomingMessage(incomingMessage)
wait(for: [expectation], timeout: 1.0)
} }
func testSimulateIncomingPacket() { @Test func simulateIncomingPacket() async throws {
let expectation = XCTestExpectation(description: "Packet processed") try await confirmation { processPacket in
let peerID = PeerID(str: UUID().uuidString)
let delegate = MockBitchatDelegate { message in
XCTAssertEqual(message.content, "Packet message") let delegate = MockBitchatDelegate { message in
expectation.fulfill() #expect(message.content == "Packet message")
#expect(message.senderPeerID == peerID)
processPacket()
}
service.delegate = delegate
let message = BitchatMessage(
id: "MSG789",
sender: "PacketSender",
content: "Packet message",
timestamp: Date(),
isRelay: false,
originalSender: nil,
isPrivate: false,
recipientNickname: nil,
senderPeerID: peerID,
mentions: nil
)
let payload = try #require(message.toBinaryPayload(), "Failed to create binary payload")
let packet = BitchatPacket(
type: 0x01,
senderID: peerID.id.data(using: .utf8)!,
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload,
signature: nil,
ttl: 3
)
service.simulateIncomingPacket(packet)
// Allow async processing
try await sleep(0.5)
} }
service.delegate = delegate
let message = BitchatMessage(
id: "MSG789",
sender: "PacketSender",
content: "Packet message",
timestamp: Date(),
isRelay: false,
originalSender: nil,
isPrivate: false,
recipientNickname: nil,
senderPeerID: "PACKET123",
mentions: nil
)
guard let payload = message.toBinaryPayload() else {
XCTFail("Failed to create binary payload")
return
}
let packet = BitchatPacket(
type: 0x01,
senderID: "PACKET123".data(using: .utf8)!,
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload,
signature: nil,
ttl: 3
)
service.simulateIncomingPacket(packet)
wait(for: [expectation], timeout: 1.0)
} }
// MARK: - Peer Nickname Tests // MARK: - Peer Nickname Tests
func testGetPeerNicknames() { @Test func getPeerNicknames() {
service.simulateConnectedPeer("PEER1") let peerID1 = PeerID(str: UUID().uuidString)
service.simulateConnectedPeer("PEER2") let peerID2 = PeerID(str: UUID().uuidString)
service.simulateConnectedPeer(peerID1)
service.simulateConnectedPeer(peerID2)
let nicknames = service.getPeerNicknames() let nicknames = service.getPeerNicknames()
XCTAssertEqual(nicknames.count, 2) #expect(nicknames.count == 2)
XCTAssertEqual(nicknames["PEER1"], "MockPeer_PEER1") #expect(nicknames[peerID1] == "MockPeer_\(peerID1)")
XCTAssertEqual(nicknames["PEER2"], "MockPeer_PEER2") #expect(nicknames[peerID2] == "MockPeer_\(peerID2)")
} }
// MARK: - Service State Tests // MARK: - Service State Tests
func testStartStopServices() { @Test func startStopServices() {
// These are mock implementations, just ensure they don't crash
service.startServices() service.startServices()
service.stopServices() service.stopServices()
let somePeerID = PeerID(str: UUID().uuidString)
// Service should still be functional after start/stop service.simulateConnectedPeer(somePeerID)
service.simulateConnectedPeer("PEER999") #expect(service.isPeerConnected(somePeerID))
XCTAssertTrue(service.isPeerConnected("PEER999"))
} }
// MARK: - Message Delivery Handler Tests // MARK: - Message Delivery Handler Tests
func testMessageDeliveryHandler() { @Test func messageDeliveryHandler() async throws {
let expectation = XCTestExpectation(description: "Delivery handler called") try await confirmation { deliveryHandler in
service.packetDeliveryHandler = { packet in
service.packetDeliveryHandler = { packet in if let msg = BitchatMessage(packet.payload) {
if let msg = BitchatMessage(packet.payload) { #expect(msg.content == "Test delivery")
XCTAssertEqual(msg.content, "Test delivery") deliveryHandler()
expectation.fulfill() }
} }
service.sendMessage("Test delivery")
// Allow async processing
try await sleep(0.5)
} }
service.sendMessage("Test delivery")
wait(for: [expectation], timeout: 1.0)
} }
func testPacketDeliveryHandler() { @Test func packetDeliveryHandler() async throws {
let expectation = XCTestExpectation(description: "Packet handler called") try await confirmation("Packet handler called") { packetHandler in
let peerID = PeerID(str: UUID().uuidString)
service.packetDeliveryHandler = { packet in
XCTAssertEqual(packet.type, 0x01) service.packetDeliveryHandler = { packet in
expectation.fulfill() #expect(packet.type == 0x01)
#expect(packet.senderID == Data(peerID.id.utf8))
packetHandler()
}
let message = BitchatMessage(
id: "PKT123",
sender: "TestSender",
content: "Test packet",
timestamp: Date(),
isRelay: false,
originalSender: nil,
isPrivate: false,
recipientNickname: nil,
senderPeerID: peerID,
mentions: nil
)
let payload = try #require(message.toBinaryPayload(), "Failed to create payload")
let packet = BitchatPacket(
type: 0x01,
senderID: peerID.id.data(using: .utf8)!,
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload,
signature: nil,
ttl: 3
)
service.simulateIncomingPacket(packet)
// Allow async processing
try await sleep(0.5)
} }
let message = BitchatMessage(
id: "PKT123",
sender: "TestSender",
content: "Test packet",
timestamp: Date(),
isRelay: false,
originalSender: nil,
isPrivate: false,
recipientNickname: nil,
senderPeerID: "TEST123",
mentions: nil
)
guard let payload = message.toBinaryPayload() else {
XCTFail("Failed to create payload")
return
}
let packet = BitchatPacket(
type: 0x01,
senderID: "TEST123".data(using: .utf8)!,
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: payload,
signature: nil,
ttl: 3
)
service.simulateIncomingPacket(packet)
wait(for: [expectation], timeout: 1.0)
} }
} }
@@ -288,5 +298,5 @@ private final class MockBitchatDelegate: BitchatDelegate {
func didUpdateMessageDeliveryStatus(_ messageID: String, status: DeliveryStatus) {} func didUpdateMessageDeliveryStatus(_ messageID: String, status: DeliveryStatus) {}
func didReceiveNoisePayload(from peerID: PeerID, type: NoisePayloadType, payload: Data, timestamp: Date) {} func didReceiveNoisePayload(from peerID: PeerID, type: NoisePayloadType, payload: Data, timestamp: Date) {}
func didUpdateBluetoothState(_ state: CBManagerState) {} func didUpdateBluetoothState(_ state: CBManagerState) {}
func didReceivePublicMessage(from peerID: String, nickname: String, content: String, timestamp: Date) {} func didReceivePublicMessage(from peerID: PeerID, nickname: String, content: String, timestamp: Date, messageID: String?) {}
} }
+13 -25
View File
@@ -1,54 +1,42 @@
import XCTest import Testing
@testable import bitchat @testable import bitchat
final class CommandProcessorTests: XCTestCase { struct CommandProcessorTests {
private var identityManager = MockIdentityManager(MockKeychain())
var identityManager: MockIdentityManager!
override func setUp() {
super.setUp()
// Provide a minimal identity manager for commands that query identity/block lists
identityManager = MockIdentityManager(MockKeychain())
}
override func tearDown() {
identityManager = nil
super.tearDown()
}
@MainActor @MainActor
func test_slap_notFoundGrammar() { @Test func slapNotFoundGrammar() {
let processor = CommandProcessor(chatViewModel: nil, meshService: nil, identityManager: identityManager) let processor = CommandProcessor(chatViewModel: nil, meshService: nil, identityManager: identityManager)
let result = processor.process("/slap @system") let result = processor.process("/slap @system")
switch result { switch result {
case .error(let message): case .error(let message):
XCTAssertEqual(message, "cannot slap system: not found") #expect(message == "cannot slap system: not found")
default: default:
XCTFail("Expected error result") Issue.record("Expected error result")
} }
} }
@MainActor @MainActor
func test_hug_notFoundGrammar() { @Test func hugNotFoundGrammar() {
let processor = CommandProcessor(chatViewModel: nil, meshService: nil, identityManager: identityManager) let processor = CommandProcessor(chatViewModel: nil, meshService: nil, identityManager: identityManager)
let result = processor.process("/hug @system") let result = processor.process("/hug @system")
switch result { switch result {
case .error(let message): case .error(let message):
XCTAssertEqual(message, "cannot hug system: not found") #expect(message == "cannot hug system: not found")
default: default:
XCTFail("Expected error result") Issue.record("Expected error result")
} }
} }
@MainActor @MainActor
func test_slap_usageMessage() { @Test func slapUsageMessage() {
let processor = CommandProcessor(chatViewModel: nil, meshService: nil, identityManager: identityManager) let processor = CommandProcessor(chatViewModel: nil, meshService: nil, identityManager: identityManager)
let result = processor.process("/slap") let result = processor.process("/slap")
switch result { switch result {
case .error(let message): case .error(let message):
XCTAssertEqual(message, "usage: /slap <nickname>") #expect(message == "usage: /slap <nickname>")
default: default:
XCTFail("Expected error result for usage message") Issue.record("Expected error result for usage message")
} }
} }
} }
+11 -13
View File
@@ -11,21 +11,19 @@ import CryptoKit
import struct Foundation.UUID import struct Foundation.UUID
@testable import bitchat @testable import bitchat
// TODO: Remove once MockBLEService is refactored to fix race condition
@Suite(.serialized)
struct PrivateChatE2ETests { struct PrivateChatE2ETests {
private let alice: MockBLEService private let alice: MockBLEService
private let bob: MockBLEService private let bob: MockBLEService
private let charlie: MockBLEService private let charlie: MockBLEService
private let mockKeychain: MockKeychain private let mockKeychain = MockKeychain()
private let bus = MockBLEBus()
init() { init() {
// Create services with unique peer IDs to avoid any collision // Create services with unique peer IDs to avoid any collision
alice = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname1) alice = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname1, bus: bus)
bob = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname2) bob = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname2, bus: bus)
charlie = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname3) charlie = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname3, bus: bus)
mockKeychain = MockKeychain()
} }
// MARK: - Basic Private Messaging Tests // MARK: - Basic Private Messaging Tests
@@ -53,7 +51,7 @@ struct PrivateChatE2ETests {
) )
// Wait a bit to ensure message would have been delivered if it was going to be // Wait a bit to ensure message would have been delivered if it was going to be
try? await Task.sleep(nanoseconds: UInt64(TestConstants.shortTimeout * 1_000_000_000)) try? await sleep(0.1)
} }
#expect(!bobReceivedMessage, "Bob should not have received the message") #expect(!bobReceivedMessage, "Bob should not have received the message")
@@ -171,7 +169,7 @@ struct PrivateChatE2ETests {
// Send encrypted private message // Send encrypted private message
alice.sendPrivateMessage( alice.sendPrivateMessage(
TestConstants.testMessage1, TestConstants.testMessage1,
to: TestConstants.testPeerID2, to: bob.peerID,
recipientNickname: TestConstants.testNickname2 recipientNickname: TestConstants.testNickname2
) )
} }
@@ -188,11 +186,11 @@ struct PrivateChatE2ETests {
// Bob relays private messages for Charlie // Bob relays private messages for Charlie
bob.packetDeliveryHandler = { packet in bob.packetDeliveryHandler = { packet in
if let recipientID = packet.recipientID, if let recipientID = packet.recipientID,
String(data: recipientID, encoding: .utf8) == charlie.peerID { PeerID(data: recipientID) == charlie.peerID {
// Relay to Charlie // Relay to Charlie
var relayPacket = packet var relayPacket = packet
relayPacket.ttl = packet.ttl - 1 relayPacket.ttl = packet.ttl - 1
self.charlie.simulateIncomingPacket(relayPacket) charlie.simulateIncomingPacket(relayPacket)
} }
} }
@@ -235,7 +233,7 @@ struct PrivateChatE2ETests {
for i in 0..<messageCount { for i in 0..<messageCount {
alice.sendPrivateMessage( alice.sendPrivateMessage(
"Private message \(i)", "Private message \(i)",
to: TestConstants.testPeerID2, to: bob.peerID,
recipientNickname: TestConstants.testNickname2 recipientNickname: TestConstants.testNickname2
) )
} }
@@ -254,7 +252,7 @@ struct PrivateChatE2ETests {
alice.sendPrivateMessage( alice.sendPrivateMessage(
TestConstants.testLongMessage, TestConstants.testLongMessage,
to: TestConstants.testPeerID2, to: bob.peerID,
recipientNickname: TestConstants.testNickname2 recipientNickname: TestConstants.testNickname2
) )
} }
@@ -10,22 +10,22 @@ import Testing
import struct Foundation.UUID import struct Foundation.UUID
@testable import bitchat @testable import bitchat
@Suite(.serialized)
struct PublicChatE2ETests { struct PublicChatE2ETests {
private let alice: MockBLEService private let alice: MockBLEService
private let bob: MockBLEService private let bob: MockBLEService
private let charlie: MockBLEService private let charlie: MockBLEService
private let david: MockBLEService private let david: MockBLEService
private let bus = MockBLEBus()
private var receivedMessages: [String: [BitchatMessage]] = [:] private var receivedMessages: [String: [BitchatMessage]] = [:]
init() { init() {
// Create mock services with unique peer IDs to avoid any collision // Create mock services with unique peer IDs to avoid any collision
alice = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname1) alice = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname1, bus: bus)
bob = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname2) bob = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname2, bus: bus)
charlie = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname3) charlie = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname3, bus: bus)
david = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname4) david = MockBLEService(peerID: PeerID(str: UUID().uuidString), nickname: TestConstants.testNickname4, bus: bus)
} }
// MARK: - Basic Broadcasting Tests // MARK: - Basic Broadcasting Tests
@@ -388,7 +388,7 @@ struct PublicChatE2ETests {
if let message = BitchatMessage(packet.payload) { if let message = BitchatMessage(packet.payload) {
// Don't relay own messages // Don't relay own messages
guard message.senderPeerID?.id != node.peerID else { return } guard message.senderPeerID != node.peerID else { return }
// Create relay message // Create relay message
let relayMessage = BitchatMessage( let relayMessage = BitchatMessage(
@@ -34,7 +34,7 @@ struct FragmentationTests {
ble.delegate = capture ble.delegate = capture
// Construct a big packet (3KB) from a remote sender (not our own ID) // Construct a big packet (3KB) from a remote sender (not our own ID)
let remoteShortID: PeerID = "1122334455667788" let remoteShortID = PeerID(str: "1122334455667788")
let original = makeLargePublicPacket(senderShortHex: remoteShortID, size: 3_000) let original = makeLargePublicPacket(senderShortHex: remoteShortID, size: 3_000)
// Use a small fragment size to ensure multiple pieces // Use a small fragment size to ensure multiple pieces
@@ -45,15 +45,15 @@ struct FragmentationTests {
// Inject fragments spaced out to avoid concurrent mutation inside BLEService // Inject fragments spaced out to avoid concurrent mutation inside BLEService
for (i, fragment) in shuffled.enumerated() { for (i, fragment) in shuffled.enumerated() {
let delay = UInt64(5 * i) * 1_000_000 // nanoseconds let delay = 5 * Double(i) * 0.001
Task { Task {
try await Task.sleep(nanoseconds: delay) try await sleep(delay)
ble._test_handlePacket(fragment, fromPeerID: remoteShortID) ble._test_handlePacket(fragment, fromPeerID: remoteShortID)
} }
} }
// Allow async processing // Allow async processing
try await Task.sleep(nanoseconds: 500_000_000) // 0.5s try await sleep(0.5)
#expect(capture.publicMessages.count == 1) #expect(capture.publicMessages.count == 1)
#expect(capture.publicMessages.first?.content.count == 3_000) #expect(capture.publicMessages.first?.content.count == 3_000)
@@ -69,7 +69,7 @@ struct FragmentationTests {
let capture = CaptureDelegate() let capture = CaptureDelegate()
ble.delegate = capture ble.delegate = capture
let remoteShortID: PeerID = "A1B2C3D4E5F60708" let remoteShortID = PeerID(str: "A1B2C3D4E5F60708")
let original = makeLargePublicPacket(senderShortHex: remoteShortID, size: 2048) let original = makeLargePublicPacket(senderShortHex: remoteShortID, size: 2048)
var frags = fragmentPacket(original, fragmentSize: 300) var frags = fragmentPacket(original, fragmentSize: 300)
@@ -79,19 +79,75 @@ struct FragmentationTests {
} }
for (i, fragment) in frags.enumerated() { for (i, fragment) in frags.enumerated() {
let delay = UInt64(5 * i) * 1_000_000 // nanoseconds let delay = 5 * Double(i) * 0.001
Task { Task {
try await Task.sleep(nanoseconds: delay) try await sleep(delay)
ble._test_handlePacket(fragment, fromPeerID: remoteShortID) ble._test_handlePacket(fragment, fromPeerID: remoteShortID)
} }
} }
// Allow async processing // Allow async processing
try await Task.sleep(nanoseconds: 500_000_000) // 0.5s try await sleep(0.5)
#expect(capture.publicMessages.count == 1) #expect(capture.publicMessages.count == 1)
#expect(capture.publicMessages.first?.content.count == 2048) #expect(capture.publicMessages.first?.content.count == 2048)
} }
@Test("Max-sized file transfer survives reassembly")
func maxSizedFileTransferSurvivesReassembly() async throws {
let ble = BLEService(
keychain: mockKeychain,
idBridge: idBridge,
identityManager: mockIdentityManager
)
let capture = CaptureDelegate()
ble.delegate = capture
let remoteID = PeerID(str: "CAFEBABECAFEBABE")
let fileContent = Data(repeating: 0x42, count: FileTransferLimits.maxPayloadBytes)
let filePacket = BitchatFilePacket(
fileName: "limit.bin",
fileSize: UInt64(fileContent.count),
mimeType: "application/octet-stream",
content: fileContent
)
let encoded = try #require(filePacket.encode(), "File packet encoding failed")
let packet = BitchatPacket(
type: MessageType.fileTransfer.rawValue,
senderID: Data(hexString: remoteID.id) ?? Data(),
recipientID: nil,
timestamp: UInt64(Date().timeIntervalSince1970 * 1000),
payload: encoded,
signature: nil,
ttl: 7,
version: 2
)
let fragments = fragmentPacket(packet, fragmentSize: 4096, pad: false)
#expect(!fragments.isEmpty)
for (i, fragment) in fragments.enumerated() {
let delay = 5 * Double(i) * 0.001
Task {
try await sleep(delay)
ble._test_handlePacket(fragment, fromPeerID: remoteID)
}
}
try await sleep(1.0)
let message = try #require(capture.receivedMessages.first, "Expected file transfer message")
#expect(message.content.hasPrefix("[file]"))
if let fileName = message.content.split(separator: " ").last {
let base = try FileManager.default.url(for: .applicationSupportDirectory, in: .userDomainMask, appropriateFor: nil, create: true)
let filesRoot = base.appendingPathComponent("files", isDirectory: true)
let incoming = filesRoot.appendingPathComponent("files/incoming", isDirectory: true)
let url = incoming.appendingPathComponent(String(fileName))
try? FileManager.default.removeItem(at: url)
}
}
@Test("Invalid fragment header is ignored") @Test("Invalid fragment header is ignored")
func invalidFragmentHeaderIsIgnored() async throws { func invalidFragmentHeaderIsIgnored() async throws {
@@ -103,7 +159,7 @@ struct FragmentationTests {
let capture = CaptureDelegate() let capture = CaptureDelegate()
ble.delegate = capture ble.delegate = capture
let remoteShortID: PeerID = "0011223344556677" let remoteShortID = PeerID(str: "0011223344556677")
let original = makeLargePublicPacket(senderShortHex: remoteShortID, size: 1000) let original = makeLargePublicPacket(senderShortHex: remoteShortID, size: 1000)
let fragments = fragmentPacket(original, fragmentSize: 250) let fragments = fragmentPacket(original, fragmentSize: 250)
@@ -124,16 +180,16 @@ struct FragmentationTests {
} }
for (i, fragment) in corrupted.enumerated() { for (i, fragment) in corrupted.enumerated() {
let delay = UInt64(5 * i) * 1_000_000 // nanoseconds let delay = 5 * Double(i) * 0.001
Task { Task {
try await Task.sleep(nanoseconds: delay) try await sleep(delay)
ble._test_handlePacket(fragment, fromPeerID: remoteShortID) ble._test_handlePacket(fragment, fromPeerID: remoteShortID)
} }
} }
// Allow async processing // Allow async processing
try await Task.sleep(nanoseconds: 500_000_000) // 0.5s try await sleep(0.5)
// Should not deliver since one fragment is invalid and reassembly can't complete // Should not deliver since one fragment is invalid and reassembly can't complete
#expect(capture.publicMessages.isEmpty) #expect(capture.publicMessages.isEmpty)
} }
@@ -142,7 +198,10 @@ struct FragmentationTests {
extension FragmentationTests { extension FragmentationTests {
private final class CaptureDelegate: BitchatDelegate { private final class CaptureDelegate: BitchatDelegate {
var publicMessages: [(peerID: PeerID, nickname: String, content: String)] = [] var publicMessages: [(peerID: PeerID, nickname: String, content: String)] = []
func didReceiveMessage(_ message: BitchatMessage) {} var receivedMessages: [BitchatMessage] = []
func didReceiveMessage(_ message: BitchatMessage) {
receivedMessages.append(message)
}
func didConnectToPeer(_ peerID: PeerID) {} func didConnectToPeer(_ peerID: PeerID) {}
func didDisconnectFromPeer(_ peerID: PeerID) {} func didDisconnectFromPeer(_ peerID: PeerID) {}
func didUpdatePeerList(_ peers: [PeerID]) {} func didUpdatePeerList(_ peers: [PeerID]) {}
@@ -150,7 +209,7 @@ extension FragmentationTests {
func didUpdateMessageDeliveryStatus(_ messageID: String, status: DeliveryStatus) {} func didUpdateMessageDeliveryStatus(_ messageID: String, status: DeliveryStatus) {}
func didReceiveNoisePayload(from peerID: PeerID, type: NoisePayloadType, payload: Data, timestamp: Date) {} func didReceiveNoisePayload(from peerID: PeerID, type: NoisePayloadType, payload: Data, timestamp: Date) {}
func didUpdateBluetoothState(_ state: CBManagerState) {} func didUpdateBluetoothState(_ state: CBManagerState) {}
func didReceivePublicMessage(from peerID: PeerID, nickname: String, content: String, timestamp: Date) { func didReceivePublicMessage(from peerID: PeerID, nickname: String, content: String, timestamp: Date, messageID: String?) {
publicMessages.append((peerID, nickname, content)) publicMessages.append((peerID, nickname, content))
} }
func didReceiveRegionalPublicMessage(from peerID: PeerID, nickname: String, content: String, timestamp: Date) {} func didReceiveRegionalPublicMessage(from peerID: PeerID, nickname: String, content: String, timestamp: Date) {}
@@ -173,8 +232,8 @@ extension FragmentationTests {
} }
// Helper: fragment a packet using the same header format BLEService expects // Helper: fragment a packet using the same header format BLEService expects
private func fragmentPacket(_ packet: BitchatPacket, fragmentSize: Int, fragmentID: Data? = nil) -> [BitchatPacket] { private func fragmentPacket(_ packet: BitchatPacket, fragmentSize: Int, fragmentID: Data? = nil, pad: Bool = true) -> [BitchatPacket] {
let fullData = packet.toBinaryData() ?? Data() guard let fullData = packet.toBinaryData(padding: pad) else { return [] }
let fid = fragmentID ?? Data((0..<8).map { _ in UInt8.random(in: 0...255) }) let fid = fragmentID ?? Data((0..<8).map { _ in UInt8.random(in: 0...255) })
let chunks: [Data] = stride(from: 0, to: fullData.count, by: fragmentSize).map { off in let chunks: [Data] = stride(from: 0, to: fullData.count, by: fragmentSize).map { off in
Data(fullData[off..<min(off + fragmentSize, fullData.count)]) Data(fullData[off..<min(off + fragmentSize, fullData.count)])
+9 -8
View File
@@ -1,22 +1,23 @@
import XCTest import Testing
import struct Foundation.Data
@testable import bitchat @testable import bitchat
final class GCSFilterTests: XCTestCase { struct GCSFilterTests {
func testBuildFilterWithDuplicateIdsProducesStableEncoding() { @Test func buildFilterWithDuplicateIdsProducesStableEncoding() {
let id = Data(repeating: 0xAB, count: 16) let id = Data(repeating: 0xAB, count: 16)
let ids = Array(repeating: id, count: 64) let ids = Array(repeating: id, count: 64)
let params = GCSFilter.buildFilter(ids: ids, maxBytes: 128, targetFpr: 0.01) let params = GCSFilter.buildFilter(ids: ids, maxBytes: 128, targetFpr: 0.01)
XCTAssertGreaterThanOrEqual(params.m, 1) #expect(params.m >= 1)
let decoded = GCSFilter.decodeToSortedSet(p: params.p, m: params.m, data: params.data) let decoded = GCSFilter.decodeToSortedSet(p: params.p, m: params.m, data: params.data)
XCTAssertLessThanOrEqual(decoded.count, 1) #expect(decoded.count <= 1)
} }
func testBucketAvoidsZeroCandidate() { @Test func bucketAvoidsZeroCandidate() {
let id = Data(repeating: 0x01, count: 16) let id = Data(repeating: 0x01, count: 16)
let bucket = GCSFilter.bucket(for: id, modulus: 2) let bucket = GCSFilter.bucket(for: id, modulus: 2)
XCTAssertNotEqual(bucket, 0) #expect(bucket != 0)
XCTAssertLessThan(bucket, 2) #expect(bucket < 2)
} }
} }
+18 -32
View File
@@ -1,52 +1,38 @@
import XCTest import Testing
import Foundation
@testable import bitchat @testable import bitchat
final class GeohashBookmarksStoreTests: XCTestCase { struct GeohashBookmarksStoreTests {
let storeKey = "locationChannel.bookmarks" private let storeKey = "locationChannel.bookmarks"
var storage: UserDefaults! private let storage = UserDefaults(suiteName: UUID().uuidString)!
var store: GeohashBookmarksStore! private let store: GeohashBookmarksStore
override func setUp() { init() {
super.setUp() store = GeohashBookmarksStore(storage: storage)
// Unique instance for each test to avoid race condition
storage = UserDefaults(suiteName: UUID().uuidString)
store = GeohashBookmarksStore(storage: storage!)
} }
override func tearDown() { @Test func toggleAndNormalize() {
storage.removeObject(forKey: storeKey)
store._resetForTesting()
store = nil
storage = nil
super.tearDown()
}
func testToggleAndNormalize() {
// Start clean // Start clean
XCTAssertTrue(store.bookmarks.isEmpty) #expect(store.bookmarks.isEmpty)
// Add with mixed case and hash prefix // Add with mixed case and hash prefix
store.toggle("#U4PRUY") store.toggle("#U4PRUY")
XCTAssertTrue(store.isBookmarked("u4pruy")) #expect(store.isBookmarked("u4pruy"))
XCTAssertEqual(store.bookmarks.first, "u4pruy") #expect(store.bookmarks.first == "u4pruy")
// Toggling again removes // Toggling again removes
store.toggle("u4pruy") store.toggle("u4pruy")
XCTAssertFalse(store.isBookmarked("u4pruy")) #expect(!store.isBookmarked("u4pruy"))
XCTAssertTrue(store.bookmarks.isEmpty) #expect(store.bookmarks.isEmpty)
} }
func testPersistenceWritten() throws { @Test func persistenceWritten() throws {
store.toggle("ezs42") store.toggle("ezs42")
store.toggle("u4pruy") store.toggle("u4pruy")
// Verify persisted JSON contains both (order not enforced here) // Verify persisted JSON contains both (order not enforced here)
guard let data = storage.data(forKey: storeKey) else { let data = try #require(storage.data(forKey: storeKey), "No persisted data found")
XCTFail("No persisted data found")
return
}
let arr = try JSONDecoder().decode([String].self, from: data) let arr = try JSONDecoder().decode([String].self, from: data)
XCTAssertTrue(arr.contains("ezs42")) #expect(arr.contains("ezs42"))
XCTAssertTrue(arr.contains("u4pruy")) #expect(arr.contains("u4pruy"))
} }
} }
+158 -41
View File
@@ -1,24 +1,28 @@
import Foundation import Foundation
import XCTest import Testing
@testable import bitchat @testable import bitchat
final class GossipSyncManagerTests: XCTestCase { struct GossipSyncManagerTests {
func testConcurrentPacketIntakeAndSyncRequest() {
let manager = GossipSyncManager(myPeerID: "0102030405060708") private let myPeerID = PeerID(str: "0102030405060708")
@Test func concurrentPacketIntakeAndSyncRequest() async throws {
let manager = GossipSyncManager(myPeerID: myPeerID)
let delegate = RecordingDelegate() let delegate = RecordingDelegate()
let sendExpectation = expectation(description: "sync request sent")
delegate.onSend = { sendExpectation.fulfill() }
manager.delegate = delegate manager.delegate = delegate
let iterations = 200 try await confirmation("sync request sent") { sent in
let group = DispatchGroup() delegate.onSend = {
sent()
}
for i in 0..<iterations { let iterations = 200
group.enter() let senderID = try #require(Data(hexString: "1122334455667788"))
DispatchQueue.global(qos: .userInitiated).async {
for i in 0..<iterations {
let packet = BitchatPacket( let packet = BitchatPacket(
type: MessageType.message.rawValue, type: MessageType.message.rawValue,
senderID: Data(hexString: "1122334455667788") ?? Data(), senderID: senderID,
recipientID: nil, recipientID: nil,
timestamp: 1_000_000 + UInt64(i), timestamp: 1_000_000 + UInt64(i),
payload: Data([UInt8(truncatingIfNeeded: i)]), payload: Data([UInt8(truncatingIfNeeded: i)]),
@@ -26,35 +30,26 @@ final class GossipSyncManagerTests: XCTestCase {
ttl: 1 ttl: 1
) )
manager.onPublicPacketSeen(packet) manager.onPublicPacketSeen(packet)
Thread.sleep(forTimeInterval: 0.001) try await sleep(0.001)
group.leave()
} }
manager.scheduleInitialSyncToPeer(PeerID(str: "FFFFFFFFFFFFFFFF"), delaySeconds: 0.0)
try await sleep(0.002)
} }
DispatchQueue.global(qos: .userInitiated).asyncAfter(deadline: .now() + 0.002) { let lastPacket = try #require(delegate.lastPacket, "Expected sync packet to be sent")
manager.scheduleInitialSyncToPeer("FFFFFFFFFFFFFFFF", delaySeconds: 0.0) #expect(lastPacket.type == MessageType.requestSync.rawValue)
} #expect(RequestSyncPacket.decode(from: lastPacket.payload) != nil)
group.wait()
wait(for: [sendExpectation], timeout: 2.0)
guard let lastPacket = delegate.lastPacket else {
XCTFail("Expected sync packet to be sent")
return
}
XCTAssertEqual(lastPacket.type, MessageType.requestSync.rawValue)
XCTAssertNotNil(RequestSyncPacket.decode(from: lastPacket.payload))
} }
func testStaleAnnouncementsArePurgedWithMessages() { @Test func staleAnnouncementsArePurgedWithMessages() throws {
var config = GossipSyncManager.Config() var config = GossipSyncManager.Config()
config.stalePeerCleanupIntervalSeconds = 0 config.stalePeerCleanupIntervalSeconds = 0
config.stalePeerTimeoutSeconds = 5 config.stalePeerTimeoutSeconds = 5
let manager = GossipSyncManager(myPeerID: "0102030405060708", config: config) let manager = GossipSyncManager(myPeerID: myPeerID, config: config)
let peerHex = "0011223344556677" let peerHex = "0011223344556677"
let senderData = Data(hexString: peerHex) ?? Data() let senderData = try #require(Data(hexString: peerHex))
let initialTimestampMs = UInt64(Date().timeIntervalSince1970 * 1000) let initialTimestampMs = UInt64(Date().timeIntervalSince1970 * 1000)
let announcePacket = BitchatPacket( let announcePacket = BitchatPacket(
@@ -82,24 +77,24 @@ final class GossipSyncManagerTests: XCTestCase {
// Flush queue without triggering stale cleanup yet // Flush queue without triggering stale cleanup yet
manager._performMaintenanceSynchronously(now: Date()) manager._performMaintenanceSynchronously(now: Date())
XCTAssertTrue(manager._hasAnnouncement(for: PeerID(str: peerHex))) #expect(manager._hasAnnouncement(for: PeerID(str: peerHex)))
XCTAssertEqual(manager._messageCount(for: PeerID(str: peerHex)), 1) #expect(manager._messageCount(for: PeerID(str: peerHex)) == 1)
// Run cleanup past the timeout // Run cleanup past the timeout
let future = Date().addingTimeInterval(config.stalePeerTimeoutSeconds + 1) let future = Date().addingTimeInterval(config.stalePeerTimeoutSeconds + 1)
manager._performMaintenanceSynchronously(now: future) manager._performMaintenanceSynchronously(now: future)
XCTAssertFalse(manager._hasAnnouncement(for: PeerID(str: peerHex))) #expect(manager._hasAnnouncement(for: PeerID(str: peerHex)) == false)
XCTAssertEqual(manager._messageCount(for: PeerID(str: peerHex)), 0) #expect(manager._messageCount(for: PeerID(str: peerHex)) == 0)
} }
func testIgnoresAnnounceOlderThanStaleTimeout() { @Test func ignoresAnnounceOlderThanStaleTimeout() throws {
var config = GossipSyncManager.Config() var config = GossipSyncManager.Config()
config.stalePeerTimeoutSeconds = 5 config.stalePeerTimeoutSeconds = 5
config.maxMessageAgeSeconds = 100 config.maxMessageAgeSeconds = 100
let manager = GossipSyncManager(myPeerID: "0102030405060708", config: config) let manager = GossipSyncManager(myPeerID: myPeerID, config: config)
let peerHex = "8899aabbccddeeff" let peerHex = "8899aabbccddeeff"
let senderData = Data(hexString: peerHex) ?? Data() let senderData = try #require(Data(hexString: peerHex))
let staleTimestampMs = UInt64(Date().addingTimeInterval(-(config.stalePeerTimeoutSeconds + 1)).timeIntervalSince1970 * 1000) let staleTimestampMs = UInt64(Date().addingTimeInterval(-(config.stalePeerTimeoutSeconds + 1)).timeIntervalSince1970 * 1000)
let freshMessage = BitchatPacket( let freshMessage = BitchatPacket(
@@ -127,19 +122,141 @@ final class GossipSyncManagerTests: XCTestCase {
manager._performMaintenanceSynchronously() manager._performMaintenanceSynchronously()
XCTAssertFalse(manager._hasAnnouncement(for: PeerID(str: peerHex))) #expect(manager._hasAnnouncement(for: PeerID(str: peerHex)) == false)
XCTAssertEqual(manager._messageCount(for: PeerID(str: peerHex)), 0) #expect(manager._messageCount(for: PeerID(str: peerHex)) == 0)
}
@Test func maintenanceEmitsTypedSyncRequests() throws {
var config = GossipSyncManager.Config()
config.seenCapacity = 10
config.fragmentCapacity = 5
config.fileTransferCapacity = 4
config.messageSyncIntervalSeconds = 1
config.fragmentSyncIntervalSeconds = 1
config.fileTransferSyncIntervalSeconds = 1
config.maintenanceIntervalSeconds = 0
let manager = GossipSyncManager(myPeerID: myPeerID, config: config)
let delegate = RecordingDelegate()
manager.delegate = delegate
let sender = try #require(Data(hexString: "1122334455667788"))
let now = UInt64(Date().timeIntervalSince1970 * 1000)
let announcePacket = BitchatPacket(
type: MessageType.announce.rawValue,
senderID: sender,
recipientID: nil,
timestamp: now,
payload: Data(),
signature: nil,
ttl: 1
)
let messagePacket = BitchatPacket(
type: MessageType.message.rawValue,
senderID: sender,
recipientID: nil,
timestamp: now,
payload: Data([0x01]),
signature: nil,
ttl: 1
)
let fragmentPacket = BitchatPacket(
type: MessageType.fragment.rawValue,
senderID: sender,
recipientID: nil,
timestamp: now,
payload: Data([0xAA]),
signature: nil,
ttl: 1
)
let filePacket = BitchatPacket(
type: MessageType.fileTransfer.rawValue,
senderID: sender,
recipientID: nil,
timestamp: now,
payload: Data([0xBB]),
signature: nil,
ttl: 1,
version: 2
)
manager.onPublicPacketSeen(announcePacket)
manager.onPublicPacketSeen(messagePacket)
manager.onPublicPacketSeen(fragmentPacket)
manager.onPublicPacketSeen(filePacket)
manager._performMaintenanceSynchronously(now: Date())
let sentPackets = delegate.packets
#expect(sentPackets.count == 3)
let decoded = sentPackets.compactMap { RequestSyncPacket.decode(from: $0.payload) }
#expect(decoded.count == 3)
#expect(decoded[0].types == .publicMessages)
#expect(decoded[1].types == .fragment)
#expect(decoded[2].types == .fileTransfer)
}
@Test func handleRequestSyncHonorsTypeFilter() async throws {
var config = GossipSyncManager.Config()
config.seenCapacity = 5
config.fragmentCapacity = 5
config.fileTransferCapacity = 0
config.messageSyncIntervalSeconds = 0
config.fragmentSyncIntervalSeconds = 0
config.fileTransferSyncIntervalSeconds = 0
let manager = GossipSyncManager(myPeerID: myPeerID, config: config)
let delegate = RecordingDelegate()
manager.delegate = delegate
let sender = try #require(Data(hexString: "aabbccddeeff0011"))
let now = UInt64(Date().timeIntervalSince1970 * 1000)
let messagePacket = BitchatPacket(
type: MessageType.message.rawValue,
senderID: sender,
recipientID: nil,
timestamp: now,
payload: Data([0x10]),
signature: nil,
ttl: 1
)
let fragmentPacket = BitchatPacket(
type: MessageType.fragment.rawValue,
senderID: sender,
recipientID: nil,
timestamp: now,
payload: Data([0x20]),
signature: nil,
ttl: 1
)
manager.onPublicPacketSeen(messagePacket)
manager.onPublicPacketSeen(fragmentPacket)
let peer = PeerID(str: "FFFFFFFFFFFFFFFF")
let request = RequestSyncPacket(p: 4, m: 1, data: Data(), types: .fragment)
manager.handleRequestSync(from: peer, request: request)
try await sleep(0.01)
let sentPackets = delegate.packets
#expect(sentPackets.count == 1)
#expect(sentPackets[0].type == MessageType.fragment.rawValue)
} }
} }
private final class RecordingDelegate: GossipSyncManager.Delegate { private final class RecordingDelegate: GossipSyncManager.Delegate {
var onSend: (() -> Void)? var onSend: (() -> Void)?
private(set) var lastPacket: BitchatPacket? private(set) var lastPacket: BitchatPacket?
private(set) var packets: [BitchatPacket] = []
private let lock = NSLock() private let lock = NSLock()
func sendPacket(_ packet: BitchatPacket) { func sendPacket(_ packet: BitchatPacket) {
lock.lock() lock.lock()
lastPacket = packet lastPacket = packet
packets.append(packet)
lock.unlock() lock.unlock()
onSend?() onSend?()
} }
+192
View File
@@ -0,0 +1,192 @@
//
// InputValidatorTests.swift
// bitchatTests
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import Testing
import Foundation
@testable import bitchat
struct InputValidatorTests {
// MARK: - Basic Validation Tests
@Test func validStringPassesValidation() throws {
let result = InputValidator.validateUserString("Hello World", maxLength: 100)
#expect(result == "Hello World")
}
@Test func emptyStringReturnsNil() throws {
let result = InputValidator.validateUserString("", maxLength: 100)
#expect(result == nil)
}
@Test func whitespaceOnlyStringReturnsNil() throws {
let result = InputValidator.validateUserString(" \n\t ", maxLength: 100)
#expect(result == nil)
}
@Test func stringExceedingMaxLengthReturnsNil() throws {
let longString = String(repeating: "a", count: 101)
let result = InputValidator.validateUserString(longString, maxLength: 100)
#expect(result == nil)
}
@Test func stringAtMaxLengthIsAccepted() throws {
let exactString = String(repeating: "a", count: 100)
let result = InputValidator.validateUserString(exactString, maxLength: 100)
#expect(result == exactString)
}
@Test func whitespaceIsTrimmed() throws {
let result = InputValidator.validateUserString(" Hello ", maxLength: 100)
#expect(result == "Hello")
}
// MARK: - Control Character Tests
@Test func nullCharacterIsRejected() throws {
let stringWithNull = "Hello\u{0000}World"
let result = InputValidator.validateUserString(stringWithNull, maxLength: 100)
#expect(result == nil)
}
@Test func bellCharacterIsRejected() throws {
let stringWithBell = "Hello\u{0007}World"
let result = InputValidator.validateUserString(stringWithBell, maxLength: 100)
#expect(result == nil)
}
@Test func backspaceCharacterIsRejected() throws {
let stringWithBackspace = "Hello\u{0008}World"
let result = InputValidator.validateUserString(stringWithBackspace, maxLength: 100)
#expect(result == nil)
}
@Test func escapeCharacterIsRejected() throws {
let stringWithEscape = "Hello\u{001B}World"
let result = InputValidator.validateUserString(stringWithEscape, maxLength: 100)
#expect(result == nil)
}
@Test func deleteCharacterIsRejected() throws {
let stringWithDelete = "Hello\u{007F}World"
let result = InputValidator.validateUserString(stringWithDelete, maxLength: 100)
#expect(result == nil)
}
@Test func multipleControlCharactersAreRejected() throws {
let stringWithMultiple = "Hello\u{0000}\u{0007}\u{001B}World"
let result = InputValidator.validateUserString(stringWithMultiple, maxLength: 100)
#expect(result == nil)
}
// MARK: - Unicode and Special Character Tests
@Test func emojiIsAccepted() throws {
let result = InputValidator.validateUserString("Hello 👋 World", maxLength: 100)
#expect(result == "Hello 👋 World")
}
@Test func unicodeCharactersAreAccepted() throws {
let result = InputValidator.validateUserString("Hello 世界 مرحبا", maxLength: 100)
#expect(result == "Hello 世界 مرحبا")
}
@Test func specialCharactersAreAccepted() throws {
let result = InputValidator.validateUserString("Hello!@#$%^&*()_+-=[]{}|;':\",./<>?", maxLength: 100)
#expect(result == "Hello!@#$%^&*()_+-=[]{}|;':\",./<>?")
}
// MARK: - Nickname Validation Tests
@Test func validNicknameIsAccepted() throws {
let result = InputValidator.validateNickname("Alice")
#expect(result == "Alice")
}
@Test func nicknameWithEmojiIsAccepted() throws {
let result = InputValidator.validateNickname("Alice 🚀")
#expect(result == "Alice 🚀")
}
@Test func nicknameTooLongIsRejected() throws {
let longNickname = String(repeating: "a", count: 51)
let result = InputValidator.validateNickname(longNickname)
#expect(result == nil)
}
@Test func nicknameAtMaxLengthIsAccepted() throws {
let exactNickname = String(repeating: "a", count: 50)
let result = InputValidator.validateNickname(exactNickname)
#expect(result == exactNickname)
}
@Test func nicknameWithControlCharacterIsRejected() throws {
let result = InputValidator.validateNickname("Alice\u{0000}")
#expect(result == nil)
}
// MARK: - Timestamp Validation Tests
@Test func currentTimestampIsValid() throws {
let now = Date()
let result = InputValidator.validateTimestamp(now)
#expect(result == true)
}
@Test func timestampWithinOneHourIsValid() throws {
let thirtyMinutesAgo = Date().addingTimeInterval(-30 * 60)
let result = InputValidator.validateTimestamp(thirtyMinutesAgo)
#expect(result == true)
}
@Test func timestampTwoHoursAgoIsInvalid() throws {
let twoHoursAgo = Date().addingTimeInterval(-2 * 3600)
let result = InputValidator.validateTimestamp(twoHoursAgo)
#expect(result == false)
}
@Test func timestampTwoHoursInFutureIsInvalid() throws {
let twoHoursFromNow = Date().addingTimeInterval(2 * 3600)
let result = InputValidator.validateTimestamp(twoHoursFromNow)
#expect(result == false)
}
@Test func timestampAtOneHourBoundaryIsValid() throws {
// Just slightly within the one-hour window
let almostOneHourAgo = Date().addingTimeInterval(-3599)
let result = InputValidator.validateTimestamp(almostOneHourAgo)
#expect(result == true)
}
// MARK: - Edge Cases
@Test func singleCharacterStringIsAccepted() throws {
let result = InputValidator.validateUserString("a", maxLength: 100)
#expect(result == "a")
}
@Test func stringWithOnlyNewlinesIsRejected() throws {
let result = InputValidator.validateUserString("\n\n\n", maxLength: 100)
#expect(result == nil)
}
@Test func stringWithMixedWhitespaceIsTrimmed() throws {
let result = InputValidator.validateUserString(" \t\nHello\n\t ", maxLength: 100)
#expect(result == "Hello")
}
@Test func stringWithLeadingControlCharacterIsRejected() throws {
let result = InputValidator.validateUserString("\u{0000}Hello", maxLength: 100)
#expect(result == nil)
}
@Test func stringWithTrailingControlCharacterIsRejected() throws {
let result = InputValidator.validateUserString("Hello\u{0000}", maxLength: 100)
#expect(result == nil)
}
}
+304 -462
View File
@@ -6,52 +6,31 @@
// For more information, see <https://unlicense.org> // For more information, see <https://unlicense.org>
// //
import XCTest import Foundation
import CryptoKit import CryptoKit
import Testing
@testable import bitchat @testable import bitchat
final class IntegrationTests: XCTestCase { struct IntegrationTests {
var nodes: [String: MockBLEService] = [:] private var helper = TestNetworkHelper()
var noiseManagers: [String: NoiseSessionManager] = [:]
private var mockKeychain: MockKeychain!
override func setUp() { init() {
super.setUp() helper.createNode("Alice", peerID: PeerID(str: UUID().uuidString))
// Use the in-memory test bus with autoFlood enabled to simulate helper.createNode("Bob", peerID: PeerID(str: UUID().uuidString))
// broadcast propagation across a larger mesh. Integration-only. helper.createNode("Charlie", peerID: PeerID(str: UUID().uuidString))
MockBLEService.resetTestBus() helper.createNode("David", peerID: PeerID(str: UUID().uuidString))
MockBLEService.autoFloodEnabled = true
mockKeychain = MockKeychain()
// Create a network of nodes
createNode("Alice", peerID: TestConstants.testPeerID1)
createNode("Bob", peerID: TestConstants.testPeerID2)
createNode("Charlie", peerID: TestConstants.testPeerID3)
createNode("David", peerID: TestConstants.testPeerID4)
}
override func tearDown() {
// Disable flooding to avoid cross-test interference
MockBLEService.autoFloodEnabled = false
nodes.removeAll()
noiseManagers.removeAll()
mockKeychain = nil
super.tearDown()
} }
// MARK: - Multi-Peer Scenarios // MARK: - Multi-Peer Scenarios
func testFullMeshCommunication() { @Test func fullMeshCommunication() async throws {
// Create full mesh - everyone connected to everyone helper.connectFullMesh()
connectFullMesh()
let expectation = XCTestExpectation(description: "All nodes communicate")
var messageMatrix: [String: Set<String>] = [:] var messageMatrix: [String: Set<String>] = [:]
for (senderName, _) in helper.nodes { messageMatrix[senderName] = [] }
// Track all receivers; parse sender name from message content "Hello from <Name>" for (receiverName, receiver) in helper.nodes {
for (senderName, _) in nodes { messageMatrix[senderName] = [] }
for (receiverName, receiver) in nodes {
receiver.messageDeliveryHandler = { message in receiver.messageDeliveryHandler = { message in
let parts = message.content.components(separatedBy: " ") let parts = message.content.components(separatedBy: " ")
if let last = parts.last, message.content.contains("Hello from") { if let last = parts.last, message.content.contains("Hello from") {
@@ -62,370 +41,336 @@ final class IntegrationTests: XCTestCase {
} }
} }
// Each node sends a message for (name, node) in helper.nodes {
for (name, node) in nodes { node.sendMessage("Hello from \(name)")
node.sendMessage("Hello from \(name)", mentions: [], to: nil)
} }
// Wait and verify // Each sender should have reached all other nodes
DispatchQueue.main.asyncAfter(deadline: .now() + 1.0) { for (sender, receivers) in messageMatrix {
// Each sender should have reached all other nodes let expectedReceivers = Set(helper.nodes.keys.filter { $0 != sender })
for (sender, receivers) in messageMatrix { #expect(receivers == expectedReceivers, "\(sender) didn't reach all nodes")
let expectedReceivers = Set(self.nodes.keys.filter { $0 != sender })
XCTAssertEqual(receivers, expectedReceivers, "\(sender) didn't reach all nodes")
}
expectation.fulfill()
} }
wait(for: [expectation], timeout: TestConstants.defaultTimeout)
} }
func testDynamicTopologyChanges() { @Test func dynamicTopologyChanges() async throws {
// Start with Alice -> Bob -> Charlie // Start with Alice -> Bob -> Charlie
connect("Alice", "Bob") helper.connect("Alice", "Bob")
connect("Bob", "Charlie") helper.connect("Bob", "Charlie")
let expectation = XCTestExpectation(description: "Topology changes handled") try await confirmation("Topology changes handled") { receiveMessage in
var phase = 1 var phase = 1
// Phase 1: Test initial topology helper.nodes["Charlie"]!.messageDeliveryHandler = { message in
nodes["Charlie"]!.messageDeliveryHandler = { message in if phase == 1 && message.sender == "Alice" {
if phase == 1 && message.sender == "Alice" { // Now change topology: disconnect Bob, connect Alice-Charlie
// Now change topology: disconnect Bob, connect Alice-Charlie helper.disconnect("Alice", "Bob")
self.disconnect("Alice", "Bob") helper.disconnect("Bob", "Charlie")
self.disconnect("Bob", "Charlie") helper.connect("Alice", "Charlie")
self.connect("Alice", "Charlie") phase = 2
phase = 2
// Send another message
// Send another message helper.nodes["Alice"]!.sendMessage("Direct message")
self.nodes["Alice"]!.sendMessage("Direct message", mentions: [], to: nil) } else if phase == 2 && message.content == "Direct message" {
} else if phase == 2 && message.content == "Direct message" { receiveMessage()
expectation.fulfill() }
} }
// Allow relay handler to be set before first send
try await sleep(0.05)
helper.nodes["Alice"]!.sendMessage("Relayed message")
} }
// Initial message through relay
// Allow relay handler to be set before first send
DispatchQueue.main.asyncAfter(deadline: .now() + 0.05) {
self.nodes["Alice"]!.sendMessage("Relayed message", mentions: [], to: nil)
}
wait(for: [expectation], timeout: TestConstants.defaultTimeout)
} }
func testNetworkPartitionRecovery() { @Test func networkPartitionRecovery() async throws {
// Create two partitions // Create two partitions
connect("Alice", "Bob") helper.connect("Alice", "Bob")
connect("Charlie", "David") helper.connect("Charlie", "David")
let expectation = XCTestExpectation(description: "Partitions merge and communicate")
let messagesBeforeMerge = 0 let messagesBeforeMerge = 0
var messagesAfterMerge = 0 var messagesAfterMerge = 0
// Monitor cross-partition messages try await confirmation("Partitions merge and communicate") { receiveMessage in
nodes["David"]!.messageDeliveryHandler = { message in // Monitor cross-partition messages
if message.sender == "Alice" { helper.nodes["David"]!.messageDeliveryHandler = { message in
messagesAfterMerge += 1 if message.sender == "Alice" {
if messagesAfterMerge == 1 { messagesAfterMerge += 1
expectation.fulfill() if messagesAfterMerge == 1 {
receiveMessage()
}
} }
} }
}
// Try to send across partition (should fail)
// Try to send across partition (should fail) helper.nodes["Alice"]!.sendMessage("Before merge")
nodes["Alice"]!.sendMessage("Before merge", mentions: [], to: nil)
// Merge partitions after delay
// Merge partitions after delay try await sleep(0.05)
DispatchQueue.main.asyncAfter(deadline: .now() + 0.5) {
// Connect partitions // Connect partitions
self.connect("Bob", "Charlie") helper.connect("Bob", "Charlie")
// Enable relay // Enable relay
self.setupRelay("Bob", nextHops: ["Charlie"]) helper.setupRelay("Bob", nextHops: ["Charlie"])
self.setupRelay("Charlie", nextHops: ["David"]) helper.setupRelay("Charlie", nextHops: ["David"])
// Send message across merged network // Send message across merged network
self.nodes["Alice"]!.sendMessage("After merge", mentions: [], to: nil) helper.nodes["Alice"]!.sendMessage("After merge")
} }
wait(for: [expectation], timeout: TestConstants.defaultTimeout) #expect(messagesBeforeMerge == 0)
XCTAssertEqual(messagesBeforeMerge, 0) #expect(messagesAfterMerge == 1)
XCTAssertEqual(messagesAfterMerge, 1)
} }
// MARK: - Mixed Message Type Scenarios // MARK: - Mixed Message Type Scenarios
func testMixedPublicPrivateMessages() throws { @Test func mixedPublicPrivateMessages() async throws {
connectFullMesh() helper.connectFullMesh()
let expectation = XCTestExpectation(description: "Mixed messages handled correctly")
var publicCount = 0 var publicCount = 0
var privateCount = 0 var privateCount = 0
// Bob monitors messages await confirmation("Mixed messages handled correctly") { completion in
nodes["Bob"]!.messageDeliveryHandler = { message in // Bob monitors messages
if message.isPrivate && message.recipientNickname == "Bob" { helper.nodes["Bob"]!.messageDeliveryHandler = { message in
privateCount += 1 if message.isPrivate && message.recipientNickname == "Bob" {
} else if !message.isPrivate { privateCount += 1
publicCount += 1 } else if !message.isPrivate {
publicCount += 1
}
if publicCount == 2 && privateCount == 1 {
completion()
}
} }
if publicCount == 2 && privateCount == 1 { // Alice sends mixed messages
expectation.fulfill() helper.nodes["Alice"]!.sendMessage("Public 1")
} helper.nodes["Alice"]!.sendPrivateMessage("Private to Bob", to: helper.nodes["Bob"]!.peerID, recipientNickname: "Bob")
helper.nodes["Alice"]!.sendMessage("Public 2")
} }
// Alice sends mixed messages #expect(publicCount == 2)
nodes["Alice"]!.sendMessage("Public 1", mentions: [], to: nil) #expect(privateCount == 1)
nodes["Alice"]!.sendPrivateMessage("Private to Bob", to: TestConstants.testPeerID2, recipientNickname: "Bob")
nodes["Alice"]!.sendMessage("Public 2", mentions: [], to: nil)
wait(for: [expectation], timeout: TestConstants.defaultTimeout)
XCTAssertEqual(publicCount, 2)
XCTAssertEqual(privateCount, 1)
} }
func testEncryptedAndUnencryptedMix() throws { @Test func encryptedAndUnencryptedMix() async throws {
connect("Alice", "Bob") helper.connect("Alice", "Bob")
// Setup Noise session // Setup Noise session
try establishNoiseSession("Alice", "Bob") try helper.establishNoiseSession("Alice", "Bob")
let expectation = XCTestExpectation(description: "Both encrypted and plain messages work")
var plainCount = 0 var plainCount = 0
var encryptedCount = 0 var encryptedCount = 0
// Setup handlers try await confirmation("Both encrypted and plain messages work") { completion in
// Plain path: send public message and count at Bob // Plain path: send public message and count at Bob
nodes["Bob"]!.messageDeliveryHandler = { message in helper.nodes["Bob"]!.messageDeliveryHandler = { message in
if message.content == "Plain message" { plainCount += 1 } if message.content == "Plain message" {
if plainCount == 1 && encryptedCount == 1 { expectation.fulfill() } plainCount += 1
} }
if plainCount == 1 && encryptedCount == 1 {
// Encrypted path: use NoiseSessionManager explicitly completion()
let plaintext = "Encrypted message".data(using: .utf8)!
let ciphertext = try noiseManagers["Alice"]!.encrypt(plaintext, for: TestConstants.testPeerID2)
nodes["Bob"]!.packetDeliveryHandler = { packet in
if packet.type == MessageType.noiseEncrypted.rawValue {
if let data = try? self.noiseManagers["Bob"]!.decrypt(ciphertext, from: TestConstants.testPeerID1),
data == plaintext {
encryptedCount = 1
if plainCount == 1 { expectation.fulfill() }
} }
} }
// Encrypted path: use NoiseSessionManager explicitly
let plaintext = "Encrypted message".data(using: .utf8)!
let ciphertext = try helper.noiseManagers["Alice"]!.encrypt(plaintext, for: helper.nodes["Bob"]!.peerID)
helper.nodes["Bob"]!.packetDeliveryHandler = { packet in
if packet.type == MessageType.noiseEncrypted.rawValue {
if let data = try? helper.noiseManagers["Bob"]!.decrypt(ciphertext, from: helper.nodes["Alice"]!.peerID),
data == plaintext {
encryptedCount = 1
if plainCount == 1 {
completion()
}
}
}
}
helper.nodes["Alice"]!.sendMessage("Plain message")
// Deliver encrypted packet directly
let encPacket = TestHelpers.createTestPacket(type: MessageType.noiseEncrypted.rawValue, payload: ciphertext)
helper.nodes["Bob"]!.simulateIncomingPacket(encPacket)
} }
nodes["Alice"]!.sendMessage("Plain message", mentions: [], to: nil)
// Deliver encrypted packet directly
let encPacket = TestHelpers.createTestPacket(type: MessageType.noiseEncrypted.rawValue, payload: ciphertext)
nodes["Bob"]!.simulateIncomingPacket(encPacket)
wait(for: [expectation], timeout: TestConstants.defaultTimeout)
} }
// MARK: - Network Resilience Tests // MARK: - Network Resilience Tests
func testMessageDeliveryUnderChurn() { @Test func messageDeliveryUnderChurn() async throws {
// Start with stable network // Start with stable network
connectFullMesh() helper.connectFullMesh()
let expectation = XCTestExpectation(description: "Messages delivered despite churn")
var receivedMessages = Set<String>()
let totalMessages = 10 let totalMessages = 10
// David tracks received messages try await confirmation("Messages delivered despite churn", expectedCount: totalMessages) { completion in
nodes["David"]!.messageDeliveryHandler = { message in // David tracks received messages
receivedMessages.insert(message.content) helper.nodes["David"]!.messageDeliveryHandler = { message in
if receivedMessages.count == totalMessages { completion()
expectation.fulfill()
} }
}
// Send messages while churning network
for i in 0..<totalMessages {
nodes["Alice"]!.sendMessage("Message \(i)", mentions: [], to: nil)
// Simulate churn // Send messages while churning network
if i % 3 == 0 { for i in 0..<totalMessages {
// Disconnect and reconnect random connection helper.nodes["Alice"]!.sendMessage("Message \(i)")
let pairs = [("Alice", "Bob"), ("Bob", "Charlie"), ("Charlie", "David")]
let randomPair = pairs.randomElement()!
disconnect(randomPair.0, randomPair.1)
DispatchQueue.main.asyncAfter(deadline: .now() + 0.1) { // Simulate churn
self.connect(randomPair.0, randomPair.1) if i % 3 == 0 {
// Disconnect and reconnect random connection
let pairs = [("Alice", "Bob"), ("Bob", "Charlie"), ("Charlie", "David")]
let randomPair = pairs.randomElement()!
helper.disconnect(randomPair.0, randomPair.1)
try await sleep(0.01)
helper.connect(randomPair.0, randomPair.1)
} }
} }
} }
}
@Test func peerPresenceTrackingAndReconnection() async throws {
helper.connect("Alice", "Bob")
wait(for: [expectation], timeout: TestConstants.longTimeout) await confirmation("Delivery after reconnection") { delivered in
XCTAssertEqual(receivedMessages.count, totalMessages) helper.nodes["Bob"]!.messageDeliveryHandler = { message in
} if message.content == "After reconnect" {
delivered()
func testPeerPresenceTrackingAndReconnection() { }
// Test that after disconnect/reconnect, message delivery resumes
connect("Alice", "Bob")
let expectation = XCTestExpectation(description: "Delivery after reconnection")
var delivered = false
nodes["Bob"]!.messageDeliveryHandler = { message in
if message.content == "After reconnect" && !delivered {
delivered = true
expectation.fulfill()
} }
// Simulate disconnect (out of range)
helper.disconnect("Alice", "Bob")
// Reconnect
helper.connect("Alice", "Bob")
// Send after reconnection
helper.nodes["Alice"]!.sendMessage("After reconnect")
} }
// Simulate disconnect (out of range)
disconnect("Alice", "Bob")
// Reconnect
connect("Alice", "Bob")
// Send after reconnection
nodes["Alice"]!.sendMessage("After reconnect", mentions: [], to: nil)
wait(for: [expectation], timeout: TestConstants.defaultTimeout)
XCTAssertTrue(delivered)
} }
func testEncryptedMessageAfterPeerRestart() { @Test func encryptedMessageAfterPeerRestart() async throws {
// Test that encrypted messages work after one peer restarts helper.connect("Alice", "Bob")
connect("Alice", "Bob")
do { do {
try establishNoiseSession("Alice", "Bob") try helper.establishNoiseSession("Alice", "Bob")
} catch { } catch {
XCTFail("Failed to establish Noise session: \(error)") Issue.record("Failed to establish Noise session: \(error)")
} }
// Exchange an encrypted message // Exchange an encrypted message
let firstExpectation = XCTestExpectation(description: "First message received") await confirmation("First message received") { received in
nodes["Bob"]!.messageDeliveryHandler = { message in helper.nodes["Bob"]!.messageDeliveryHandler = { message in
if message.content == "Before restart" && message.isPrivate { if message.content == "Before restart" && message.isPrivate {
firstExpectation.fulfill() received()
}
} }
helper.nodes["Alice"]!.sendPrivateMessage("Before restart", to: helper.nodes["Bob"]!.peerID, recipientNickname: "Bob")
} }
nodes["Alice"]!.sendPrivateMessage("Before restart", to: TestConstants.testPeerID2, recipientNickname: "Bob")
wait(for: [firstExpectation], timeout: TestConstants.defaultTimeout)
// Simulate Bob restart by recreating his Noise manager // Simulate Bob restart by recreating his Noise manager
let bobKey = Curve25519.KeyAgreement.PrivateKey() let bobKey = Curve25519.KeyAgreement.PrivateKey()
noiseManagers["Bob"] = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain) helper.noiseManagers["Bob"] = NoiseSessionManager(localStaticKey: bobKey, keychain: helper.mockKeychain)
// Re-establish Noise handshake explicitly via managers // Re-establish Noise handshake explicitly via managers
do { do {
let m1 = try noiseManagers["Bob"]!.initiateHandshake(with: TestConstants.testPeerID1) let m1 = try helper.noiseManagers["Bob"]!.initiateHandshake(with: helper.nodes["Alice"]!.peerID)
let m2 = try noiseManagers["Alice"]!.handleIncomingHandshake(from: TestConstants.testPeerID2, message: m1)! let m2 = try helper.noiseManagers["Alice"]!.handleIncomingHandshake(from: helper.nodes["Bob"]!.peerID, message: m1)!
let m3 = try noiseManagers["Bob"]!.handleIncomingHandshake(from: TestConstants.testPeerID1, message: m2)! let m3 = try helper.noiseManagers["Bob"]!.handleIncomingHandshake(from: helper.nodes["Alice"]!.peerID, message: m2)!
_ = try noiseManagers["Alice"]!.handleIncomingHandshake(from: TestConstants.testPeerID2, message: m3) _ = try helper.noiseManagers["Alice"]!.handleIncomingHandshake(from: helper.nodes["Bob"]!.peerID, message: m3)
} catch { } catch {
XCTFail("Failed to re-establish Noise session after restart: \(error)") Issue.record("Failed to re-establish Noise session after restart: \(error)")
} }
// Now messages should work again // Now messages should work again - simulate encrypted packet
let secondExpectation = XCTestExpectation(description: "Message after restart received") await confirmation("Message after restart received") { received in
nodes["Alice"]!.messageDeliveryHandler = { message in helper.nodes["Alice"]!.messageDeliveryHandler = { message in
if message.content == "After restart success" && message.isPrivate { if message.content == "After restart success" && message.isPrivate {
secondExpectation.fulfill() received()
}
}
// Simulate encrypted message using managers
do {
let plaintext = "After restart success".data(using: .utf8)!
let ciphertext = try noiseManagers["Bob"]!.encrypt(plaintext, for: TestConstants.testPeerID1)
let packet = TestHelpers.createTestPacket(type: MessageType.noiseEncrypted.rawValue, payload: ciphertext)
nodes["Alice"]!.packetDeliveryHandler = { pkt in
if pkt.type == MessageType.noiseEncrypted.rawValue {
if let data = try? self.noiseManagers["Alice"]!.decrypt(pkt.payload, from: TestConstants.testPeerID2),
String(data: data, encoding: .utf8) == "After restart success" {
secondExpectation.fulfill()
}
} }
} }
nodes["Alice"]!.simulateIncomingPacket(packet)
} catch { do {
XCTFail("Encryption after restart failed: \(error)") let plaintext = "After restart success".data(using: .utf8)!
let ciphertext = try helper.noiseManagers["Bob"]!.encrypt(plaintext, for: helper.nodes["Alice"]!.peerID)
let packet = TestHelpers.createTestPacket(type: MessageType.noiseEncrypted.rawValue, payload: ciphertext)
helper.nodes["Alice"]!.packetDeliveryHandler = { pkt in
if pkt.type == MessageType.noiseEncrypted.rawValue {
if let data = try? helper.noiseManagers["Alice"]!.decrypt(pkt.payload, from: helper.nodes["Bob"]!.peerID),
String(data: data, encoding: .utf8) == "After restart success" {
received()
}
}
}
helper.nodes["Alice"]!.simulateIncomingPacket(packet)
} catch {
Issue.record("Encryption after restart failed: \(error)")
}
} }
wait(for: [secondExpectation], timeout: TestConstants.defaultTimeout)
} }
func testLargeScaleNetwork() { @Test func largeScaleNetwork() async throws {
// Create larger network // Create larger network
for i in 5...10 { for i in 5...10 {
createNode("Node\(i)", peerID: "PEER\(i)") helper.createNode("Node\(i)", peerID: PeerID(str: "PEER\(i)"))
} }
// Connect in ring topology with cross-connections // Connect in ring topology with cross-connections
let allNodes = Array(nodes.keys).sorted() let allNodes = Array(helper.nodes.keys).sorted()
for i in 0..<allNodes.count { for i in 0..<allNodes.count {
// Ring connection // Ring connection
connect(allNodes[i], allNodes[(i + 1) % allNodes.count]) helper.connect(allNodes[i], allNodes[(i + 1) % allNodes.count])
// Cross connection // Cross connection
if i + 3 < allNodes.count { if i + 3 < allNodes.count {
connect(allNodes[i], allNodes[i + 3]) helper.connect(allNodes[i], allNodes[i + 3])
} }
} }
let expectation = XCTestExpectation(description: "Large network handles broadcast") await confirmation("Large network handles broadcast", expectedCount: helper.nodes.count - 1) { nodeReaced in
var nodesReached = Set<String>() // All nodes except Alice listen
for (name, node) in helper.nodes where name != "Alice" {
// All nodes except Alice listen node.messageDeliveryHandler = { message in
for (name, node) in nodes where name != "Alice" { if message.content == "Broadcast test" {
node.messageDeliveryHandler = { message in nodeReaced()
if message.content == "Broadcast test" {
nodesReached.insert(name)
if nodesReached.count == self.nodes.count - 1 {
expectation.fulfill()
} }
} }
} }
// Alice broadcasts
helper.nodes["Alice"]!.sendMessage("Broadcast test")
} }
// Alice broadcasts
nodes["Alice"]!.sendMessage("Broadcast test", mentions: [], to: nil)
wait(for: [expectation], timeout: TestConstants.longTimeout)
XCTAssertEqual(nodesReached.count, nodes.count - 1)
} }
// MARK: - Stress Tests // MARK: - Stress Tests
func testHighLoadScenario() { @Test func highLoadScenario() async throws {
connectFullMesh() helper.connectFullMesh()
let messagesPerNode = 25 let messagesPerNode = 25
let expectedTotal = messagesPerNode * nodes.count * (nodes.count - 1) let expectedTotal = messagesPerNode * helper.nodes.count * (helper.nodes.count - 1)
var receivedTotal = 0
let expectation = XCTestExpectation(description: "High load handled")
// Each node tracks messages await confirmation("High load handled", expectedCount: expectedTotal) { received in
for (_, node) in nodes { // Each node tracks messages
node.messageDeliveryHandler = { _ in for (_, node) in helper.nodes {
receivedTotal += 1 node.messageDeliveryHandler = { _ in
if receivedTotal >= (expectedTotal - 2) { received()
expectation.fulfill()
} }
} }
}
// All nodes send many messages simultaneously
// All nodes send many messages simultaneously await withTaskGroup(of: Void.self) { group in
DispatchQueue.concurrentPerform(iterations: nodes.count) { index in for (name, node) in helper.nodes {
let nodeName = Array(nodes.keys).sorted()[index] group.addTask {
for i in 0..<messagesPerNode { for i in 0..<messagesPerNode {
nodes[nodeName]!.sendMessage("\(nodeName) message \(i)", mentions: [], to: nil) node.sendMessage("\(name) message \(i)")
}
}
}
await group.waitForAll()
} }
} }
wait(for: [expectation], timeout: TestConstants.longTimeout)
XCTAssertGreaterThanOrEqual(receivedTotal, expectedTotal - 2)
} }
func testMixedTrafficPatterns() { @Test func mixedTrafficPatterns() async throws {
connectFullMesh() helper.connectFullMesh()
let expectation = XCTestExpectation(description: "Mixed traffic handled")
var metrics = [ var metrics = [
"public": 0, "public": 0,
"private": 0, "private": 0,
@@ -434,7 +379,7 @@ final class IntegrationTests: XCTestCase {
] ]
// Setup complex handlers // Setup complex handlers
for (name, node) in nodes { for (name, node) in helper.nodes {
node.messageDeliveryHandler = { message in node.messageDeliveryHandler = { message in
if message.isPrivate { if message.isPrivate {
metrics["private"]! += 1 metrics["private"]! += 1
@@ -453,222 +398,119 @@ final class IntegrationTests: XCTestCase {
} }
// Generate mixed traffic // Generate mixed traffic
nodes["Alice"]!.sendMessage("Public broadcast", mentions: [], to: nil) helper.nodes["Alice"]!.sendMessage("Public broadcast")
nodes["Alice"]!.sendPrivateMessage("Private to Bob", to: TestConstants.testPeerID2, recipientNickname: "Bob") helper.nodes["Alice"]!.sendPrivateMessage("Private to Bob", to: helper.nodes["Bob"]!.peerID, recipientNickname: "Bob")
nodes["Bob"]!.sendMessage("Mentioning @Charlie", mentions: ["Charlie"], to: nil) helper.nodes["Bob"]!.sendMessage("Mentioning @Charlie", mentions: ["Charlie"])
// Disconnect to force relay // Disconnect to force relay
disconnect("Alice", "David") helper.disconnect("Alice", "David")
nodes["Alice"]!.sendMessage("Needs relay to David", mentions: [], to: nil) helper.nodes["Alice"]!.sendMessage("Needs relay to David")
DispatchQueue.main.asyncAfter(deadline: .now() + 1.0) { #expect(metrics["public", default: 0] > 0)
XCTAssertGreaterThan(metrics["public"]!, 0) #expect(metrics["private", default: 0] > 0)
XCTAssertGreaterThan(metrics["private"]!, 0) #expect(metrics["mentions", default: 0] > 0)
XCTAssertGreaterThan(metrics["mentions"]!, 0)
expectation.fulfill()
}
wait(for: [expectation], timeout: TestConstants.defaultTimeout)
} }
// MARK: - Security Integration Tests // MARK: - Security Integration Tests
// Replacement for the legacy NACK test: verifies that after a // Replacement for the legacy NACK test: verifies that after a
// decryption failure, peers can rehandshake via NoiseSessionManager // decryption failure, peers can rehandshake via NoiseSessionManager
// and resume secure communication. // and resume secure communication.
func testRehandshakeAfterDecryptionFailure() throws { @Test func rehandshakeAfterDecryptionFailure() throws {
// Alice <-> Bob connected // Alice <-> Bob connected
connect("Alice", "Bob") helper.connect("Alice", "Bob")
// Establish initial Noise session // Establish initial Noise session
try establishNoiseSession("Alice", "Bob") try helper.establishNoiseSession("Alice", "Bob")
guard let aliceManager = noiseManagers["Alice"], guard let aliceManager = helper.noiseManagers["Alice"],
let bobManager = noiseManagers["Bob"], let bobManager = helper.noiseManagers["Bob"],
let alicePeerID = nodes["Alice"]?.peerID, let alicePeerID = helper.nodes["Alice"]?.peerID,
let bobPeerID = nodes["Bob"]?.peerID else { let bobPeerID = helper.nodes["Bob"]?.peerID
return XCTFail("Missing managers or peer IDs") else {
Issue.record("Missing managers or peer IDs")
return
} }
// Baseline: encrypt from Alice, decrypt at Bob // Baseline: encrypt from Alice, decrypt at Bob
let plaintext1 = Data("hello-secure".utf8) let plaintext1 = Data("hello-secure".utf8)
let encrypted1 = try aliceManager.encrypt(plaintext1, for: bobPeerID) let encrypted1 = try aliceManager.encrypt(plaintext1, for: bobPeerID)
let decrypted1 = try bobManager.decrypt(encrypted1, from: alicePeerID) let decrypted1 = try bobManager.decrypt(encrypted1, from: alicePeerID)
XCTAssertEqual(decrypted1, plaintext1) #expect(decrypted1 == plaintext1)
// Simulate decryption failure by corrupting ciphertext // Simulate decryption failure by corrupting ciphertext
var corrupted = encrypted1 let corrupted = encrypted1.prefix(15)
if !corrupted.isEmpty { corrupted[corrupted.count - 1] ^= 0xFF } #expect(throws: NoiseError.invalidCiphertext) {
do {
_ = try bobManager.decrypt(corrupted, from: alicePeerID) _ = try bobManager.decrypt(corrupted, from: alicePeerID)
XCTFail("Corrupted ciphertext should not decrypt")
} catch {
// Expected: treat as session desync and rehandshake
} }
// Bob initiates a new handshake; clear Bob's session first so initiateHandshake won't throw // Bob initiates a new handshake; clear Bob's session first so initiateHandshake won't throw
bobManager.removeSession(for: alicePeerID) bobManager.removeSession(for: alicePeerID)
try establishNoiseSession("Bob", "Alice") try helper.establishNoiseSession("Bob", "Alice")
// After rehandshake, encryption/decryption works again // After rehandshake, encryption/decryption works again
let plaintext2 = Data("hello-again".utf8) let plaintext2 = Data("hello-again".utf8)
let encrypted2 = try aliceManager.encrypt(plaintext2, for: bobPeerID) let encrypted2 = try aliceManager.encrypt(plaintext2, for: bobPeerID)
let decrypted2 = try bobManager.decrypt(encrypted2, from: alicePeerID) let decrypted2 = try bobManager.decrypt(encrypted2, from: alicePeerID)
XCTAssertEqual(decrypted2, plaintext2) #expect(decrypted2 == plaintext2)
} }
func testEndToEndSecurityScenario() throws { @Test func endToEndSecurityScenario() async throws {
connect("Alice", "Bob") helper.connect("Alice", "Bob")
connect("Bob", "Charlie") // Charlie will try to eavesdrop helper.connect("Bob", "Charlie") // Charlie will try to eavesdrop
// Establish secure session between Alice and Bob only // Establish secure session between Alice and Bob only
try establishNoiseSession("Alice", "Bob") try helper.establishNoiseSession("Alice", "Bob")
let expectation = XCTestExpectation(description: "Secure communication maintained") await confirmation("Secure communication maintained", expectedCount: 2) { receivedPacket in
var bobDecrypted = false
var charlieIntercepted = false
// Setup encryption at Alice
nodes["Alice"]!.packetDeliveryHandler = { packet in
if packet.type == 0x01,
let message = BitchatMessage(packet.payload),
message.isPrivate && packet.recipientID != nil {
// Encrypt private messages
if let encrypted = try? self.noiseManagers["Alice"]!.encrypt(packet.payload, for: TestConstants.testPeerID2) {
let encPacket = BitchatPacket(
type: 0x02,
senderID: packet.senderID,
recipientID: packet.recipientID,
timestamp: packet.timestamp,
payload: encrypted,
signature: packet.signature,
ttl: packet.ttl
)
self.nodes["Bob"]!.simulateIncomingPacket(encPacket)
}
}
}
// Bob can decrypt
nodes["Bob"]!.packetDeliveryHandler = { packet in
if packet.type == 0x02 {
if let decrypted = try? self.noiseManagers["Bob"]!.decrypt(packet.payload, from: TestConstants.testPeerID1),
let message = BitchatMessage(decrypted) {
bobDecrypted = message.content == "Secret message"
expectation.fulfill()
}
// Relay encrypted packet to Charlie
self.nodes["Charlie"]!.simulateIncomingPacket(packet)
}
}
// Charlie cannot decrypt
nodes["Charlie"]!.packetDeliveryHandler = { packet in
if packet.type == 0x02 {
charlieIntercepted = true
// Try to decrypt (should fail)
do {
_ = try self.noiseManagers["Charlie"]?.decrypt(packet.payload, from: TestConstants.testPeerID1)
XCTFail("Charlie should not be able to decrypt")
} catch {
// Expected
}
}
}
// Send encrypted private message
nodes["Alice"]!.sendPrivateMessage("Secret message", to: TestConstants.testPeerID2, recipientNickname: "Bob")
wait(for: [expectation], timeout: TestConstants.defaultTimeout)
XCTAssertTrue(bobDecrypted)
XCTAssertTrue(charlieIntercepted)
}
// MARK: - Helper Methods
private func createNode(_ name: String, peerID: PeerID) {
let node = MockBLEService()
node.myPeerID = peerID
node.mockNickname = name
nodes[name] = node
// Create Noise manager
let key = Curve25519.KeyAgreement.PrivateKey()
noiseManagers[name] = NoiseSessionManager(localStaticKey: key, keychain: mockKeychain)
}
private func connect(_ node1: String, _ node2: String) {
guard let n1 = nodes[node1], let n2 = nodes[node2] else { return }
n1.simulateConnectedPeer(n2.peerID)
n2.simulateConnectedPeer(n1.peerID)
}
private func disconnect(_ node1: String, _ node2: String) {
guard let n1 = nodes[node1], let n2 = nodes[node2] else { return }
n1.simulateDisconnectedPeer(n2.peerID)
n2.simulateDisconnectedPeer(n1.peerID)
}
private func connectFullMesh() {
let nodeNames = Array(nodes.keys)
for i in 0..<nodeNames.count {
for j in i+1..<nodeNames.count {
connect(nodeNames[i], nodeNames[j])
}
}
}
private func setupRelay(_ nodeName: String, nextHops: [String]) {
guard let node = nodes[nodeName] else { return }
node.packetDeliveryHandler = { packet in
guard packet.ttl > 1 else { return }
if let message = BitchatMessage(packet.payload) { // Setup encryption at Alice
guard message.senderPeerID != node.peerID else { return } helper.nodes["Alice"]!.packetDeliveryHandler = { packet in
if packet.type == 0x01,
let relayMessage = BitchatMessage( let message = BitchatMessage(packet.payload),
id: message.id, message.isPrivate && packet.recipientID != nil {
sender: message.sender, // Encrypt private messages
content: message.content, if let encrypted = try? helper.noiseManagers["Alice"]!.encrypt(packet.payload, for: helper.nodes["Bob"]!.peerID) {
timestamp: message.timestamp, let encPacket = BitchatPacket(
isRelay: true, type: 0x02,
originalSender: message.isRelay ? message.originalSender : message.sender, senderID: packet.senderID,
isPrivate: message.isPrivate, recipientID: packet.recipientID,
recipientNickname: message.recipientNickname, timestamp: packet.timestamp,
senderPeerID: message.senderPeerID, payload: encrypted,
mentions: message.mentions signature: packet.signature,
) ttl: packet.ttl
)
if let relayPayload = relayMessage.toBinaryPayload() { helper.nodes["Bob"]!.simulateIncomingPacket(encPacket)
let relayPacket = BitchatPacket(
type: packet.type,
senderID: packet.senderID,
recipientID: packet.recipientID,
timestamp: packet.timestamp,
payload: relayPayload,
signature: packet.signature,
ttl: packet.ttl - 1
)
for hop in nextHops {
self.nodes[hop]?.simulateIncomingPacket(relayPacket)
} }
} }
} }
// Bob can decrypt
helper.nodes["Bob"]!.packetDeliveryHandler = { packet in
if packet.type == 0x02 {
receivedPacket()
if let decrypted = try? helper.noiseManagers["Bob"]!.decrypt(packet.payload, from: helper.nodes["Alice"]!.peerID) {
#expect(BitchatMessage(decrypted)?.content == "Secret message")
} else {
Issue.record("Bob was unable to decrypt the message")
}
// Relay encrypted packet to Charlie
helper.nodes["Charlie"]!.simulateIncomingPacket(packet)
}
}
// Charlie cannot decrypt
helper.nodes["Charlie"]!.packetDeliveryHandler = { packet in
if packet.type == 0x02 {
receivedPacket()
#expect(throws: NoiseSessionError.sessionNotFound, "Charlie should not be able to decrypt") {
_ = try helper.noiseManagers["Charlie"]?.decrypt(packet.payload, from: helper.nodes["Alice"]!.peerID)
}
}
}
// Send encrypted private message
helper.nodes["Alice"]!.sendPrivateMessage("Secret message", to: helper.nodes["Bob"]!.peerID, recipientNickname: "Bob")
} }
} }
private func establishNoiseSession(_ node1: String, _ node2: String) throws {
guard let manager1 = noiseManagers[node1],
let manager2 = noiseManagers[node2],
let peer1ID = nodes[node1]?.peerID,
let peer2ID = nodes[node2]?.peerID else { return }
let msg1 = try manager1.initiateHandshake(with: peer2ID)
let msg2 = try manager2.handleIncomingHandshake(from: peer1ID, message: msg1)!
let msg3 = try manager1.handleIncomingHandshake(from: peer2ID, message: msg2)!
_ = try manager2.handleIncomingHandshake(from: peer1ID, message: msg3)
}
} }
@@ -0,0 +1,123 @@
//
// TestNetworkHelper.swift
// bitchatTests
//
// Extracted shared, mutable integration state for nodes and noise sessions.
// Keeps test containers nonmutating (Swift Testing-friendly).
//
import Foundation
import CryptoKit
@testable import bitchat
final class TestNetworkHelper {
// Public, read-only views for tests; mutation only through methods
var nodes: [String: MockBLEService] = [:]
var noiseManagers: [String: NoiseSessionManager] = [:]
let mockKeychain = MockKeychain()
private let bus = MockBLEBus(autoFloodEnabled: true)
// MARK: - Node/Manager management
@discardableResult
func createNode(_ name: String, peerID: PeerID) -> MockBLEService {
let node = MockBLEService(bus: bus)
node.myPeerID = peerID
node.mockNickname = name
nodes[name] = node
// Create/replace Noise manager for this node
let key = Curve25519.KeyAgreement.PrivateKey()
noiseManagers[name] = NoiseSessionManager(localStaticKey: key, keychain: mockKeychain)
return node
}
func getNode(_ name: String) -> MockBLEService? {
nodes[name]
}
func getManager(_ name: String) -> NoiseSessionManager? {
noiseManagers[name]
}
// MARK: - Topology
func connect(_ a: String, _ b: String) {
guard let n1 = nodes[a], let n2 = nodes[b] else { return }
n1.simulateConnectedPeer(n2.peerID)
n2.simulateConnectedPeer(n1.peerID)
}
func disconnect(_ a: String, _ b: String) {
guard let n1 = nodes[a], let n2 = nodes[b] else { return }
n1.simulateDisconnectedPeer(n2.peerID)
n2.simulateDisconnectedPeer(n1.peerID)
}
func connectFullMesh() {
let names = Array(nodes.keys)
for i in 0..<names.count {
for j in (i+1)..<names.count {
connect(names[i], names[j])
}
}
}
// MARK: - Relay
func setupRelay(_ nodeName: String, nextHops: [String]) {
guard let node = nodes[nodeName] else { return }
node.packetDeliveryHandler = { [weak self] packet in
guard let self else { return }
guard packet.ttl > 1 else { return }
if let message = BitchatMessage(packet.payload) {
guard message.senderPeerID != node.peerID else { return }
let relayMessage = BitchatMessage(
id: message.id,
sender: message.sender,
content: message.content,
timestamp: message.timestamp,
isRelay: true,
originalSender: message.isRelay ? message.originalSender : message.sender,
isPrivate: message.isPrivate,
recipientNickname: message.recipientNickname,
senderPeerID: message.senderPeerID,
mentions: message.mentions
)
if let relayPayload = relayMessage.toBinaryPayload() {
let relayPacket = BitchatPacket(
type: packet.type,
senderID: packet.senderID,
recipientID: packet.recipientID,
timestamp: packet.timestamp,
payload: relayPayload,
signature: packet.signature,
ttl: packet.ttl - 1
)
for hop in nextHops {
self.nodes[hop]?.simulateIncomingPacket(relayPacket)
}
}
}
}
}
// MARK: - Noise sessions
func establishNoiseSession(_ node1: String, _ node2: String) throws {
guard let manager1 = noiseManagers[node1],
let manager2 = noiseManagers[node2],
let peer1ID = nodes[node1]?.peerID,
let peer2ID = nodes[node2]?.peerID else { return }
let msg1 = try manager1.initiateHandshake(with: peer2ID)
let msg2 = try manager2.handleIncomingHandshake(from: peer1ID, message: msg1)!
let msg3 = try manager1.handleIncomingHandshake(from: peer2ID, message: msg2)!
_ = try manager2.handleIncomingHandshake(from: peer1ID, message: msg3)
}
}
+18 -17
View File
@@ -1,8 +1,9 @@
import XCTest import Testing
import Foundation
@testable import bitchat @testable import bitchat
final class LocationChannelsTests: XCTestCase { struct LocationChannelsTests {
func testGeohashEncoderPrecisionMapping() { @Test func geohashEncoderPrecisionMapping() {
// Sanity: known coords (Statue of Liberty approx) // Sanity: known coords (Statue of Liberty approx)
let lat = 40.6892 let lat = 40.6892
let lon = -74.0445 let lon = -74.0445
@@ -12,35 +13,35 @@ final class LocationChannelsTests: XCTestCase {
let region = Geohash.encode(latitude: lat, longitude: lon, precision: GeohashChannelLevel.province.precision) let region = Geohash.encode(latitude: lat, longitude: lon, precision: GeohashChannelLevel.province.precision)
let country = Geohash.encode(latitude: lat, longitude: lon, precision: GeohashChannelLevel.region.precision) let country = Geohash.encode(latitude: lat, longitude: lon, precision: GeohashChannelLevel.region.precision)
XCTAssertEqual(block.count, 7) #expect(block.count == 7)
XCTAssertEqual(neighborhood.count, 6) #expect(neighborhood.count == 6)
XCTAssertEqual(city.count, 5) #expect(city.count == 5)
XCTAssertEqual(region.count, 4) #expect(region.count == 4)
XCTAssertEqual(country.count, 2) #expect(country.count == 2)
// All prefixes must match progressively // All prefixes must match progressively
XCTAssertTrue(block.hasPrefix(neighborhood)) #expect(block.hasPrefix(neighborhood))
XCTAssertTrue(neighborhood.hasPrefix(city)) #expect(neighborhood.hasPrefix(city))
XCTAssertTrue(city.hasPrefix(region)) #expect(city.hasPrefix(region))
XCTAssertTrue(region.hasPrefix(country)) #expect(region.hasPrefix(country))
} }
func testNostrGeohashFilterEncoding() throws { @Test func nostrGeohashFilterEncoding() throws {
let gh = "u4pruy" let gh = "u4pruy"
let filter = NostrFilter.geohashEphemeral(gh) let filter = NostrFilter.geohashEphemeral(gh)
let data = try JSONEncoder().encode(filter) let data = try JSONEncoder().encode(filter)
let json = String(data: data, encoding: .utf8) ?? "" let json = String(data: data, encoding: .utf8) ?? ""
// Expect kinds includes 20000 and tag filter '#g':[gh] // Expect kinds includes 20000 and tag filter '#g':[gh]
XCTAssertTrue(json.contains("20000")) #expect(json.contains("20000"))
XCTAssertTrue(json.contains("\"#g\":[\"\(gh)\"]")) #expect(json.contains("\"#g\":[\"\(gh)\"]"))
} }
func testPerGeohashIdentityDeterministic() throws { @Test func perGeohashIdentityDeterministic() throws {
// Derive twice for same geohash; should be identical // Derive twice for same geohash; should be identical
let idBridge = NostrIdentityBridge(keychain: MockKeychainHelper()) let idBridge = NostrIdentityBridge(keychain: MockKeychainHelper())
let gh = "u4pruy" let gh = "u4pruy"
let id1 = try idBridge.deriveIdentity(forGeohash: gh) let id1 = try idBridge.deriveIdentity(forGeohash: gh)
let id2 = try idBridge.deriveIdentity(forGeohash: gh) let id2 = try idBridge.deriveIdentity(forGeohash: gh)
XCTAssertEqual(id1.publicKeyHex, id2.publicKeyHex) #expect(id1.publicKeyHex == id2.publicKeyHex)
} }
} }
+11 -68
View File
@@ -1,8 +1,9 @@
import XCTest import Testing
import Foundation
@testable import bitchat @testable import bitchat
@MainActor @MainActor
final class LocationNotesManagerTests: XCTestCase { struct LocationNotesManagerTests {
// func testSubscribeWithoutRelaysSetsNoRelaysState() { // func testSubscribeWithoutRelaysSetsNoRelaysState() {
// var subscribeCalled = false // var subscribeCalled = false
// let deps = LocationNotesDependencies( // let deps = LocationNotesDependencies(
@@ -47,15 +48,15 @@ final class LocationNotesManagerTests: XCTestCase {
// XCTAssertNotEqual(manager.errorMessage, "location_notes.error.no_relays") // XCTAssertNotEqual(manager.errorMessage, "location_notes.error.no_relays")
// } // }
func testSubscribeUsesGeoRelaysAndAppendsNotes() { @Test func subscribeUsesGeoRelaysAndAppendsNotes() {
var relaysCaptured: [String] = [] var relaysCaptured: [String] = []
var storedHandler: ((NostrEvent) -> Void)? var storedHandler: ((NostrEvent) -> Void)?
var storedEOSE: (() -> Void)? var storedEOSE: (() -> Void)?
let deps = LocationNotesDependencies( let deps = LocationNotesDependencies(
relayLookup: { _, _ in ["wss://relay.one"] }, relayLookup: { _, _ in ["wss://relay.one"] },
subscribe: { filter, id, relays, handler, eose in subscribe: { filter, id, relays, handler, eose in
XCTAssertEqual(filter.kinds, [1]) #expect(filter.kinds == [1])
XCTAssertFalse(id.isEmpty) #expect(!id.isEmpty)
relaysCaptured = relays relaysCaptured = relays
storedHandler = handler storedHandler = handler
storedEOSE = eose storedEOSE = eose
@@ -67,8 +68,8 @@ final class LocationNotesManagerTests: XCTestCase {
) )
let manager = LocationNotesManager(geohash: "u4pruydq", dependencies: deps) let manager = LocationNotesManager(geohash: "u4pruydq", dependencies: deps)
XCTAssertEqual(relaysCaptured, ["wss://relay.one"]) #expect(relaysCaptured == ["wss://relay.one"])
XCTAssertEqual(manager.state, .loading) #expect(manager.state == .loading)
var event = NostrEvent( var event = NostrEvent(
pubkey: "pub", pubkey: "pub",
@@ -81,70 +82,12 @@ final class LocationNotesManagerTests: XCTestCase {
storedHandler?(event) storedHandler?(event)
storedEOSE?() storedEOSE?()
XCTAssertEqual(manager.state, .ready) #expect(manager.state == .ready)
XCTAssertEqual(manager.notes.count, 1) #expect(manager.notes.count == 1)
XCTAssertEqual(manager.notes.first?.content, "hi") #expect(manager.notes.first?.content == "hi")
} }
private enum TestError: Error { private enum TestError: Error {
case shouldNotDerive case shouldNotDerive
} }
} }
@MainActor
final class LocationNotesCounterTests: XCTestCase {
func testSubscribeWithoutRelaysMarksUnavailable() {
var subscribeCalled = false
let deps = LocationNotesCounterDependencies(
relayLookup: { _, _ in [] },
subscribe: { _, _, _, _, _ in subscribeCalled = true },
unsubscribe: { _ in }
)
let counter = LocationNotesCounter(testDependencies: deps)
counter.subscribe(geohash: "u4pruydq")
XCTAssertFalse(subscribeCalled)
XCTAssertFalse(counter.relayAvailable)
XCTAssertTrue(counter.initialLoadComplete)
XCTAssertEqual(counter.count, 0)
}
func testSubscribeCountsUniqueNotes() {
var storedHandler: ((NostrEvent) -> Void)?
var storedEOSE: (() -> Void)?
let deps = LocationNotesCounterDependencies(
relayLookup: { _, _ in ["wss://relay.geo"] },
subscribe: { filter, id, relays, handler, eose in
XCTAssertEqual(relays, ["wss://relay.geo"])
XCTAssertEqual(filter.kinds, [1])
XCTAssertFalse(id.isEmpty)
storedHandler = handler
storedEOSE = eose
},
unsubscribe: { _ in }
)
let counter = LocationNotesCounter(testDependencies: deps)
counter.subscribe(geohash: "u4pruydq")
var first = NostrEvent(
pubkey: "pub",
createdAt: Date(),
kind: .textNote,
tags: [["g", "u4pruydq"]],
content: "a"
)
first.id = "eventA"
storedHandler?(first)
let duplicate = first
storedHandler?(duplicate)
storedEOSE?()
XCTAssertTrue(counter.relayAvailable)
XCTAssertEqual(counter.count, 1)
XCTAssertTrue(counter.initialLoadComplete)
}
}
+90
View File
@@ -0,0 +1,90 @@
//
// MimeTypeTests.swift
// bitchatTests
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import Testing
import Foundation
@testable import bitchat
// MARK: - MimeType Mapping and Signature Tests
struct MimeTypeTests {
// MARK: MIME Enum Parsing + Default Extension
@Test(arguments: [
("image/jpeg", MimeType.jpeg, "jpg"),
("image/jpg", MimeType.jpeg, "jpg"),
("image/png", MimeType.png, "png"),
("image/gif", MimeType.gif, "gif"),
("image/webp", MimeType.webp, "webp"),
("audio/mp4", MimeType.mp4Audio, "m4a"),
("audio/m4a", MimeType.m4a, "m4a"),
("audio/aac", MimeType.aac, "m4a"),
("audio/mpeg", MimeType.mpeg, "mp3"),
("audio/mp3", MimeType.mp3, "mp3"),
("audio/wav", MimeType.wav, "wav"),
("audio/x-wav", MimeType.xWav, "wav"),
("audio/ogg", MimeType.ogg, "ogg"),
("application/pdf", MimeType.pdf, "pdf"),
("application/octet-stream", MimeType.octetStream, "bin")
])
func mimeTypeParsingAndExtensions(
mimeString: String,
expectedType: MimeType,
expectedExt: String
) throws {
guard let mime = MimeType(mimeString) else {
Issue.record("Failed to parse \(mimeString)")
return
}
#expect(mime == expectedType, "Expected \(expectedType) for \(mimeString)")
#expect(mime.mimeString == expectedType.mimeString)
#expect(mime.defaultExtension == expectedExt)
#expect(mime.isAllowed)
}
// MARK: - File Signature Validation
@Test(arguments: [
// === Image types ===
(MimeType.jpeg, [0xFF, 0xD8, 0xFF]),
(MimeType.png, [0x89, 0x50, 0x4E, 0x47, 0x0D, 0x0A, 0x1A, 0x0A]),
(MimeType.gif, [0x47, 0x49, 0x46, 0x38, 0x39, 0x61]), // "GIF89a"
(MimeType.webp, [0x52, 0x49, 0x46, 0x46, 0x00, 0x00, 0x00, 0x00,
0x57, 0x45, 0x42, 0x50]), // "RIFF....WEBP"
// === Audio types ===
(MimeType.mp3, [0x49, 0x44, 0x33]), // "ID3"
(MimeType.wav, [0x52, 0x49, 0x46, 0x46, 0x00, 0x00, 0x00, 0x00,
0x57, 0x41, 0x56, 0x45]), // "RIFF....WAVE"
(MimeType.ogg, [0x4F, 0x67, 0x67, 0x53]), // "OggS"
// === Application types ===
(MimeType.pdf, [0x25, 0x50, 0x44, 0x46]) // "%PDF"
])
func validSignatures(mime: MimeType, bytes: [UInt8]) throws {
let data = Data(bytes)
#expect(mime.matches(data: data),
"Expected \(mime.mimeString) to match its signature")
}
// MARK: - Negative Tests
@Test func invalidDataDoesNotMatch() throws {
let badData = Data(repeating: 0x00, count: 16)
for mime in MimeType.allCases where mime != .octetStream {
#expect(!mime.matches(data: badData),
"Unexpectedly matched \(mime.mimeString) with zeroed data")
}
}
// MARK: - Octet-stream (generic binary)
@Test func octetStreamAlwaysMatches() throws {
let randomData = Data([0x00, 0x11, 0x22, 0x33])
#expect(MimeType.octetStream.matches(data: randomData),
"application/octet-stream should always be considered valid")
}
}
+57
View File
@@ -0,0 +1,57 @@
//
// MockBLEBus.swift
// bitchatTests
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import Foundation
@testable import bitchat
final class MockBLEBus {
private var registry: [PeerID: MockBLEService] = [:]
private var adjacency: [PeerID: Set<PeerID>] = [:]
// Enable automatic flooding for public messages in integration tests only
let autoFloodEnabled: Bool
init(autoFloodEnabled: Bool = false) {
self.autoFloodEnabled = autoFloodEnabled
}
func register(_ service: MockBLEService, for peerID: PeerID) {
registry[peerID] = service
if adjacency[peerID] == nil { adjacency[peerID] = [] }
}
func connect(_ a: PeerID, _ b: PeerID) {
var setA = adjacency[a] ?? []
setA.insert(b)
adjacency[a] = setA
var setB = adjacency[b] ?? []
setB.insert(a)
adjacency[b] = setB
}
func disconnect(_ a: PeerID, _ b: PeerID) {
if var setA = adjacency[a] { setA.remove(b); adjacency[a] = setA }
if var setB = adjacency[b] { setB.remove(a); adjacency[b] = setB }
}
func neighbors(of peerID: PeerID) -> [MockBLEService] {
let ids = adjacency[peerID] ?? []
let result = ids.compactMap { registry[$0] }
return result
}
func isDirectNeighbor(_ a: PeerID, _ b: PeerID) -> Bool {
let res = adjacency[a]?.contains(b) ?? false
return res
}
func service(for peerID: PeerID) -> MockBLEService? {
let svc = registry[peerID]
return svc
}
}
+17 -52
View File
@@ -26,13 +26,12 @@ import CoreBluetooth
/// simulate broadcast propagation across the mesh. E2E tests keep it off and perform explicit /// simulate broadcast propagation across the mesh. E2E tests keep it off and perform explicit
/// relays when needed. /// relays when needed.
final class MockBLEService: NSObject { final class MockBLEService: NSObject {
// Enable automatic flooding for public messages in integration tests only private let bus: MockBLEBus
static var autoFloodEnabled: Bool = false
// MARK: - Properties matching BLEService // MARK: - Properties matching BLEService
weak var delegate: BitchatDelegate? weak var delegate: BitchatDelegate?
var myPeerID: PeerID = "MOCK1234" var myPeerID = PeerID(str: "MOCK1234")
var myNickname: String = "MockUser" var myNickname: String = "MockUser"
private let mockKeychain = MockKeychain() private let mockKeychain = MockKeychain()
@@ -60,8 +59,8 @@ final class MockBLEService: NSObject {
// MARK: - Initialization // MARK: - Initialization
override init() { init(bus: MockBLEBus) {
super.init() self.bus = bus
} }
// MARK: - Methods matching BLEService // MARK: - Methods matching BLEService
@@ -71,42 +70,15 @@ final class MockBLEService: NSObject {
} }
// MARK: - In-memory test bus (for E2E/Integration) // MARK: - In-memory test bus (for E2E/Integration)
/// Global per-process bus for deterministic routing in tests.
private static var registry: [PeerID: MockBLEService] = [:]
private static var adjacency: [PeerID: Set<PeerID>] = [:]
/// Clears global bus state. Call from test `setUp()`.
static func resetTestBus() {
registry.removeAll()
adjacency.removeAll()
}
/// Registers this instance on first use. /// Registers this instance on first use.
private func registerIfNeeded() { private func registerIfNeeded() {
MockBLEService.registry[myPeerID] = self bus.register(self, for: myPeerID)
if MockBLEService.adjacency[myPeerID] == nil { MockBLEService.adjacency[myPeerID] = [] }
} }
/// Returns adjacent neighbors based on the current simulated topology. /// Returns adjacent neighbors based on the current simulated topology.
private func neighbors() -> [MockBLEService] { private func neighbors() -> [MockBLEService] {
guard let ids = MockBLEService.adjacency[myPeerID] else { return [] } bus.neighbors(of: myPeerID)
return ids.compactMap { MockBLEService.registry[$0] }
}
/// Adds an undirected edge between two peerIDs.
private static func connectPeers(_ a: PeerID, _ b: PeerID) {
var setA = adjacency[a] ?? []
setA.insert(b)
adjacency[a] = setA
var setB = adjacency[b] ?? []
setB.insert(a)
adjacency[b] = setB
}
/// Removes an undirected edge between two peerIDs.
private static func disconnectPeers(_ a: PeerID, _ b: PeerID) {
if var setA = adjacency[a] { setA.remove(b); adjacency[a] = setA }
if var setB = adjacency[b] { setB.remove(a); adjacency[b] = setB }
} }
func startServices() { func startServices() {
@@ -173,7 +145,7 @@ final class MockBLEService: NSObject {
// Surface raw packet to tests that intercept/relay/encrypt // Surface raw packet to tests that intercept/relay/encrypt
packetDeliveryHandler?(packet) packetDeliveryHandler?(packet)
// Deliver public messages to adjacent peers via test bus // Deliver public messages to adjacent peers via bus
if recipientID == nil { if recipientID == nil {
for neighbor in neighbors() { for neighbor in neighbors() {
neighbor.simulateIncomingPacket(packet) neighbor.simulateIncomingPacket(packet)
@@ -227,20 +199,13 @@ final class MockBLEService: NSObject {
packetDeliveryHandler?(packet) packetDeliveryHandler?(packet)
// If directly connected to recipient, deliver only to them. // If directly connected to recipient, deliver only to them.
if let neighbors = MockBLEService.adjacency[myPeerID], neighbors.contains(recipientPeerID), if bus.isDirectNeighbor(myPeerID, recipientPeerID),
let target = MockBLEService.registry[recipientPeerID] { let target = bus.service(for: recipientPeerID) {
target.simulateIncomingPacket(packet) target.simulateIncomingPacket(packet)
} else { } else {
// Not directly connected: deliver to neighbors for relay; also deliver directly if target is known // Not directly connected: deliver to neighbors for relay
if let target = MockBLEService.registry[recipientPeerID] { for neighbor in neighbors() where neighbor.peerID != recipientPeerID {
target.simulateIncomingPacket(packet) neighbor.simulateIncomingPacket(packet)
}
if let neighbors = MockBLEService.adjacency[myPeerID] {
for peer in neighbors where peer != recipientPeerID {
if let neighbor = MockBLEService.registry[peer] {
neighbor.simulateIncomingPacket(packet)
}
}
} }
} }
} }
@@ -287,14 +252,14 @@ final class MockBLEService: NSObject {
func simulateConnectedPeer(_ peerID: PeerID) { func simulateConnectedPeer(_ peerID: PeerID) {
registerIfNeeded() registerIfNeeded()
MockBLEService.connectPeers(myPeerID, peerID) bus.connect(myPeerID, peerID)
connectedPeers.insert(peerID) connectedPeers.insert(peerID)
delegate?.didConnectToPeer(peerID) delegate?.didConnectToPeer(peerID)
delegate?.didUpdatePeerList(Array(connectedPeers)) delegate?.didUpdatePeerList(Array(connectedPeers))
} }
func simulateDisconnectedPeer(_ peerID: PeerID) { func simulateDisconnectedPeer(_ peerID: PeerID) {
MockBLEService.disconnectPeers(myPeerID, peerID) bus.disconnect(myPeerID, peerID)
connectedPeers.remove(peerID) connectedPeers.remove(peerID)
delegate?.didDisconnectFromPeer(peerID) delegate?.didDisconnectFromPeer(peerID)
delegate?.didUpdatePeerList(Array(connectedPeers)) delegate?.didUpdatePeerList(Array(connectedPeers))
@@ -327,7 +292,7 @@ final class MockBLEService: NSObject {
// When enabled, propagate a public broadcast across the entire connected // When enabled, propagate a public broadcast across the entire connected
// component regardless of the original TTL to better emulate large-network // component regardless of the original TTL to better emulate large-network
// broadcast expectations. De-duplication via seenMessageIDs prevents loops. // broadcast expectations. De-duplication via seenMessageIDs prevents loops.
if MockBLEService.autoFloodEnabled, if bus.autoFloodEnabled,
packet.recipientID == nil, packet.recipientID == nil,
!message.isPrivate { !message.isPrivate {
let nextTTL = packet.ttl > 0 ? packet.ttl - 1 : 0 let nextTTL = packet.ttl > 0 ? packet.ttl - 1 : 0
@@ -361,8 +326,8 @@ typealias MockSimplifiedBluetoothService = MockBLEService
// MARK: - Helpers // MARK: - Helpers
extension MockBLEService { extension MockBLEService {
convenience init(peerID: PeerID, nickname: String) { convenience init(peerID: PeerID, nickname: String, bus: MockBLEBus) {
self.init() self.init(bus: bus)
myPeerID = peerID myPeerID = peerID
mockNickname = nickname mockNickname = nickname
} }
+217 -252
View File
@@ -6,135 +6,123 @@
// For more information, see <https://unlicense.org> // For more information, see <https://unlicense.org>
// //
import XCTest import Testing
import CryptoKit import CryptoKit
import Foundation
@testable import bitchat @testable import bitchat
final class NoiseProtocolTests: XCTestCase { struct NoiseProtocolTests {
var aliceKey: Curve25519.KeyAgreement.PrivateKey! private let aliceKey = Curve25519.KeyAgreement.PrivateKey()
var bobKey: Curve25519.KeyAgreement.PrivateKey! private let bobKey = Curve25519.KeyAgreement.PrivateKey()
var aliceSession: NoiseSession! private let mockKeychain = MockKeychain()
var bobSession: NoiseSession!
private var mockKeychain: MockKeychain!
override func setUp() { private let alicePeerID = PeerID(str: UUID().uuidString)
super.setUp() private let bobPeerID = PeerID(str: UUID().uuidString)
aliceKey = Curve25519.KeyAgreement.PrivateKey()
bobKey = Curve25519.KeyAgreement.PrivateKey()
mockKeychain = MockKeychain()
}
override func tearDown() { private let aliceSession: NoiseSession
aliceSession = nil private let bobSession: NoiseSession
bobSession = nil
mockKeychain = nil
super.tearDown()
}
// MARK: - Basic Handshake Tests init() {
func testXXPatternHandshake() throws {
// Create sessions
aliceSession = NoiseSession( aliceSession = NoiseSession(
peerID: TestConstants.testPeerID2, peerID: alicePeerID,
role: .initiator, role: .initiator,
keychain: mockKeychain, keychain: mockKeychain,
localStaticKey: aliceKey localStaticKey: aliceKey
) )
bobSession = NoiseSession( bobSession = NoiseSession(
peerID: TestConstants.testPeerID1, peerID: bobPeerID,
role: .responder, role: .responder,
keychain: mockKeychain, keychain: mockKeychain,
localStaticKey: bobKey localStaticKey: bobKey
) )
}
// MARK: - Basic Handshake Tests
@Test func xxPatternHandshake() throws {
// Alice starts handshake (message 1) // Alice starts handshake (message 1)
let message1 = try aliceSession.startHandshake() let message1 = try aliceSession.startHandshake()
XCTAssertFalse(message1.isEmpty) #expect(!message1.isEmpty)
XCTAssertEqual(aliceSession.getState(), .handshaking) #expect(aliceSession.getState() == .handshaking)
// Bob processes message 1 and creates message 2 // Bob processes message 1 and creates message 2
let message2 = try bobSession.processHandshakeMessage(message1) let message2 = try bobSession.processHandshakeMessage(message1)
XCTAssertNotNil(message2) #expect(message2 != nil)
XCTAssertFalse(message2!.isEmpty) #expect(!message2!.isEmpty)
XCTAssertEqual(bobSession.getState(), .handshaking) #expect(bobSession.getState() == .handshaking)
// Alice processes message 2 and creates message 3 // Alice processes message 2 and creates message 3
let message3 = try aliceSession.processHandshakeMessage(message2!) let message3 = try aliceSession.processHandshakeMessage(message2!)
XCTAssertNotNil(message3) #expect(message3 != nil)
XCTAssertFalse(message3!.isEmpty) #expect(!message3!.isEmpty)
XCTAssertEqual(aliceSession.getState(), .established) #expect(aliceSession.getState() == .established)
// Bob processes message 3 and completes handshake // Bob processes message 3 and completes handshake
let finalMessage = try bobSession.processHandshakeMessage(message3!) let finalMessage = try bobSession.processHandshakeMessage(message3!)
XCTAssertNil(finalMessage) // No more messages needed #expect(finalMessage == nil) // No more messages needed
XCTAssertEqual(bobSession.getState(), .established) #expect(bobSession.getState() == .established)
// Verify both sessions are established // Verify both sessions are established
XCTAssertTrue(aliceSession.isEstablished()) #expect(aliceSession.isEstablished())
XCTAssertTrue(bobSession.isEstablished()) #expect(bobSession.isEstablished())
// Verify they have each other's static keys // Verify they have each other's static keys
XCTAssertEqual(aliceSession.getRemoteStaticPublicKey()?.rawRepresentation, bobKey.publicKey.rawRepresentation) #expect(aliceSession.getRemoteStaticPublicKey()?.rawRepresentation == bobKey.publicKey.rawRepresentation)
XCTAssertEqual(bobSession.getRemoteStaticPublicKey()?.rawRepresentation, aliceKey.publicKey.rawRepresentation) #expect(bobSession.getRemoteStaticPublicKey()?.rawRepresentation == aliceKey.publicKey.rawRepresentation)
} }
func testHandshakeStateValidation() throws { @Test func handshakeStateValidation() throws {
aliceSession = NoiseSession(
peerID: TestConstants.testPeerID2,
role: .initiator,
keychain: mockKeychain,
localStaticKey: aliceKey
)
// Cannot process message before starting handshake // Cannot process message before starting handshake
XCTAssertThrowsError(try aliceSession.processHandshakeMessage(Data())) #expect(throws: NoiseSessionError.invalidState) {
try aliceSession.processHandshakeMessage(Data())
}
// Start handshake // Start handshake
_ = try aliceSession.startHandshake() _ = try aliceSession.startHandshake()
// Cannot start handshake twice // Cannot start handshake twice
XCTAssertThrowsError(try aliceSession.startHandshake()) #expect(throws: NoiseSessionError.invalidState) {
try aliceSession.startHandshake()
}
} }
// MARK: - Encryption/Decryption Tests // MARK: - Encryption/Decryption Tests
func testBasicEncryptionDecryption() throws { @Test func basicEncryptionDecryption() throws {
// Establish sessions try performHandshake(initiator: aliceSession, responder: bobSession)
try establishSessions()
let plaintext = "Hello, Bob!".data(using: .utf8)! let plaintext = "Hello, Bob!".data(using: .utf8)!
// Alice encrypts // Alice encrypts
let ciphertext = try aliceSession.encrypt(plaintext) let ciphertext = try aliceSession.encrypt(plaintext)
XCTAssertNotEqual(ciphertext, plaintext) #expect(ciphertext != plaintext)
XCTAssertGreaterThan(ciphertext.count, plaintext.count) // Should have overhead #expect(ciphertext.count > plaintext.count) // Should have overhead
// Bob decrypts // Bob decrypts
let decrypted = try bobSession.decrypt(ciphertext) let decrypted = try bobSession.decrypt(ciphertext)
XCTAssertEqual(decrypted, plaintext) #expect(decrypted == plaintext)
} }
func testBidirectionalEncryption() throws { @Test func bidirectionalEncryption() throws {
try establishSessions() try performHandshake(initiator: aliceSession, responder: bobSession)
// Alice -> Bob // Alice -> Bob
let aliceMessage = "Hello from Alice".data(using: .utf8)! let aliceMessage = "Hello from Alice".data(using: .utf8)!
let aliceCiphertext = try aliceSession.encrypt(aliceMessage) let aliceCiphertext = try aliceSession.encrypt(aliceMessage)
let bobReceived = try bobSession.decrypt(aliceCiphertext) let bobReceived = try bobSession.decrypt(aliceCiphertext)
XCTAssertEqual(bobReceived, aliceMessage) #expect(bobReceived == aliceMessage)
// Bob -> Alice // Bob -> Alice
let bobMessage = "Hello from Bob".data(using: .utf8)! let bobMessage = "Hello from Bob".data(using: .utf8)!
let bobCiphertext = try bobSession.encrypt(bobMessage) let bobCiphertext = try bobSession.encrypt(bobMessage)
let aliceReceived = try aliceSession.decrypt(bobCiphertext) let aliceReceived = try aliceSession.decrypt(bobCiphertext)
XCTAssertEqual(aliceReceived, bobMessage) #expect(aliceReceived == bobMessage)
} }
func testLargeMessageEncryption() throws { @Test func largeMessageEncryption() throws {
try establishSessions() try performHandshake(initiator: aliceSession, responder: bobSession)
// Create a large message // Create a large message
let largeMessage = TestHelpers.generateRandomData(length: 100_000) let largeMessage = TestHelpers.generateRandomData(length: 100_000)
@@ -143,81 +131,78 @@ final class NoiseProtocolTests: XCTestCase {
let ciphertext = try aliceSession.encrypt(largeMessage) let ciphertext = try aliceSession.encrypt(largeMessage)
let decrypted = try bobSession.decrypt(ciphertext) let decrypted = try bobSession.decrypt(ciphertext)
XCTAssertEqual(decrypted, largeMessage) #expect(decrypted == largeMessage)
} }
func testEncryptionBeforeHandshake() { @Test func encryptionBeforeHandshake() {
aliceSession = NoiseSession(
peerID: TestConstants.testPeerID2,
role: .initiator,
keychain: mockKeychain,
localStaticKey: aliceKey
)
let plaintext = "test".data(using: .utf8)! let plaintext = "test".data(using: .utf8)!
// Should throw when not established #expect(throws: NoiseSessionError.notEstablished) {
XCTAssertThrowsError(try aliceSession.encrypt(plaintext)) try aliceSession.encrypt(plaintext)
XCTAssertThrowsError(try aliceSession.decrypt(plaintext)) }
#expect(throws: NoiseSessionError.notEstablished) {
try aliceSession.decrypt(plaintext)
}
} }
// MARK: - Session Manager Tests // MARK: - Session Manager Tests
func testSessionManagerBasicOperations() throws { @Test func sessionManagerBasicOperations() throws {
let manager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain) let manager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain)
// Create session #expect(manager.getSession(for: alicePeerID) == nil)
let session = manager.createSession(for: TestConstants.testPeerID2, role: .initiator)
XCTAssertNotNil(session) _ = try manager.initiateHandshake(with: alicePeerID)
#expect(manager.getSession(for: alicePeerID) != nil)
// Get session // Get session
let retrieved = manager.getSession(for: TestConstants.testPeerID2) let retrieved = manager.getSession(for: alicePeerID)
XCTAssertNotNil(retrieved) #expect(retrieved != nil)
XCTAssertTrue(session === retrieved)
// Remove session // Remove session
manager.removeSession(for: TestConstants.testPeerID2) manager.removeSession(for: alicePeerID)
XCTAssertNil(manager.getSession(for: TestConstants.testPeerID2)) #expect(manager.getSession(for: alicePeerID) == nil)
} }
func testSessionManagerHandshakeInitiation() throws { @Test func sessionManagerHandshakeInitiation() throws {
let manager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain) let manager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain)
// Initiate handshake // Initiate handshake
let handshakeData = try manager.initiateHandshake(with: TestConstants.testPeerID2) let handshakeData = try manager.initiateHandshake(with: alicePeerID)
XCTAssertFalse(handshakeData.isEmpty) #expect(!handshakeData.isEmpty)
// Session should exist // Session should exist
let session = manager.getSession(for: TestConstants.testPeerID2) let session = manager.getSession(for: alicePeerID)
XCTAssertNotNil(session) #expect(session != nil)
XCTAssertEqual(session?.getState(), .handshaking) #expect(session?.getState() == .handshaking)
} }
func testSessionManagerIncomingHandshake() throws { @Test func sessionManagerIncomingHandshake() throws {
let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain) let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain)
let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain) let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain)
// Alice initiates // Alice initiates
let message1 = try aliceManager.initiateHandshake(with: TestConstants.testPeerID2) let message1 = try aliceManager.initiateHandshake(with: alicePeerID)
// Bob responds // Bob responds
let message2 = try bobManager.handleIncomingHandshake(from: TestConstants.testPeerID1, message: message1) let message2 = try bobManager.handleIncomingHandshake(from: bobPeerID, message: message1)
XCTAssertNotNil(message2) #expect(message2 != nil)
// Continue handshake // Continue handshake
let message3 = try aliceManager.handleIncomingHandshake(from: TestConstants.testPeerID2, message: message2!) let message3 = try aliceManager.handleIncomingHandshake(from: alicePeerID, message: message2!)
XCTAssertNotNil(message3) #expect(message3 != nil)
// Complete handshake // Complete handshake
let finalMessage = try bobManager.handleIncomingHandshake(from: TestConstants.testPeerID1, message: message3!) let finalMessage = try bobManager.handleIncomingHandshake(from: bobPeerID, message: message3!)
XCTAssertNil(finalMessage) #expect(finalMessage == nil)
// Both should have established sessions // Both should have established sessions
XCTAssertTrue(aliceManager.getSession(for: TestConstants.testPeerID2)?.isEstablished() ?? false) #expect(aliceManager.getSession(for: alicePeerID)?.isEstablished() == true)
XCTAssertTrue(bobManager.getSession(for: TestConstants.testPeerID1)?.isEstablished() ?? false) #expect(bobManager.getSession(for: bobPeerID)?.isEstablished() == true)
} }
func testSessionManagerEncryptionDecryption() throws { @Test func sessionManagerEncryptionDecryption() throws {
let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain) let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain)
let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain) let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain)
@@ -226,17 +211,17 @@ final class NoiseProtocolTests: XCTestCase {
// Encrypt with manager // Encrypt with manager
let plaintext = "Test message".data(using: .utf8)! let plaintext = "Test message".data(using: .utf8)!
let ciphertext = try aliceManager.encrypt(plaintext, for: TestConstants.testPeerID2) let ciphertext = try aliceManager.encrypt(plaintext, for: alicePeerID)
// Decrypt with manager // Decrypt with manager
let decrypted = try bobManager.decrypt(ciphertext, from: TestConstants.testPeerID1) let decrypted = try bobManager.decrypt(ciphertext, from: bobPeerID)
XCTAssertEqual(decrypted, plaintext) #expect(decrypted == plaintext)
} }
// MARK: - Security Tests // MARK: - Security Tests
func testTamperedCiphertextDetection() throws { @Test func tamperedCiphertextDetection() throws {
try establishSessions() try performHandshake(initiator: aliceSession, responder: bobSession)
let plaintext = "Secret message".data(using: .utf8)! let plaintext = "Secret message".data(using: .utf8)!
var ciphertext = try aliceSession.encrypt(plaintext) var ciphertext = try aliceSession.encrypt(plaintext)
@@ -245,11 +230,19 @@ final class NoiseProtocolTests: XCTestCase {
ciphertext[ciphertext.count / 2] ^= 0xFF ciphertext[ciphertext.count / 2] ^= 0xFF
// Decryption should fail // Decryption should fail
XCTAssertThrowsError(try bobSession.decrypt(ciphertext)) if #available(macOS 14.4, iOS 17.4, *) {
#expect(throws: CryptoKitError.authenticationFailure) {
try bobSession.decrypt(ciphertext)
}
} else {
#expect(throws: (any Error).self) {
try bobSession.decrypt(ciphertext)
}
}
} }
func testReplayPrevention() throws { @Test func replayPrevention() throws {
try establishSessions() try performHandshake(initiator: aliceSession, responder: bobSession)
let plaintext = "Test message".data(using: .utf8)! let plaintext = "Test message".data(using: .utf8)!
let ciphertext = try aliceSession.encrypt(plaintext) let ciphertext = try aliceSession.encrypt(plaintext)
@@ -258,16 +251,18 @@ final class NoiseProtocolTests: XCTestCase {
_ = try bobSession.decrypt(ciphertext) _ = try bobSession.decrypt(ciphertext)
// Replaying the same ciphertext should fail // Replaying the same ciphertext should fail
XCTAssertThrowsError(try bobSession.decrypt(ciphertext)) #expect(throws: NoiseError.replayDetected) {
try bobSession.decrypt(ciphertext)
}
} }
func testSessionIsolation() throws { @Test func sessionIsolation() throws {
// Create two separate session pairs // Create two separate session pairs
let aliceSession1 = NoiseSession(peerID: "peer1", role: .initiator, keychain: mockKeychain, localStaticKey: aliceKey) let aliceSession1 = NoiseSession(peerID: PeerID(str: "peer1"), role: .initiator, keychain: mockKeychain, localStaticKey: aliceKey)
let bobSession1 = NoiseSession(peerID: "alice1", role: .responder, keychain: mockKeychain, localStaticKey: bobKey) let bobSession1 = NoiseSession(peerID: PeerID(str: "alice1"), role: .responder, keychain: mockKeychain, localStaticKey: bobKey)
let aliceSession2 = NoiseSession(peerID: "peer2", role: .initiator, keychain: mockKeychain, localStaticKey: aliceKey) let aliceSession2 = NoiseSession(peerID: PeerID(str: "peer2"), role: .initiator, keychain: mockKeychain, localStaticKey: aliceKey)
let bobSession2 = NoiseSession(peerID: "alice2", role: .responder, keychain: mockKeychain, localStaticKey: bobKey) let bobSession2 = NoiseSession(peerID: PeerID(str: "alice2"), role: .responder, keychain: mockKeychain, localStaticKey: bobKey)
// Establish both pairs // Establish both pairs
try performHandshake(initiator: aliceSession1, responder: bobSession1) try performHandshake(initiator: aliceSession1, responder: bobSession1)
@@ -278,16 +273,24 @@ final class NoiseProtocolTests: XCTestCase {
let ciphertext1 = try aliceSession1.encrypt(plaintext) let ciphertext1 = try aliceSession1.encrypt(plaintext)
// Should not be able to decrypt with session 2 // Should not be able to decrypt with session 2
XCTAssertThrowsError(try bobSession2.decrypt(ciphertext1)) if #available(macOS 14.4, iOS 17.4, *) {
#expect(throws: CryptoKitError.authenticationFailure) {
try bobSession2.decrypt(ciphertext1)
}
} else {
#expect(throws: (any Error).self) {
try bobSession2.decrypt(ciphertext1)
}
}
// But should work with correct session // But should work with correct session
let decrypted = try bobSession1.decrypt(ciphertext1) let decrypted = try bobSession1.decrypt(ciphertext1)
XCTAssertEqual(decrypted, plaintext) #expect(decrypted == plaintext)
} }
// MARK: - Session Recovery Tests // MARK: - Session Recovery Tests
func testPeerRestartDetection() throws { @Test func peerRestartDetection() throws {
// Establish initial sessions // Establish initial sessions
let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain) let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain)
let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain) let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain)
@@ -295,38 +298,38 @@ final class NoiseProtocolTests: XCTestCase {
try establishManagerSessions(aliceManager: aliceManager, bobManager: bobManager) try establishManagerSessions(aliceManager: aliceManager, bobManager: bobManager)
// Exchange some messages to establish nonce state // Exchange some messages to establish nonce state
let message1 = try aliceManager.encrypt("Hello".data(using: .utf8)!, for: TestConstants.testPeerID2) let message1 = try aliceManager.encrypt("Hello".data(using: .utf8)!, for: alicePeerID)
_ = try bobManager.decrypt(message1, from: TestConstants.testPeerID1) _ = try bobManager.decrypt(message1, from: bobPeerID)
let message2 = try bobManager.encrypt("World".data(using: .utf8)!, for: TestConstants.testPeerID1) let message2 = try bobManager.encrypt("World".data(using: .utf8)!, for: bobPeerID)
_ = try aliceManager.decrypt(message2, from: TestConstants.testPeerID2) _ = try aliceManager.decrypt(message2, from: alicePeerID)
// Simulate Bob restart by creating new manager with same key // Simulate Bob restart by creating new manager with same key
let bobManagerRestarted = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain) let bobManagerRestarted = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain)
// Bob initiates new handshake after restart // Bob initiates new handshake after restart
let newHandshake1 = try bobManagerRestarted.initiateHandshake(with: TestConstants.testPeerID1) let newHandshake1 = try bobManagerRestarted.initiateHandshake(with: bobPeerID)
// Alice should accept the new handshake (clearing old session) // Alice should accept the new handshake (clearing old session)
let newHandshake2 = try aliceManager.handleIncomingHandshake(from: TestConstants.testPeerID2, message: newHandshake1) let newHandshake2 = try aliceManager.handleIncomingHandshake(from: alicePeerID, message: newHandshake1)
XCTAssertNotNil(newHandshake2) #expect(newHandshake2 != nil)
// Complete the new handshake // Complete the new handshake
let newHandshake3 = try bobManagerRestarted.handleIncomingHandshake(from: TestConstants.testPeerID1, message: newHandshake2!) let newHandshake3 = try bobManagerRestarted.handleIncomingHandshake(from: bobPeerID, message: newHandshake2!)
XCTAssertNotNil(newHandshake3) #expect(newHandshake3 != nil)
_ = try aliceManager.handleIncomingHandshake(from: TestConstants.testPeerID2, message: newHandshake3!) _ = try aliceManager.handleIncomingHandshake(from: alicePeerID, message: newHandshake3!)
// Should be able to exchange messages with new sessions // Should be able to exchange messages with new sessions
let testMessage = "After restart".data(using: .utf8)! let testMessage = "After restart".data(using: .utf8)!
let encrypted = try bobManagerRestarted.encrypt(testMessage, for: TestConstants.testPeerID1) let encrypted = try bobManagerRestarted.encrypt(testMessage, for: bobPeerID)
let decrypted = try aliceManager.decrypt(encrypted, from: TestConstants.testPeerID2) let decrypted = try aliceManager.decrypt(encrypted, from: alicePeerID)
XCTAssertEqual(decrypted, testMessage) #expect(decrypted == testMessage)
} }
func testNonceDesynchronizationRecovery() throws { @Test func nonceDesynchronizationRecovery() throws {
// Create two sessions // Create two sessions
aliceSession = NoiseSession(peerID: TestConstants.testPeerID2, role: .initiator, keychain: mockKeychain, localStaticKey: aliceKey) let aliceSession = NoiseSession(peerID: alicePeerID, role: .initiator, keychain: mockKeychain, localStaticKey: aliceKey)
bobSession = NoiseSession(peerID: TestConstants.testPeerID1, role: .responder, keychain: mockKeychain, localStaticKey: bobKey) let bobSession = NoiseSession(peerID: bobPeerID, role: .responder, keychain: mockKeychain, localStaticKey: bobKey)
// Establish sessions // Establish sessions
try performHandshake(initiator: aliceSession, responder: bobSession) try performHandshake(initiator: aliceSession, responder: bobSession)
@@ -344,10 +347,12 @@ final class NoiseProtocolTests: XCTestCase {
// With per-packet nonce carried, decryption should not throw here // With per-packet nonce carried, decryption should not throw here
let desyncMessage = try aliceSession.encrypt("This now succeeds".data(using: .utf8)!) let desyncMessage = try aliceSession.encrypt("This now succeeds".data(using: .utf8)!)
XCTAssertNoThrow(try bobSession.decrypt(desyncMessage)) #expect(throws: Never.self) {
try bobSession.decrypt(desyncMessage)
}
} }
func testConcurrentEncryption() throws { @Test func concurrentEncryption() async throws {
// Test thread safety of encryption operations // Test thread safety of encryption operations
let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain) let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain)
let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain) let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain)
@@ -355,37 +360,35 @@ final class NoiseProtocolTests: XCTestCase {
try establishManagerSessions(aliceManager: aliceManager, bobManager: bobManager) try establishManagerSessions(aliceManager: aliceManager, bobManager: bobManager)
let messageCount = 100 let messageCount = 100
let expectation = XCTestExpectation(description: "All messages encrypted and decrypted")
expectation.expectedFulfillmentCount = messageCount
var encryptedMessages: [Int: Data] = [:]
// Encrypt messages sequentially to avoid nonce races in manager
for i in 0..<messageCount {
let plaintext = "Concurrent message \(i)".data(using: .utf8)!
let encrypted = try aliceManager.encrypt(plaintext, for: TestConstants.testPeerID2)
encryptedMessages[i] = encrypted
}
// Decrypt messages sequentially to avoid triggering anti-replay with reordering try await confirmation("All messages encrypted and decrypted", expectedCount: messageCount) { completion in
for i in 0..<messageCount { var encryptedMessages: [Int: Data] = [:]
do { // Encrypt messages sequentially to avoid nonce races in manager
guard let encrypted = encryptedMessages[i] else { for i in 0..<messageCount {
XCTFail("Missing encrypted message \(i)") let plaintext = "Concurrent message \(i)".data(using: .utf8)!
return let encrypted = try aliceManager.encrypt(plaintext, for: alicePeerID)
encryptedMessages[i] = encrypted
}
// Decrypt messages sequentially to avoid triggering anti-replay with reordering
for i in 0..<messageCount {
do {
guard let encrypted = encryptedMessages[i] else {
Issue.record("Missing encrypted message \(i)")
return
}
let decrypted = try bobManager.decrypt(encrypted, from: bobPeerID)
let expected = "Concurrent message \(i)".data(using: .utf8)!
#expect(decrypted == expected)
completion()
} catch {
Issue.record("Decryption failed for message \(i): \(error)")
} }
let decrypted = try bobManager.decrypt(encrypted, from: TestConstants.testPeerID1)
let expected = "Concurrent message \(i)".data(using: .utf8)!
XCTAssertEqual(decrypted, expected)
expectation.fulfill()
} catch {
XCTFail("Decryption failed for message \(i): \(error)")
} }
} }
wait(for: [expectation], timeout: 10.0)
} }
func testSessionStaleDetection() throws { @Test func sessionStaleDetection() throws {
// Test that sessions are properly marked as stale // Test that sessions are properly marked as stale
let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain) let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain)
let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain) let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain)
@@ -396,10 +399,10 @@ final class NoiseProtocolTests: XCTestCase {
let sessions = aliceManager.getSessionsNeedingRekey() let sessions = aliceManager.getSessionsNeedingRekey()
// New session should not need rekey // New session should not need rekey
XCTAssertTrue(sessions.isEmpty || sessions.allSatisfy { !$0.needsRekey }) #expect(sessions.isEmpty || sessions.allSatisfy { !$0.needsRekey })
} }
func testHandshakeAfterDecryptionFailure() throws { @Test func handshakeAfterDecryptionFailure() throws {
// Test that handshake is properly initiated after decryption failure // Test that handshake is properly initiated after decryption failure
let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain) let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain)
let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain) let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain)
@@ -408,17 +411,25 @@ final class NoiseProtocolTests: XCTestCase {
try establishManagerSessions(aliceManager: aliceManager, bobManager: bobManager) try establishManagerSessions(aliceManager: aliceManager, bobManager: bobManager)
// Create a corrupted message // Create a corrupted message
var encrypted = try aliceManager.encrypt("Test".data(using: .utf8)!, for: TestConstants.testPeerID2) var encrypted = try aliceManager.encrypt("Test".data(using: .utf8)!, for: alicePeerID)
encrypted[10] ^= 0xFF // Corrupt the data encrypted[10] ^= 0xFF // Corrupt the data
// Decryption should fail // Decryption should fail
XCTAssertThrowsError(try bobManager.decrypt(encrypted, from: TestConstants.testPeerID1)) if #available(macOS 14.4, iOS 17.4, *) {
#expect(throws: CryptoKitError.authenticationFailure) {
try bobManager.decrypt(encrypted, from: bobPeerID)
}
} else {
#expect(throws: (any Error).self) {
try bobManager.decrypt(encrypted, from: bobPeerID)
}
}
// Bob should still have the session (it's not removed on single failure) // Bob should still have the session (it's not removed on single failure)
XCTAssertNotNil(bobManager.getSession(for: TestConstants.testPeerID1)) #expect(bobManager.getSession(for: bobPeerID) != nil)
} }
func testHandshakeAlwaysAcceptedWithExistingSession() throws { @Test func handshakeAlwaysAcceptedWithExistingSession() throws {
// Test that handshake is always accepted even with existing valid session // Test that handshake is always accepted even with existing valid session
let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain) let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain)
let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain) let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain)
@@ -427,38 +438,38 @@ final class NoiseProtocolTests: XCTestCase {
try establishManagerSessions(aliceManager: aliceManager, bobManager: bobManager) try establishManagerSessions(aliceManager: aliceManager, bobManager: bobManager)
// Verify sessions are established // Verify sessions are established
XCTAssertTrue(aliceManager.getSession(for: TestConstants.testPeerID2)?.isEstablished() ?? false) #expect(aliceManager.getSession(for: alicePeerID)?.isEstablished() == true)
XCTAssertTrue(bobManager.getSession(for: TestConstants.testPeerID1)?.isEstablished() ?? false) #expect(bobManager.getSession(for: bobPeerID)?.isEstablished() == true)
// Exchange messages to verify sessions work // Exchange messages to verify sessions work
let testMessage = "Session works".data(using: .utf8)! let testMessage = "Session works".data(using: .utf8)!
let encrypted = try aliceManager.encrypt(testMessage, for: TestConstants.testPeerID2) let encrypted = try aliceManager.encrypt(testMessage, for: alicePeerID)
let decrypted = try bobManager.decrypt(encrypted, from: TestConstants.testPeerID1) let decrypted = try bobManager.decrypt(encrypted, from: bobPeerID)
XCTAssertEqual(decrypted, testMessage) #expect(decrypted == testMessage)
// Alice clears her session (simulating decryption failure) // Alice clears her session (simulating decryption failure)
aliceManager.removeSession(for: TestConstants.testPeerID2) aliceManager.removeSession(for: alicePeerID)
// Alice initiates new handshake despite Bob having valid session // Alice initiates new handshake despite Bob having valid session
let newHandshake1 = try aliceManager.initiateHandshake(with: TestConstants.testPeerID2) let newHandshake1 = try aliceManager.initiateHandshake(with: alicePeerID)
// Bob should accept the new handshake even though he has a valid session // Bob should accept the new handshake even though he has a valid session
let newHandshake2 = try bobManager.handleIncomingHandshake(from: TestConstants.testPeerID1, message: newHandshake1) let newHandshake2 = try bobManager.handleIncomingHandshake(from: bobPeerID, message: newHandshake1)
XCTAssertNotNil(newHandshake2, "Bob should accept handshake despite having valid session") #expect(newHandshake2 != nil, "Bob should accept handshake despite having valid session")
// Complete the handshake // Complete the handshake
let newHandshake3 = try aliceManager.handleIncomingHandshake(from: TestConstants.testPeerID2, message: newHandshake2!) let newHandshake3 = try aliceManager.handleIncomingHandshake(from: alicePeerID, message: newHandshake2!)
XCTAssertNotNil(newHandshake3) #expect(newHandshake3 != nil)
_ = try bobManager.handleIncomingHandshake(from: TestConstants.testPeerID1, message: newHandshake3!) _ = try bobManager.handleIncomingHandshake(from: bobPeerID, message: newHandshake3!)
// Verify new sessions work // Verify new sessions work
let testMessage2 = "New session works".data(using: .utf8)! let testMessage2 = "New session works".data(using: .utf8)!
let encrypted2 = try aliceManager.encrypt(testMessage2, for: TestConstants.testPeerID2) let encrypted2 = try aliceManager.encrypt(testMessage2, for: alicePeerID)
let decrypted2 = try bobManager.decrypt(encrypted2, from: TestConstants.testPeerID1) let decrypted2 = try bobManager.decrypt(encrypted2, from: bobPeerID)
XCTAssertEqual(decrypted2, testMessage2) #expect(decrypted2 == testMessage2)
} }
func testNonceDesynchronizationCausesRehandshake() throws { @Test func nonceDesynchronizationCausesRehandshake() throws {
// Test that nonce desynchronization leads to proper re-handshake // Test that nonce desynchronization leads to proper re-handshake
let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain) let aliceManager = NoiseSessionManager(localStaticKey: aliceKey, keychain: mockKeychain)
let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain) let bobManager = NoiseSessionManager(localStaticKey: bobKey, keychain: mockKeychain)
@@ -468,89 +479,43 @@ final class NoiseProtocolTests: XCTestCase {
// Exchange messages normally // Exchange messages normally
for i in 0..<5 { for i in 0..<5 {
let msg = try aliceManager.encrypt("Message \(i)".data(using: .utf8)!, for: TestConstants.testPeerID2) let msg = try aliceManager.encrypt("Message \(i)".data(using: .utf8)!, for: alicePeerID)
_ = try bobManager.decrypt(msg, from: TestConstants.testPeerID1) _ = try bobManager.decrypt(msg, from: bobPeerID)
} }
// Simulate desynchronization - Alice sends messages that Bob doesn't receive // Simulate desynchronization - Alice sends messages that Bob doesn't receive
for i in 0..<3 { for i in 0..<3 {
_ = try aliceManager.encrypt("Lost message \(i)".data(using: .utf8)!, for: TestConstants.testPeerID2) _ = try aliceManager.encrypt("Lost message \(i)".data(using: .utf8)!, for: alicePeerID)
} }
// With nonce carried in packet, decryption should not throw here // With nonce carried in packet, decryption should not throw here
let desyncMessage = try aliceManager.encrypt("This now succeeds".data(using: .utf8)!, for: TestConstants.testPeerID2) let desyncMessage = try aliceManager.encrypt("This now succeeds".data(using: .utf8)!, for: alicePeerID)
XCTAssertNoThrow(try bobManager.decrypt(desyncMessage, from: TestConstants.testPeerID1)) #expect(throws: Never.self) {
try bobManager.decrypt(desyncMessage, from: bobPeerID)
}
// Bob clears session and initiates new handshake // Bob clears session and initiates new handshake
bobManager.removeSession(for: TestConstants.testPeerID1) bobManager.removeSession(for: bobPeerID)
let rehandshake1 = try bobManager.initiateHandshake(with: TestConstants.testPeerID1) let rehandshake1 = try bobManager.initiateHandshake(with: bobPeerID)
// Alice should accept despite having a "valid" (but desynced) session // Alice should accept despite having a "valid" (but desynced) session
let rehandshake2 = try aliceManager.handleIncomingHandshake(from: TestConstants.testPeerID2, message: rehandshake1) let rehandshake2 = try aliceManager.handleIncomingHandshake(from: alicePeerID, message: rehandshake1)
XCTAssertNotNil(rehandshake2, "Alice should accept handshake to fix desync") #expect(rehandshake2 != nil, "Alice should accept handshake to fix desync")
// Complete handshake // Complete handshake
let rehandshake3 = try bobManager.handleIncomingHandshake(from: TestConstants.testPeerID1, message: rehandshake2!) let rehandshake3 = try bobManager.handleIncomingHandshake(from: bobPeerID, message: rehandshake2!)
XCTAssertNotNil(rehandshake3) #expect(rehandshake3 != nil)
_ = try aliceManager.handleIncomingHandshake(from: TestConstants.testPeerID2, message: rehandshake3!) _ = try aliceManager.handleIncomingHandshake(from: alicePeerID, message: rehandshake3!)
// Verify communication works again // Verify communication works again
let testResynced = "Resynced".data(using: .utf8)! let testResynced = "Resynced".data(using: .utf8)!
let encryptedResync = try aliceManager.encrypt(testResynced, for: TestConstants.testPeerID2) let encryptedResync = try aliceManager.encrypt(testResynced, for: alicePeerID)
let decryptedResync = try bobManager.decrypt(encryptedResync, from: TestConstants.testPeerID1) let decryptedResync = try bobManager.decrypt(encryptedResync, from: bobPeerID)
XCTAssertEqual(decryptedResync, testResynced) #expect(decryptedResync == testResynced)
}
// MARK: - Performance Tests
func testHandshakePerformance() throws {
measure {
do {
let alice = NoiseSession(peerID: "bob", role: .initiator, keychain: mockKeychain, localStaticKey: aliceKey)
let bob = NoiseSession(peerID: "alice", role: .responder, keychain: mockKeychain, localStaticKey: bobKey)
try performHandshake(initiator: alice, responder: bob)
} catch {
XCTFail("Handshake failed: \(error)")
}
}
}
func testEncryptionPerformance() throws {
try establishSessions()
let message = TestHelpers.generateRandomData(length: 1024)
measure {
do {
for _ in 0..<100 {
let ciphertext = try aliceSession.encrypt(message)
_ = try bobSession.decrypt(ciphertext)
}
} catch {
XCTFail("Encryption/decryption failed: \(error)")
}
}
} }
// MARK: - Helper Methods // MARK: - Helper Methods
private func establishSessions() throws {
aliceSession = NoiseSession(
peerID: TestConstants.testPeerID2,
role: .initiator,
keychain: mockKeychain,
localStaticKey: aliceKey
)
bobSession = NoiseSession(
peerID: TestConstants.testPeerID1,
role: .responder,
keychain: mockKeychain,
localStaticKey: bobKey
)
try performHandshake(initiator: aliceSession, responder: bobSession)
}
private func performHandshake(initiator: NoiseSession, responder: NoiseSession) throws { private func performHandshake(initiator: NoiseSession, responder: NoiseSession) throws {
let msg1 = try initiator.startHandshake() let msg1 = try initiator.startHandshake()
let msg2 = try responder.processHandshakeMessage(msg1)! let msg2 = try responder.processHandshakeMessage(msg1)!
@@ -559,9 +524,9 @@ final class NoiseProtocolTests: XCTestCase {
} }
private func establishManagerSessions(aliceManager: NoiseSessionManager, bobManager: NoiseSessionManager) throws { private func establishManagerSessions(aliceManager: NoiseSessionManager, bobManager: NoiseSessionManager) throws {
let msg1 = try aliceManager.initiateHandshake(with: TestConstants.testPeerID2) let msg1 = try aliceManager.initiateHandshake(with: alicePeerID)
let msg2 = try bobManager.handleIncomingHandshake(from: TestConstants.testPeerID1, message: msg1)! let msg2 = try bobManager.handleIncomingHandshake(from: bobPeerID, message: msg1)!
let msg3 = try aliceManager.handleIncomingHandshake(from: TestConstants.testPeerID2, message: msg2)! let msg3 = try aliceManager.handleIncomingHandshake(from: alicePeerID, message: msg2)!
_ = try bobManager.handleIncomingHandshake(from: TestConstants.testPeerID1, message: msg3) _ = try bobManager.handleIncomingHandshake(from: bobPeerID, message: msg3)
} }
} }
+63 -64
View File
@@ -5,20 +5,20 @@
// Tests for NIP-17 gift-wrapped private messages // Tests for NIP-17 gift-wrapped private messages
// //
import XCTest import Testing
import CryptoKit
import Foundation
@testable import bitchat @testable import bitchat
final class NostrProtocolTests: XCTestCase { struct NostrProtocolTests {
func testNIP17MessageRoundTrip() throws { @Test func nip17MessageRoundTrip() throws {
// Create sender and recipient identities // Create sender and recipient identities
let sender = try NostrIdentity.generate() let sender = try NostrIdentity.generate()
let recipient = try NostrIdentity.generate() let recipient = try NostrIdentity.generate()
#if DEBUG
print("Sender pubkey: \(sender.publicKeyHex)") print("Sender pubkey: \(sender.publicKeyHex)")
print("Recipient pubkey: \(recipient.publicKeyHex)") print("Recipient pubkey: \(recipient.publicKeyHex)")
#endif
// Create a test message // Create a test message
let originalContent = "Hello from NIP-17 test!" let originalContent = "Hello from NIP-17 test!"
@@ -30,10 +30,8 @@ final class NostrProtocolTests: XCTestCase {
senderIdentity: sender senderIdentity: sender
) )
#if DEBUG
print("Gift wrap created with ID: \(giftWrap.id)") print("Gift wrap created with ID: \(giftWrap.id)")
print("Gift wrap pubkey: \(giftWrap.pubkey)") print("Gift wrap pubkey: \(giftWrap.pubkey)")
#endif
// Decrypt the gift wrap // Decrypt the gift wrap
let (decryptedContent, senderPubkey, timestamp) = try NostrProtocol.decryptPrivateMessage( let (decryptedContent, senderPubkey, timestamp) = try NostrProtocol.decryptPrivateMessage(
@@ -42,20 +40,18 @@ final class NostrProtocolTests: XCTestCase {
) )
// Verify // Verify
XCTAssertEqual(decryptedContent, originalContent) #expect(decryptedContent == originalContent)
XCTAssertEqual(senderPubkey, sender.publicKeyHex) #expect(senderPubkey == sender.publicKeyHex)
// Verify timestamp is reasonable (within last minute) // Verify timestamp is reasonable (within last minute)
let messageDate = Date(timeIntervalSince1970: TimeInterval(timestamp)) let messageDate = Date(timeIntervalSince1970: TimeInterval(timestamp))
let timeDiff = abs(messageDate.timeIntervalSinceNow) let timeDiff = abs(messageDate.timeIntervalSinceNow)
XCTAssertLessThan(timeDiff, 60, "Message timestamp should be recent") #expect(timeDiff < 60, "Message timestamp should be recent")
#if DEBUG
print("✅ Successfully decrypted message: '\(decryptedContent)' from \(senderPubkey) at \(messageDate)") print("✅ Successfully decrypted message: '\(decryptedContent)' from \(senderPubkey) at \(messageDate)")
#endif
} }
func testGiftWrapUsesUniqueEphemeralKeys() throws { @Test func giftWrapUsesUniqueEphemeralKeys() throws {
// Create identities // Create identities
let sender = try NostrIdentity.generate() let sender = try NostrIdentity.generate()
let recipient = try NostrIdentity.generate() let recipient = try NostrIdentity.generate()
@@ -74,11 +70,10 @@ final class NostrProtocolTests: XCTestCase {
) )
// Gift wrap pubkeys should be different (unique ephemeral keys) // Gift wrap pubkeys should be different (unique ephemeral keys)
XCTAssertNotEqual(message1.pubkey, message2.pubkey) #expect(message1.pubkey != message2.pubkey)
#if DEBUG
print("Message 1 gift wrap pubkey: \(message1.pubkey)") print("Message 1 gift wrap pubkey: \(message1.pubkey)")
print("Message 2 gift wrap pubkey: \(message2.pubkey)") print("Message 2 gift wrap pubkey: \(message2.pubkey)")
#endif
// Both should decrypt successfully // Both should decrypt successfully
let (content1, _, _) = try NostrProtocol.decryptPrivateMessage( let (content1, _, _) = try NostrProtocol.decryptPrivateMessage(
@@ -90,11 +85,11 @@ final class NostrProtocolTests: XCTestCase {
recipientIdentity: recipient recipientIdentity: recipient
) )
XCTAssertEqual(content1, "Message 1") #expect(content1 == "Message 1")
XCTAssertEqual(content2, "Message 2") #expect(content2 == "Message 2")
} }
func testDecryptionFailsWithWrongRecipient() throws { @Test func decryptionFailsWithWrongRecipient() throws {
let sender = try NostrIdentity.generate() let sender = try NostrIdentity.generate()
let recipient = try NostrIdentity.generate() let recipient = try NostrIdentity.generate()
let wrongRecipient = try NostrIdentity.generate() let wrongRecipient = try NostrIdentity.generate()
@@ -107,13 +102,20 @@ final class NostrProtocolTests: XCTestCase {
) )
// Try to decrypt with wrong recipient // Try to decrypt with wrong recipient
XCTAssertThrowsError(try NostrProtocol.decryptPrivateMessage( if #available(macOS 14.4, iOS 17.4, *) {
giftWrap: giftWrap, #expect(throws: CryptoKitError.authenticationFailure) {
recipientIdentity: wrongRecipient try NostrProtocol.decryptPrivateMessage(
)) { error in giftWrap: giftWrap,
#if DEBUG recipientIdentity: wrongRecipient
print("Expected error when decrypting with wrong key: \(error)") )
#endif }
} else {
#expect(throws: (any Error).self) {
try NostrProtocol.decryptPrivateMessage(
giftWrap: giftWrap,
recipientIdentity: wrongRecipient
)
}
} }
} }
@@ -124,11 +126,12 @@ final class NostrProtocolTests: XCTestCase {
// Build a DELIVERED ack embedded payload (geohash-style, no recipient peer ID) // Build a DELIVERED ack embedded payload (geohash-style, no recipient peer ID)
let messageID = "TEST-MSG-DELIVERED-1" let messageID = "TEST-MSG-DELIVERED-1"
let senderPeerID = "0123456789abcdef" // 8-byte hex peer ID let senderPeerID = PeerID(str: "0123456789abcdef") // 8-byte hex peer ID
guard let embedded = NostrEmbeddedBitChat.encodeAckForNostrNoRecipient(type: .delivered, messageID: messageID, senderPeerID: senderPeerID) else {
XCTFail("Failed to embed delivered ack") let embedded = try #require(
return NostrEmbeddedBitChat.encodeAckForNostrNoRecipient(type: .delivered, messageID: messageID, senderPeerID: senderPeerID),
} "Failed to embed delivered ack"
)
// Create NIP-17 gift wrap to recipient (uses NIP-44 v2 internally) // Create NIP-17 gift wrap to recipient (uses NIP-44 v2 internally)
let giftWrap = try NostrProtocol.createPrivateMessage( let giftWrap = try NostrProtocol.createPrivateMessage(
@@ -138,7 +141,7 @@ final class NostrProtocolTests: XCTestCase {
) )
// Ensure v2 format was used for ciphertext // Ensure v2 format was used for ciphertext
XCTAssertTrue(giftWrap.content.hasPrefix("v2:")) #expect(giftWrap.content.hasPrefix("v2:"))
// Decrypt as recipient // Decrypt as recipient
let (content, senderPubkey, _) = try NostrProtocol.decryptPrivateMessage( let (content, senderPubkey, _) = try NostrProtocol.decryptPrivateMessage(
@@ -147,39 +150,37 @@ final class NostrProtocolTests: XCTestCase {
) )
// Verify sender is correct // Verify sender is correct
XCTAssertEqual(senderPubkey, sender.publicKeyHex) #expect(senderPubkey == sender.publicKeyHex)
// Parse BitChat payload // Parse BitChat payload
XCTAssertTrue(content.hasPrefix("bitchat1:")) #expect(content.hasPrefix("bitchat1:"))
let base64url = String(content.dropFirst("bitchat1:".count)) let base64url = String(content.dropFirst("bitchat1:".count))
guard let packetData = Self.base64URLDecode(base64url), let packetData = try #require(Self.base64URLDecode(base64url))
let packet = BitchatPacket.from(packetData) else { let packet = try #require(BitchatPacket.from(packetData), "Failed to decode bitchat packet")
return XCTFail("Failed to decode bitchat packet")
} #expect(packet.type == MessageType.noiseEncrypted.rawValue)
XCTAssertEqual(packet.type, MessageType.noiseEncrypted.rawValue) let payload = try #require(NoisePayload.decode(packet.payload), "Failed to decode NoisePayload")
guard let payload = NoisePayload.decode(packet.payload) else {
return XCTFail("Failed to decode NoisePayload")
}
switch payload.type { switch payload.type {
case .delivered: case .delivered:
let mid = String(data: payload.data, encoding: .utf8) let mid = String(data: payload.data, encoding: .utf8)
XCTAssertEqual(mid, messageID) #expect(mid == messageID)
default: default:
XCTFail("Unexpected payload type: \(payload.type)") Issue.record("Unexpected payload type: \(payload.type)")
} }
} }
func testAckRoundTripNIP44V2_ReadReceipt() throws { @Test func ackRoundTripNIP44V2_ReadReceipt() throws {
// Identities // Identities
let sender = try NostrIdentity.generate() let sender = try NostrIdentity.generate()
let recipient = try NostrIdentity.generate() let recipient = try NostrIdentity.generate()
let messageID = "TEST-MSG-READ-1" let messageID = "TEST-MSG-READ-1"
let senderPeerID = "fedcba9876543210" // 8-byte hex peer ID let senderPeerID = PeerID(str: "fedcba9876543210") // 8-byte hex peer ID
guard let embedded = NostrEmbeddedBitChat.encodeAckForNostrNoRecipient(type: .readReceipt, messageID: messageID, senderPeerID: senderPeerID) else { let embedded = try #require(
XCTFail("Failed to embed read ack") NostrEmbeddedBitChat.encodeAckForNostrNoRecipient(type: .readReceipt, messageID: messageID, senderPeerID: senderPeerID),
return "Failed to embed read ack"
} )
let giftWrap = try NostrProtocol.createPrivateMessage( let giftWrap = try NostrProtocol.createPrivateMessage(
content: embedded, content: embedded,
@@ -187,30 +188,28 @@ final class NostrProtocolTests: XCTestCase {
senderIdentity: sender senderIdentity: sender
) )
XCTAssertTrue(giftWrap.content.hasPrefix("v2:")) #expect(giftWrap.content.hasPrefix("v2:"))
let (content, senderPubkey, _) = try NostrProtocol.decryptPrivateMessage( let (content, senderPubkey, _) = try NostrProtocol.decryptPrivateMessage(
giftWrap: giftWrap, giftWrap: giftWrap,
recipientIdentity: recipient recipientIdentity: recipient
) )
XCTAssertEqual(senderPubkey, sender.publicKeyHex) #expect(senderPubkey == sender.publicKeyHex)
XCTAssertTrue(content.hasPrefix("bitchat1:")) #expect(content.hasPrefix("bitchat1:"))
let base64url = String(content.dropFirst("bitchat1:".count)) let base64url = String(content.dropFirst("bitchat1:".count))
guard let packetData = Self.base64URLDecode(base64url), let packetData = try #require(Self.base64URLDecode(base64url))
let packet = BitchatPacket.from(packetData) else { let packet = try #require(BitchatPacket.from(packetData), "Failed to decode bitchat packet")
return XCTFail("Failed to decode bitchat packet")
} #expect(packet.type == MessageType.noiseEncrypted.rawValue)
XCTAssertEqual(packet.type, MessageType.noiseEncrypted.rawValue) let payload = try #require(NoisePayload.decode(packet.payload), "Failed to decode NoisePayload")
guard let payload = NoisePayload.decode(packet.payload) else {
return XCTFail("Failed to decode NoisePayload")
}
switch payload.type { switch payload.type {
case .readReceipt: case .readReceipt:
let mid = String(data: payload.data, encoding: .utf8) let mid = String(data: payload.data, encoding: .utf8)
XCTAssertEqual(mid, messageID) #expect(mid == messageID)
default: default:
XCTFail("Unexpected payload type: \(payload.type)") Issue.record("Unexpected payload type: \(payload.type)")
} }
} }
@@ -1,7 +1,8 @@
import XCTest import Testing
import Foundation
@testable import bitchat @testable import bitchat
final class NotificationStreamAssemblerTests: XCTestCase { struct NotificationStreamAssemblerTests {
private func makePacket(timestamp: UInt64 = 0x0102030405) -> BitchatPacket { private func makePacket(timestamp: UInt64 = 0x0102030405) -> BitchatPacket {
let sender = Data([0x00, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77]) let sender = Data([0x00, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77])
return BitchatPacket( return BitchatPacket(
@@ -15,60 +16,51 @@ final class NotificationStreamAssemblerTests: XCTestCase {
) )
} }
func testAssemblesSingleFrameAcrossChunks() { @Test func assemblesSingleFrameAcrossChunks() throws {
var assembler = NotificationStreamAssembler() var assembler = NotificationStreamAssembler()
let packet = makePacket() let packet = makePacket()
guard let frame = packet.toBinaryData(padding: false) else { let frame = try #require(packet.toBinaryData(padding: false), "Failed to encode packet")
return XCTFail("Failed to encode packet")
} #expect(BinaryProtocol.decode(frame) != nil)
XCTAssertNotNil(BinaryProtocol.decode(frame))
let payloadLen = (Int(frame[12]) << 8) | Int(frame[13]) let payloadLen = (Int(frame[12]) << 8) | Int(frame[13])
XCTAssertEqual(payloadLen, packet.payload.count) #expect(payloadLen == packet.payload.count)
let splitIndex = min(20, max(1, frame.count / 2)) let splitIndex = min(20, max(1, frame.count / 2))
let first = frame.prefix(splitIndex) let first = frame.prefix(splitIndex)
let second = frame.suffix(from: splitIndex) let second = frame.suffix(from: splitIndex)
XCTAssertEqual(first.count + second.count, frame.count) #expect(first.count + second.count == frame.count)
var result = assembler.append(first) var result = assembler.append(first)
XCTAssertTrue(result.frames.isEmpty) #expect(result.frames.isEmpty)
XCTAssertTrue(result.droppedPrefixes.isEmpty) #expect(result.droppedPrefixes.isEmpty)
XCTAssertFalse(result.reset) #expect(!result.reset)
result = assembler.append(second) result = assembler.append(second)
XCTAssertEqual(result.frames.count, 1) #expect(result.frames.count == 1)
XCTAssertTrue(result.droppedPrefixes.isEmpty) #expect(result.droppedPrefixes.isEmpty)
XCTAssertFalse(result.reset) #expect(!result.reset)
guard let frameData = result.frames.first else { let frameData = try #require(result.frames.first, "Missing frame data")
return XCTFail("Missing frame data") #expect(frameData.count == frame.count)
}
if frameData.count != frame.count { let decoded = try #require(BinaryProtocol.decode(frameData), "Failed to decode frame")
XCTFail("Frame size mismatch: expected \(frame.count) got \(frameData.count)\nframe=\(Array(frame))\nassembled=\(Array(frameData))") #expect(decoded.type == packet.type)
return #expect(decoded.payload == packet.payload)
} #expect(decoded.senderID == packet.senderID)
guard let decoded = BinaryProtocol.decode(frameData) else { #expect(decoded.timestamp == packet.timestamp)
return XCTFail("Failed to decode frame")
}
XCTAssertEqual(decoded.type, packet.type)
XCTAssertEqual(decoded.payload, packet.payload)
XCTAssertEqual(decoded.senderID, packet.senderID)
XCTAssertEqual(decoded.timestamp, packet.timestamp)
var directAssembler = NotificationStreamAssembler() var directAssembler = NotificationStreamAssembler()
let directResult = directAssembler.append(frame) let directResult = directAssembler.append(frame)
XCTAssertEqual(directResult.frames.first?.count, frame.count) #expect(directResult.frames.first?.count == frame.count)
} }
func testAssemblesMultipleFramesSequentially() { @Test func assemblesMultipleFramesSequentially() throws {
var assembler = NotificationStreamAssembler() var assembler = NotificationStreamAssembler()
let packet1 = makePacket(timestamp: 0xABC) let packet1 = makePacket(timestamp: 0xABC)
let packet2 = makePacket(timestamp: 0xDEF) let packet2 = makePacket(timestamp: 0xDEF)
guard let frame1 = packet1.toBinaryData(padding: false), let frame1 = try #require(packet1.toBinaryData(padding: false), "Failed to encode packet")
let frame2 = packet2.toBinaryData(padding: false) else { let frame2 = try #require(packet2.toBinaryData(padding: false), "Failed to encode packet")
return XCTFail("Failed to encode packets")
}
var combined = Data() var combined = Data()
combined.append(frame1) combined.append(frame1)
@@ -77,36 +69,31 @@ final class NotificationStreamAssemblerTests: XCTestCase {
let secondChunk = combined.suffix(from: 20) let secondChunk = combined.suffix(from: 20)
var result = assembler.append(firstChunk) var result = assembler.append(firstChunk)
XCTAssertTrue(result.frames.isEmpty) #expect(result.frames.isEmpty)
result = assembler.append(secondChunk) result = assembler.append(secondChunk)
XCTAssertEqual(result.frames.count, 2) #expect(result.frames.count == 2)
guard let decoded1 = BinaryProtocol.decode(result.frames[0]),
let decoded2 = BinaryProtocol.decode(result.frames[1]) else { let decoded1 = try #require(BinaryProtocol.decode(result.frames[0]), "Failed to decode frame")
return XCTFail("Failed to decode frames") let decoded2 = try #require(BinaryProtocol.decode(result.frames[1]), "Failed to decode frame")
} #expect(decoded1.timestamp == packet1.timestamp)
XCTAssertEqual(decoded1.timestamp, packet1.timestamp) #expect(decoded2.timestamp == packet2.timestamp)
XCTAssertEqual(decoded2.timestamp, packet2.timestamp)
} }
func testDropsInvalidPrefixByte() { @Test func dropsInvalidPrefixByte() throws {
var assembler = NotificationStreamAssembler() var assembler = NotificationStreamAssembler()
let packet = makePacket(timestamp: 0xF00) let packet = makePacket(timestamp: 0xF00)
guard let frame = packet.toBinaryData(padding: false) else { let frame = try #require(packet.toBinaryData(padding: false), "Failed to encode packet")
return XCTFail("Failed to encode packet")
}
var noisyFrame = Data([0x00]) var noisyFrame = Data([0x00])
noisyFrame.append(frame) noisyFrame.append(frame)
let result = assembler.append(noisyFrame) let result = assembler.append(noisyFrame)
XCTAssertEqual(result.droppedPrefixes, [0x00]) #expect(result.droppedPrefixes == [0x00])
XCTAssertEqual(result.frames.count, 1) #expect(result.frames.count == 1)
XCTAssertFalse(result.reset) #expect(result.reset == false)
guard let decoded = BinaryProtocol.decode(result.frames[0]) else { let decoded = try #require(BinaryProtocol.decode(result.frames[0]), "Failed to decode frame after drop")
return XCTFail("Failed to decode frame after drop") #expect(decoded.timestamp == packet.timestamp)
}
XCTAssertEqual(decoded.timestamp, packet.timestamp)
} }
func testAssemblesCompressedLargeFrame() throws { func testAssemblesCompressedLargeFrame() throws {
@@ -120,9 +107,7 @@ final class NotificationStreamAssemblerTests: XCTestCase {
mimeType: "application/octet-stream", mimeType: "application/octet-stream",
content: largeContent content: largeContent
) )
guard let tlvPayload = filePacket.encode() else { let tlvPayload = try #require(filePacket.encode(), "Failed to encode file packet")
return XCTFail("Failed to encode file packet")
}
let senderID = Data(repeating: 0xAA, count: BinaryProtocol.senderIDSize) let senderID = Data(repeating: 0xAA, count: BinaryProtocol.senderIDSize)
let packet = BitchatPacket( let packet = BitchatPacket(
@@ -136,39 +121,31 @@ final class NotificationStreamAssemblerTests: XCTestCase {
version: 2 version: 2
) )
guard let frame = packet.toBinaryData(padding: false) else { let frame = try #require(packet.toBinaryData(padding: false), "Failed to encode packet frame")
return XCTFail("Failed to encode packet frame")
}
XCTAssertLessThan(BinaryProtocol.Offsets.flags, frame.count) #expect(BinaryProtocol.Offsets.flags < frame.count)
let flags = frame[frame.startIndex + BinaryProtocol.Offsets.flags] let flags = frame[frame.startIndex + BinaryProtocol.Offsets.flags]
XCTAssertNotEqual(flags & BinaryProtocol.Flags.isCompressed, 0, "Frame should be compressed for large payloads") #expect((flags & BinaryProtocol.Flags.isCompressed) != 0, "Frame should be compressed for large payloads")
let splitIndex = min(4096, frame.count / 2) let splitIndex = min(4096, frame.count / 2)
var result = assembler.append(frame.prefix(splitIndex)) var result = assembler.append(frame.prefix(splitIndex))
XCTAssertTrue(result.frames.isEmpty) #expect(result.frames.isEmpty)
result = assembler.append(frame.suffix(from: splitIndex)) result = assembler.append(frame.suffix(from: splitIndex))
XCTAssertEqual(result.frames.count, 1) #expect(result.frames.count == 1)
XCTAssertTrue(result.droppedPrefixes.isEmpty) #expect(result.droppedPrefixes.isEmpty)
XCTAssertFalse(result.reset) #expect(result.reset == false)
guard let assembled = result.frames.first else { let assembled = try #require(result.frames.first, "Missing assembled frame")
return XCTFail("Missing assembled frame") #expect(assembled.count == frame.count)
}
XCTAssertEqual(assembled.count, frame.count)
guard let decodedPacket = BinaryProtocol.decode(assembled) else { let decodedPacket = try #require(BinaryProtocol.decode(assembled), "Failed to decode compressed frame")
return XCTFail("Failed to decode compressed frame") #expect(decodedPacket.payload.count == tlvPayload.count)
}
XCTAssertEqual(decodedPacket.payload.count, tlvPayload.count)
guard let decodedFile = BitchatFilePacket.decode(decodedPacket.payload) else { let decodedFile = try #require(BitchatFilePacket.decode(decodedPacket.payload), "Failed to decode TLV payload")
return XCTFail("Failed to decode TLV payload") #expect(decodedFile.fileName == filePacket.fileName)
} #expect(decodedFile.mimeType == filePacket.mimeType)
XCTAssertEqual(decodedFile.fileName, filePacket.fileName) #expect(decodedFile.content.count == largeContent.count)
XCTAssertEqual(decodedFile.mimeType, filePacket.mimeType) #expect(decodedFile.content.prefix(32) == largeContent.prefix(32))
XCTAssertEqual(decodedFile.content.count, largeContent.count)
XCTAssertEqual(decodedFile.content.prefix(32), largeContent.prefix(32))
} }
} }
@@ -5,30 +5,29 @@
// This is free and unencumbered software released into the public domain. // This is free and unencumbered software released into the public domain.
// //
import XCTest import Testing
@testable import bitchat @testable import bitchat
final class BinaryProtocolPaddingTests: XCTestCase { struct BinaryProtocolPaddingTests {
func test_padded_vs_unpadded_length() throws { @Test func padded_vs_unpadded_length() throws {
// Use helper to create a small test packet // Use helper to create a small test packet
let packet = TestHelpers.createTestPacket() let packet = TestHelpers.createTestPacket()
guard let padded = BinaryProtocol.encode(packet, padding: true) else { return XCTFail("encode padded") } let padded = try #require(BinaryProtocol.encode(packet, padding: true), "encode padded")
guard let unpadded = BinaryProtocol.encode(packet, padding: false) else { return XCTFail("encode unpadded") } let unpadded = try #require(BinaryProtocol.encode(packet, padding: false), "encode unpadded")
XCTAssertGreaterThanOrEqual(padded.count, unpadded.count, "Padded frame should be >= unpadded") #expect(padded.count >= unpadded.count, "Padded frame should be >= unpadded")
} }
func test_decode_padded_and_unpadded_round_trip() throws { @Test func decode_padded_and_unpadded_round_trip() throws {
let packet = TestHelpers.createTestPacket() let packet = TestHelpers.createTestPacket()
// Padded
guard let padded = BinaryProtocol.encode(packet, padding: true) else { return XCTFail("encode padded") } let padded = try #require(BinaryProtocol.encode(packet, padding: true), "encode padded")
guard let dec1 = BinaryProtocol.decode(padded) else { return XCTFail("decode padded") } let dec1 = try #require(BinaryProtocol.decode(padded), "decode padded")
XCTAssertEqual(dec1.type, packet.type) #expect(dec1.type == packet.type)
XCTAssertEqual(dec1.payload, packet.payload) #expect(dec1.payload == packet.payload)
// Unpadded
guard let unpadded = BinaryProtocol.encode(packet, padding: false) else { return XCTFail("encode unpadded") } let unpadded = try #require(BinaryProtocol.encode(packet, padding: false), "encode unpadded")
guard let dec2 = BinaryProtocol.decode(unpadded) else { return XCTFail("decode unpadded") } let dec2 = try #require(BinaryProtocol.decode(unpadded), "decode unpadded")
XCTAssertEqual(dec2.type, packet.type) #expect(dec2.type == packet.type)
XCTAssertEqual(dec2.payload, packet.payload) #expect(dec2.payload == packet.payload)
} }
} }
+201 -213
View File
@@ -6,123 +6,170 @@
// For more information, see <https://unlicense.org> // For more information, see <https://unlicense.org>
// //
import XCTest import Testing
import Foundation
@testable import bitchat @testable import bitchat
final class BinaryProtocolTests: XCTestCase { struct BinaryProtocolTests {
// MARK: - Basic Encoding/Decoding Tests // MARK: - Basic Encoding/Decoding Tests
func testBasicPacketEncodingDecoding() throws { @Test func basicPacketEncodingDecoding() throws {
let originalPacket = TestHelpers.createTestPacket() let originalPacket = TestHelpers.createTestPacket()
// Encode let encodedData = try #require(BinaryProtocol.encode(originalPacket), "Failed to encode packet")
guard let encodedData = BinaryProtocol.encode(originalPacket) else { let decodedPacket = try #require(BinaryProtocol.decode(encodedData), "Failed to decode packet")
XCTFail("Failed to encode packet")
return
}
// Decode
guard let decodedPacket = BinaryProtocol.decode(encodedData) else {
XCTFail("Failed to decode packet")
return
}
// Verify // Verify
XCTAssertEqual(decodedPacket.type, originalPacket.type) #expect(decodedPacket.type == originalPacket.type)
XCTAssertEqual(decodedPacket.ttl, originalPacket.ttl) #expect(decodedPacket.ttl == originalPacket.ttl)
XCTAssertEqual(decodedPacket.timestamp, originalPacket.timestamp) #expect(decodedPacket.timestamp == originalPacket.timestamp)
XCTAssertEqual(decodedPacket.payload, originalPacket.payload) #expect(decodedPacket.payload == originalPacket.payload)
// Sender ID should match (accounting for padding) // Sender ID should match (accounting for padding)
let originalSenderID = originalPacket.senderID.prefix(BinaryProtocol.senderIDSize) let originalSenderID = originalPacket.senderID.prefix(BinaryProtocol.senderIDSize)
let decodedSenderID = decodedPacket.senderID.trimmingNullBytes() let decodedSenderID = decodedPacket.senderID.trimmingNullBytes()
XCTAssertEqual(decodedSenderID, originalSenderID) #expect(decodedSenderID == originalSenderID)
} }
func testPacketWithRecipient() throws { @Test func packetWithRecipient() throws {
let recipientID = TestConstants.testPeerID2 let recipientID = PeerID(str: "abcdef0123456789abcdef0123456789abcdef0123456789abcdef0123456789")
let packet = TestHelpers.createTestPacket(recipientID: recipientID) let packet = TestHelpers.createTestPacket(recipientID: recipientID)
let encodedData = try #require(BinaryProtocol.encode(packet), "Failed to encode packet with recipient")
// Encode and decode let decodedPacket = try #require(BinaryProtocol.decode(encodedData), "Failed to decode packet with recipient")
guard let encodedData = BinaryProtocol.encode(packet),
let decodedPacket = BinaryProtocol.decode(encodedData) else {
XCTFail("Failed to encode/decode packet with recipient")
return
}
// Verify recipient // Verify recipient
XCTAssertNotNil(decodedPacket.recipientID) #expect(decodedPacket.recipientID != nil)
let decodedRecipientID = decodedPacket.recipientID?.trimmingNullBytes() let decodedRecipientID = decodedPacket.recipientID?.trimmingNullBytes()
XCTAssertTrue(String(data: decodedRecipientID!, encoding: .utf8) == recipientID) // TODO: Check if this is intended that the decoding only gets the first 8
#expect(String(data: decodedRecipientID!, encoding: .utf8) == "abcdef01")
} }
func testPacketWithSignature() throws { @Test func packetWithSignature() throws {
let packet = TestHelpers.createTestPacket( let packet = TestHelpers.createTestPacket(signature: TestConstants.testSignature)
signature: TestConstants.testSignature let encodedData = try #require(BinaryProtocol.encode(packet), "Failed to encode packet with signature")
) let decodedPacket = try #require(BinaryProtocol.decode(encodedData), "Failed to decode packet with signature")
// Encode and decode
guard let encodedData = BinaryProtocol.encode(packet),
let decodedPacket = BinaryProtocol.decode(encodedData) else {
XCTFail("Failed to encode/decode packet with signature")
return
}
// Verify signature // Verify signature
XCTAssertNotNil(decodedPacket.signature) #expect(decodedPacket.signature != nil)
XCTAssertEqual(decodedPacket.signature, TestConstants.testSignature) #expect(decodedPacket.signature == TestConstants.testSignature)
}
@Test func packetWithRouteRoundTrip() throws {
let route: [Data] = [
try #require(Data(hexString: "0102030405060708")),
try #require(Data(hexString: "1112131415161718")),
try #require(Data(hexString: "2122232425262728"))
]
var packet = BitchatPacket(
type: 0x01,
senderID: route[0],
recipientID: route.last,
timestamp: 1_720_000_000_000,
payload: Data("route-test".utf8),
signature: nil,
ttl: 6
)
packet.route = route
let encoded = try #require(BinaryProtocol.encode(packet), "Failed to encode packet with route")
let flagsByte = encoded[BinaryProtocol.Offsets.flags]
#expect((flagsByte & BinaryProtocol.Flags.hasRoute) != 0)
let decoded = try #require(BinaryProtocol.decode(encoded), "Failed to decode packet with route")
let decodedRoute = try #require(decoded.route)
#expect(decodedRoute.count == route.count)
for (expected, actual) in zip(route, decodedRoute) {
#expect(actual == expected)
}
}
@Test func packetWithRoutePadsShortHop() throws {
let sender = try #require(Data(hexString: "0011223344556677"))
let destination = try #require(Data(hexString: "8899aabbccddeeff"))
let shortHop = Data([0xAA, 0xBB, 0xCC])
var packet = BitchatPacket(
type: 0x02,
senderID: sender,
recipientID: destination,
timestamp: 1_730_000_000_000,
payload: Data("pad-test".utf8),
signature: nil,
ttl: 5
)
packet.route = [shortHop, destination]
let encoded = try #require(BinaryProtocol.encode(packet), "Failed to encode packet with short hop route")
let decoded = try #require(BinaryProtocol.decode(encoded), "Failed to decode packet with short hop route")
let decodedRoute = try #require(decoded.route)
let firstHop = try #require(decodedRoute.first)
#expect(firstHop.count == BinaryProtocol.senderIDSize)
#expect(firstHop.prefix(shortHop.count) == shortHop)
let paddingBytes = firstHop.suffix(firstHop.count - shortHop.count)
#expect(paddingBytes.allSatisfy { $0 == 0 })
}
@Test func packetWithRouteAndCompressedPayload() throws {
let route: [Data] = [
try #require(Data(hexString: "0101010101010101")),
try #require(Data(hexString: "0202020202020202"))
]
let repeatedString = String(repeating: "compress-me", count: 150)
var packet = BitchatPacket(
type: 0x03,
senderID: route[0],
recipientID: route.last,
timestamp: 1_740_000_000_000,
payload: Data(repeatedString.utf8),
signature: nil,
ttl: 7
)
packet.route = route
let encoded = try #require(BinaryProtocol.encode(packet), "Failed to encode packet with route and compression")
let decoded = try #require(BinaryProtocol.decode(encoded), "Failed to decode packet with route and compression")
#expect(decoded.payload == Data(repeatedString.utf8))
let decodedRoute = try #require(decoded.route)
#expect(decodedRoute == route)
} }
// MARK: - Compression Tests // MARK: - Compression Tests
func testPayloadCompression() throws { @Test("Create a large, compressible payload above current threshold (2048B)")
// Create a large, compressible payload above current threshold (2048B) func payloadCompression() throws {
let repeatedString = String(repeating: "This is a test message. ", count: 200) let repeatedString = String(repeating: "This is a test message. ", count: 200)
let largePayload = repeatedString.data(using: .utf8)! let largePayload = repeatedString.data(using: .utf8)!
let packet = TestHelpers.createTestPacket(payload: largePayload) let packet = TestHelpers.createTestPacket(payload: largePayload)
// Encode (should compress) // Encode (should compress)
guard let encodedData = BinaryProtocol.encode(packet) else { let encodedData = try #require(BinaryProtocol.encode(packet), "Failed to encode packet with large payload")
XCTFail("Failed to encode packet with large payload")
return
}
// The encoded size should be smaller than uncompressed due to compression // The encoded size should be smaller than uncompressed due to compression
guard let headerSize = BinaryProtocol.headerSize(for: packet.version) else { let headerSize = try #require(BinaryProtocol.headerSize(for: packet.version), "Invalid packet version")
XCTFail("Invalid version")
return
}
let uncompressedSize = headerSize + BinaryProtocol.senderIDSize + largePayload.count let uncompressedSize = headerSize + BinaryProtocol.senderIDSize + largePayload.count
XCTAssertLessThan(encodedData.count, uncompressedSize) #expect(encodedData.count < uncompressedSize, "Compressed packet should be smaller than uncompressed form")
// Decode and verify // Decode and verify
guard let decodedPacket = BinaryProtocol.decode(encodedData) else { let decodedPacket = try #require(BinaryProtocol.decode(encodedData), "Failed to decode compressed packet")
XCTFail("Failed to decode compressed packet")
return
}
XCTAssertEqual(decodedPacket.payload, largePayload) #expect(decodedPacket.payload == largePayload)
} }
func testSmallPayloadNoCompression() throws { @Test("Small payloads should not be compressed")
// Small payloads should not be compressed func smallPayloadNoCompression() throws {
let smallPayload = "Hi".data(using: .utf8)! let smallPayload = "Hi".data(using: .utf8)!
let packet = TestHelpers.createTestPacket(payload: smallPayload) let packet = TestHelpers.createTestPacket(payload: smallPayload)
let encodedData = try #require(BinaryProtocol.encode(packet), "Failed to encode small packet")
guard let encodedData = BinaryProtocol.encode(packet), let decodedPacket = try #require(BinaryProtocol.decode(encodedData), "Failed to decode small packet")
let decodedPacket = BinaryProtocol.decode(encodedData) else { #expect(decodedPacket.payload == smallPayload)
XCTFail("Failed to encode/decode small packet")
return
}
XCTAssertEqual(decodedPacket.payload, smallPayload)
} }
// MARK: - Message Padding Tests // MARK: - Message Padding Tests
func testMessagePadding() throws { @Test func messagePadding() throws {
let payloads = [ let payloads = [
"Short", "Short",
String(repeating: "Medium length message content ", count: 10), // ~300 bytes String(repeating: "Medium length message content ", count: 10), // ~300 bytes
@@ -134,43 +181,32 @@ final class BinaryProtocolTests: XCTestCase {
for payload in payloads { for payload in payloads {
let packet = TestHelpers.createTestPacket(payload: payload.data(using: .utf8)!) let packet = TestHelpers.createTestPacket(payload: payload.data(using: .utf8)!)
let encodedData = try #require(BinaryProtocol.encode(packet), "Failed to encode packet")
guard let encodedData = BinaryProtocol.encode(packet) else {
XCTFail("Failed to encode packet")
continue
}
// Verify padding creates standard block sizes up to configured limit (no 4096 bucket currently) // Verify padding creates standard block sizes up to configured limit (no 4096 bucket currently)
let blockSizes = [256, 512, 1024, 2048] let blockSizes = [256, 512, 1024, 2048]
if encodedData.count <= 2048 { if encodedData.count <= 2048 {
XCTAssertTrue(blockSizes.contains(encodedData.count), "Encoded size \(encodedData.count) is not a standard block size") #expect(blockSizes.contains(encodedData.count), "Encoded size \(encodedData.count) is not a standard block size")
} else { } else {
// For very large payloads we expect no additional padding beyond raw size // For very large payloads we expect no additional padding beyond raw size
XCTAssertGreaterThan(encodedData.count, 2048) #expect(encodedData.count > 2048)
} }
encodedSizes.insert(encodedData.count) encodedSizes.insert(encodedData.count)
// Verify decoding works // Verify decoding works
guard let decodedPacket = BinaryProtocol.decode(encodedData) else { let decodedPacket = try #require(BinaryProtocol.decode(encodedData), "Failed to decode padded packet")
XCTFail("Failed to decode padded packet") #expect(String(data: decodedPacket.payload, encoding: .utf8) == payload)
continue
}
XCTAssertEqual(String(data: decodedPacket.payload, encoding: .utf8), payload)
} }
// Different payload sizes (within <=2048) may map to the same bucket depending on compression. // Different payload sizes (within <=2048) may map to the same bucket depending on compression.
// Require at least one padded size to be present. // Require at least one padded size to be present.
XCTAssertGreaterThanOrEqual(encodedSizes.filter { $0 <= 2048 }.count, 1, "Expected at least one padded size up to 2048, got \(encodedSizes)") #expect(encodedSizes.filter { $0 <= 2048 }.count >= 1, "Expected at least one padded size up to 2048, got \(encodedSizes)")
} }
func testInvalidPKCS7PaddingIsRejected() throws { @Test func invalidPKCS7PaddingIsRejected() throws {
let pkt = TestHelpers.createTestPacket(payload: Data(repeating: 0x41, count: 50)) // small let pkt = TestHelpers.createTestPacket(payload: Data(repeating: 0x41, count: 50)) // small
guard let enc0 = BinaryProtocol.encode(pkt) else { let enc0 = try #require(BinaryProtocol.encode(pkt), "encode failed")
XCTFail("encode failed")
return
}
// Force padding to known block for test stability // Force padding to known block for test stability
var enc = MessagePadding.pad(enc0, toSize: 256) var enc = MessagePadding.pad(enc0, toSize: 256)
let unpadded = MessagePadding.unpad(enc) let unpadded = MessagePadding.unpad(enc)
@@ -181,39 +217,33 @@ final class BinaryProtocolTests: XCTestCase {
let maybe = BinaryProtocol.decode(enc) let maybe = BinaryProtocol.decode(enc)
// If decode still succeeds (nested pad edge case), at least ensure payload integrity // If decode still succeeds (nested pad edge case), at least ensure payload integrity
if let pkt2 = maybe { if let pkt2 = maybe {
XCTAssertEqual(pkt2.payload, pkt.payload) #expect(pkt2.payload == pkt.payload)
} else { } else {
XCTAssertNil(maybe) #expect(maybe == nil)
} }
} else { } else {
// If no padding was applied, just assert decode succeeds (nothing to test) // If no padding was applied, just assert decode succeeds (nothing to test)
XCTAssertNotNil(BinaryProtocol.decode(enc)) #expect(BinaryProtocol.decode(enc) != nil)
} }
} }
// MARK: - Message Encoding/Decoding Tests // MARK: - Message Encoding/Decoding Tests
func testMessageEncodingDecoding() throws { @Test func messageEncodingDecoding() throws {
let message = TestHelpers.createTestMessage() let message = TestHelpers.createTestMessage()
guard let payload = message.toBinaryPayload() else { let payload = try #require(message.toBinaryPayload(), "Failed to encode message to binary")
XCTFail("Failed to encode message to binary")
return
}
guard let decodedMessage = BitchatMessage(payload) else { let decodedMessage = try #require(BitchatMessage(payload), "Failed to decode message from binary")
XCTFail("Failed to decode message from binary")
return
}
XCTAssertEqual(decodedMessage.content, message.content) #expect(decodedMessage.content == message.content)
XCTAssertEqual(decodedMessage.sender, message.sender) #expect(decodedMessage.sender == message.sender)
XCTAssertEqual(decodedMessage.senderPeerID, message.senderPeerID) #expect(decodedMessage.senderPeerID == message.senderPeerID)
XCTAssertEqual(decodedMessage.isPrivate, message.isPrivate) #expect(decodedMessage.isPrivate == message.isPrivate)
// Timestamp should be close (within 1 second due to conversion) // Timestamp should be close (within 1 second due to conversion)
let timeDiff = abs(decodedMessage.timestamp.timeIntervalSince(message.timestamp)) let timeDiff = abs(decodedMessage.timestamp.timeIntervalSince(message.timestamp))
XCTAssertLessThan(timeDiff, 1.0) #expect(timeDiff < 1)
} }
func testPrivateMessageEncoding() throws { func testPrivateMessageEncoding() throws {
@@ -222,30 +252,22 @@ final class BinaryProtocolTests: XCTestCase {
recipientNickname: TestConstants.testNickname2 recipientNickname: TestConstants.testNickname2
) )
guard let payload = message.toBinaryPayload(), let payload = try #require(message.toBinaryPayload(), "Failed to encode private message")
let decodedMessage = BitchatMessage(payload) else { let decodedMessage = try #require(BitchatMessage(payload), "Failed to decode private message")
XCTFail("Failed to encode/decode private message")
return
}
XCTAssertTrue(decodedMessage.isPrivate) #expect(decodedMessage.isPrivate)
XCTAssertEqual(decodedMessage.recipientNickname, TestConstants.testNickname2) #expect(decodedMessage.recipientNickname == TestConstants.testNickname2)
} }
func testMessageWithMentions() throws { @Test func messageWithMentions() throws {
let mentions = [TestConstants.testNickname2, TestConstants.testNickname3] let mentions = [TestConstants.testNickname2, TestConstants.testNickname3]
let message = TestHelpers.createTestMessage(mentions: mentions) let message = TestHelpers.createTestMessage(mentions: mentions)
let payload = try #require(message.toBinaryPayload(), "Failed to encode message with mentions")
guard let payload = message.toBinaryPayload(), let decodedMessage = try #require(BitchatMessage(payload), "Failed to decode message with mentions")
let decodedMessage = BitchatMessage(payload) else { #expect(decodedMessage.mentions == mentions)
XCTFail("Failed to encode/decode message with mentions")
return
}
XCTAssertEqual(decodedMessage.mentions, mentions)
} }
func testRelayMessageEncoding() throws { @Test func relayMessageEncoding() throws {
let message = BitchatMessage( let message = BitchatMessage(
id: UUID().uuidString, id: UUID().uuidString,
sender: TestConstants.testNickname1, sender: TestConstants.testNickname1,
@@ -255,105 +277,77 @@ final class BinaryProtocolTests: XCTestCase {
originalSender: TestConstants.testNickname3, originalSender: TestConstants.testNickname3,
isPrivate: false, isPrivate: false,
recipientNickname: nil, recipientNickname: nil,
senderPeerID: TestConstants.testPeerID1,
mentions: nil mentions: nil
) )
let payload = try #require(message.toBinaryPayload(), "Failed to encode relay message")
guard let payload = message.toBinaryPayload(), let decodedMessage = try #require(BitchatMessage(payload), "Failed to decode relay message")
let decodedMessage = BitchatMessage(payload) else { #expect(decodedMessage.isRelay)
XCTFail("Failed to encode/decode relay message") #expect(decodedMessage.originalSender == TestConstants.testNickname3)
return
}
XCTAssertTrue(decodedMessage.isRelay)
XCTAssertEqual(decodedMessage.originalSender, TestConstants.testNickname3)
} }
// MARK: - Edge Cases and Error Handling // MARK: - Edge Cases and Error Handling
func testInvalidDataDecoding() { @Test("Too small data")
// Too small data func invalidDataDecoding() throws {
let tooSmall = Data(repeating: 0, count: 5) let tooSmall = Data(repeating: 0, count: 5)
XCTAssertNil(BinaryProtocol.decode(tooSmall)) #expect(BinaryProtocol.decode(tooSmall) == nil)
// Random data // Random data
let random = TestHelpers.generateRandomData(length: 100) let random = TestHelpers.generateRandomData(length: 100)
XCTAssertNil(BinaryProtocol.decode(random)) #expect(BinaryProtocol.decode(random) == nil)
// Corrupted header // Corrupted header
let packet = TestHelpers.createTestPacket() let packet = TestHelpers.createTestPacket()
guard var encoded = BinaryProtocol.encode(packet) else { var encoded = try #require(BinaryProtocol.encode(packet), "Failed to encode test packet")
XCTFail("Failed to encode test packet")
return
}
// Corrupt the version byte // Corrupt the version byte
encoded[0] = 0xFF encoded[0] = 0xFF
XCTAssertNil(BinaryProtocol.decode(encoded)) #expect(BinaryProtocol.decode(encoded) == nil)
} }
func testLargeMessageHandling() throws { @Test("Test maximum size handling")
// Test maximum size handling func largeMessageHandling() throws {
let largeContent = String(repeating: "X", count: 65535) // Max uint16 let largeContent = String(repeating: "X", count: 65535) // Max uint16
let message = TestHelpers.createTestMessage(content: largeContent) let message = TestHelpers.createTestMessage(content: largeContent)
let payload = try #require(message.toBinaryPayload(), "Failed to handle large message")
guard let payload = message.toBinaryPayload(), let decodedMessage = try #require(BitchatMessage(payload), "Failed to handle large message")
let decodedMessage = BitchatMessage(payload) else { #expect(decodedMessage.content == largeContent)
XCTFail("Failed to handle large message")
return
}
XCTAssertEqual(decodedMessage.content, largeContent)
} }
func testEmptyFieldsHandling() throws { @Test("Test message with empty content")
// Test message with empty content func emptyFieldsHandling() throws {
let emptyMessage = TestHelpers.createTestMessage(content: "") let emptyMessage = TestHelpers.createTestMessage(content: "")
let payload = try #require(emptyMessage.toBinaryPayload(), "Failed to handle empty message")
guard let payload = emptyMessage.toBinaryPayload(), let decodedMessage = try #require(BitchatMessage(payload), "Failed to handle empty message")
let decodedMessage = BitchatMessage(payload) else { #expect(decodedMessage.content.isEmpty)
XCTFail("Failed to handle empty message")
return
}
XCTAssertEqual(decodedMessage.content, "")
} }
// MARK: - Protocol Version Tests // MARK: - Protocol Version Tests
func testProtocolVersionHandling() throws { @Test("Test with supported version (version is always 1 in init)")
// Test with supported version (version is always 1 in init) func protocolVersionHandling() throws {
let packet = TestHelpers.createTestPacket() let packet = TestHelpers.createTestPacket()
let encoded = try #require(BinaryProtocol.encode(packet), "Failed to encode packet with version")
guard let encoded = BinaryProtocol.encode(packet), let decoded = try #require(BinaryProtocol.decode(encoded), "Failed to decode packet with version")
let decoded = BinaryProtocol.decode(encoded) else { #expect(decoded.version == 1)
XCTFail("Failed to encode/decode packet with version")
return
}
XCTAssertEqual(decoded.version, 1)
} }
func testUnsupportedProtocolVersion() throws { @Test("Create packet data with unsupported version")
// Create packet data with unsupported version func unsupportedProtocolVersion() throws {
let packet = TestHelpers.createTestPacket() let packet = TestHelpers.createTestPacket()
var encoded = try #require(BinaryProtocol.encode(packet), "Failed to encode packet")
guard var encoded = BinaryProtocol.encode(packet) else {
XCTFail("Failed to encode packet")
return
}
// Manually change version byte to unsupported value // Manually change version byte to unsupported value
encoded[0] = 99 // Unsupported version encoded[0] = 99 // Unsupported version
// Should fail to decode // Should fail to decode
XCTAssertNil(BinaryProtocol.decode(encoded)) #expect(BinaryProtocol.decode(encoded) == nil)
} }
// MARK: - Bounds Checking Tests (Crash Prevention) // MARK: - Bounds Checking Tests (Crash Prevention)
func testMalformedPacketWithInvalidPayloadLength() throws { @Test("Test the specific crash scenario: payloadLength = 193 (0xc1) but only 30 bytes available")
// Test the specific crash scenario: payloadLength = 193 (0xc1) but only 30 bytes available func malformedPacketWithInvalidPayloadLength() throws {
var malformedData = Data() var malformedData = Data()
// Valid header (13 bytes) // Valid header (13 bytes)
@@ -383,20 +377,17 @@ final class BinaryProtocolTests: XCTestCase {
} }
// Total data is now 30 bytes, but payloadLength claims 193 // Total data is now 30 bytes, but payloadLength claims 193
XCTAssertEqual(malformedData.count, 30) #expect(malformedData.count == 30)
// This should not crash - should return nil gracefully // This should not crash - should return nil gracefully
let result = BinaryProtocol.decode(malformedData) let result = BinaryProtocol.decode(malformedData)
XCTAssertNil(result, "Malformed packet with invalid payload length should return nil, not crash") #expect(result == nil, "Malformed packet with invalid payload length should return nil, not crash")
} }
func testTruncatedPacketHandling() throws { @Test("Test various truncation scenarios")
// Test various truncation scenarios func truncatedPacketHandling() throws {
let packet = TestHelpers.createTestPacket() let packet = TestHelpers.createTestPacket()
guard let validEncoded = BinaryProtocol.encode(packet) else { let validEncoded = try #require(BinaryProtocol.encode(packet), "Failed to encode test packet")
XCTFail("Failed to encode test packet")
return
}
// Test truncation at various points // Test truncation at various points
let truncationPoints = [0, 5, 10, 15, 20, 25] let truncationPoints = [0, 5, 10, 15, 20, 25]
@@ -404,12 +395,12 @@ final class BinaryProtocolTests: XCTestCase {
for point in truncationPoints { for point in truncationPoints {
let truncated = validEncoded.prefix(point) let truncated = validEncoded.prefix(point)
let result = BinaryProtocol.decode(truncated) let result = BinaryProtocol.decode(truncated)
XCTAssertNil(result, "Truncated packet at \(point) bytes should return nil, not crash") #expect(result == nil, "Truncated packet at \(point) bytes should return nil, not crash")
} }
} }
func testMalformedCompressedPacket() throws { @Test("Test compressed packet with invalid original size")
// Test compressed packet with invalid original size func malformedCompressedPacket() throws {
var malformedData = Data() var malformedData = Data()
// Valid header // Valid header
@@ -438,11 +429,11 @@ final class BinaryProtocolTests: XCTestCase {
// Should handle this gracefully // Should handle this gracefully
let result = BinaryProtocol.decode(malformedData) let result = BinaryProtocol.decode(malformedData)
XCTAssertNil(result, "Malformed compressed packet should return nil, not crash") #expect(result == nil, "Malformed compressed packet should return nil, not crash")
} }
func testExcessivelyLargePayloadLength() throws { @Test("Test packet claiming extremely large payload")
// Test packet claiming extremely large payload func excessivelyLargePayloadLength() throws {
var malformedData = Data() var malformedData = Data()
// Valid header // Valid header
@@ -471,11 +462,11 @@ final class BinaryProtocolTests: XCTestCase {
// Should handle this gracefully without trying to allocate massive amounts of memory // Should handle this gracefully without trying to allocate massive amounts of memory
let result = BinaryProtocol.decode(malformedData) let result = BinaryProtocol.decode(malformedData)
XCTAssertNil(result, "Packet with excessive payload length should return nil, not crash") #expect(result == nil, "Packet with excessive payload length should return nil, not crash")
} }
func testCompressedPacketWithInvalidOriginalSize() throws { @Test("Test compressed packet with unreasonable original size")
// Test compressed packet with unreasonable original size func compressedPacketWithInvalidOriginalSize() throws {
var malformedData = Data() var malformedData = Data()
// Valid header // Valid header
@@ -513,11 +504,11 @@ final class BinaryProtocolTests: XCTestCase {
} }
let result = BinaryProtocol.decode(malformedData) let result = BinaryProtocol.decode(malformedData)
XCTAssertNil(result, "Compressed packet with invalid original size should return nil, not crash") #expect(result == nil, "Compressed packet with invalid original size should return nil, not crash")
} }
func testMaliciousPacketWithIntegerOverflow() throws { @Test("Test packet designed to cause integer overflow")
// Test packet designed to cause integer overflow func maliciousPacketWithIntegerOverflow() throws {
var maliciousData = Data() var maliciousData = Data()
// Valid header // Valid header
@@ -552,27 +543,24 @@ final class BinaryProtocolTests: XCTestCase {
// Should handle gracefully without integer overflow issues // Should handle gracefully without integer overflow issues
let result = BinaryProtocol.decode(maliciousData) let result = BinaryProtocol.decode(maliciousData)
XCTAssertNil(result, "Malicious packet designed for integer overflow should return nil, not crash") #expect(result == nil, "Malicious packet designed for integer overflow should return nil, not crash")
} }
func testPartialHeaderData() throws { @Test("Test packets with incomplete headers")
// Test packets with incomplete headers func partialHeaderData() throws {
let headerSizes = [0, 1, 5, 10, 12] // Various incomplete header sizes let headerSizes = [0, 1, 5, 10, 12] // Various incomplete header sizes
for size in headerSizes { for size in headerSizes {
let partialData = Data(repeating: 0x01, count: size) let partialData = Data(repeating: 0x01, count: size)
let result = BinaryProtocol.decode(partialData) let result = BinaryProtocol.decode(partialData)
XCTAssertNil(result, "Partial header data (\(size) bytes) should return nil, not crash") #expect(result == nil, "Partial header data (\(size) bytes) should return nil, not crash")
} }
} }
func testBoundaryConditions() throws { @Test("Test exact boundary conditions")
// Test exact boundary conditions func boundaryConditions() throws {
let packet = TestHelpers.createTestPacket() let packet = TestHelpers.createTestPacket()
guard let validEncoded = BinaryProtocol.encode(packet) else { let validEncoded = try #require(BinaryProtocol.encode(packet), "Failed to encode test packet")
XCTFail("Failed to encode test packet")
return
}
// If truncation only removes padding, decode may still succeed. Compute unpadded size. // If truncation only removes padding, decode may still succeed. Compute unpadded size.
let unpadded = MessagePadding.unpad(validEncoded) let unpadded = MessagePadding.unpad(validEncoded)
@@ -580,7 +568,7 @@ final class BinaryProtocolTests: XCTestCase {
let cut = max(1, unpadded.count - 10) let cut = max(1, unpadded.count - 10)
let truncatedCore = unpadded.prefix(cut) let truncatedCore = unpadded.prefix(cut)
let result = BinaryProtocol.decode(truncatedCore) let result = BinaryProtocol.decode(truncatedCore)
XCTAssertNil(result, "Truncated core frame should return nil, not crash") #expect(result == nil, "Truncated core frame should return nil, not crash")
// Test minimum valid size - create a valid minimal packet // Test minimum valid size - create a valid minimal packet
var minData = Data() var minData = Data()
@@ -0,0 +1,86 @@
//
// MeshTopologyTrackerTests.swift
// bitchatTests
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import Testing
import Foundation
@testable import bitchat
struct MeshTopologyTrackerTests {
private func hex(_ value: String) throws -> Data {
try #require(Data(hexString: value))
}
@Test func directLinkProducesRoute() throws {
let tracker = MeshTopologyTracker()
let a = try hex("0102030405060708")
let b = try hex("1112131415161718")
tracker.recordDirectLink(between: a, and: b)
let route = try #require(tracker.computeRoute(from: a, to: b))
#expect(route == [a, b])
}
@Test func multiHopRouteComputation() throws {
let tracker = MeshTopologyTracker()
let a = try hex("0001020304050607")
let b = try hex("1011121314151617")
let c = try hex("2021222324252627")
let d = try hex("3031323334353637")
tracker.recordDirectLink(between: a, and: b)
tracker.recordDirectLink(between: b, and: c)
tracker.recordDirectLink(between: c, and: d)
let route = try #require(tracker.computeRoute(from: a, to: d))
#expect(route == [a, b, c, d])
}
@Test func recordRouteAddsEdges() throws {
let tracker = MeshTopologyTracker()
var a = Data([0xAA, 0xBB, 0xCC])
let b = try hex("4445464748494A4B")
let c = try hex("5455565758595A5B")
tracker.recordRoute([a, b, c])
a.append(Data(repeating: 0, count: BinaryProtocol.senderIDSize - a.count))
let route = try #require(tracker.computeRoute(from: a, to: c))
#expect(route.first == a)
#expect(route.last == c)
}
@Test func removingDirectLinkBreaksRoute() throws {
let tracker = MeshTopologyTracker()
let a = try hex("0101010101010101")
let b = try hex("0202020202020202")
let c = try hex("0303030303030303")
tracker.recordDirectLink(between: a, and: b)
tracker.recordDirectLink(between: b, and: c)
let initialRoute = try #require(tracker.computeRoute(from: a, to: c))
#expect(initialRoute == [a, b, c])
tracker.removeDirectLink(between: b, and: c)
#expect(tracker.computeRoute(from: a, to: c) == nil)
}
@Test func removingPeerClearsEdges() throws {
let tracker = MeshTopologyTracker()
let a = try hex("0F0E0D0C0B0A0908")
let b = try hex("0A0B0C0D0E0F0001")
let c = try hex("0011223344556677")
tracker.recordRoute([a, b, c])
let initialRoute = try #require(tracker.computeRoute(from: a, to: c))
#expect(initialRoute == [a, b, c])
tracker.removePeer(b)
#expect(tracker.computeRoute(from: a, to: c) == nil)
}
}
@@ -14,11 +14,6 @@ struct TestConstants {
static let shortTimeout: TimeInterval = 1.0 static let shortTimeout: TimeInterval = 1.0
static let longTimeout: TimeInterval = 10.0 static let longTimeout: TimeInterval = 10.0
static let testPeerID1: PeerID = "PEER1234"
static let testPeerID2: PeerID = "PEER5678"
static let testPeerID3: PeerID = "PEER9012"
static let testPeerID4: PeerID = "PEER3456"
static let testNickname1 = "Alice" static let testNickname1 = "Alice"
static let testNickname2 = "Bob" static let testNickname2 = "Bob"
static let testNickname3 = "Charlie" static let testNickname3 = "Charlie"
+6 -14
View File
@@ -30,7 +30,7 @@ final class TestHelpers {
static func createTestMessage( static func createTestMessage(
content: String = TestConstants.testMessage1, content: String = TestConstants.testMessage1,
sender: String = TestConstants.testNickname1, sender: String = TestConstants.testNickname1,
senderPeerID: PeerID = TestConstants.testPeerID1, senderPeerID: PeerID = PeerID(str: UUID().uuidString),
isPrivate: Bool = false, isPrivate: Bool = false,
recipientNickname: String? = nil, recipientNickname: String? = nil,
mentions: [String]? = nil mentions: [String]? = nil
@@ -51,7 +51,7 @@ final class TestHelpers {
static func createTestPacket( static func createTestPacket(
type: UInt8 = 0x01, type: UInt8 = 0x01,
senderID: PeerID = TestConstants.testPeerID1, senderID: PeerID = PeerID(str: UUID().uuidString),
recipientID: PeerID? = nil, recipientID: PeerID? = nil,
payload: Data = "test payload".data(using: .utf8)!, payload: Data = "test payload".data(using: .utf8)!,
signature: Data? = nil, signature: Data? = nil,
@@ -90,7 +90,7 @@ final class TestHelpers {
if Date().timeIntervalSince(start) > timeout { if Date().timeIntervalSince(start) > timeout {
throw TestError.timeout throw TestError.timeout
} }
try await Task.sleep(nanoseconds: 10_000_000) // 10ms try await sleep(0.01)
} }
} }
@@ -104,7 +104,7 @@ final class TestHelpers {
} }
group.addTask { group.addTask {
try await Task.sleep(nanoseconds: UInt64(timeout * 1_000_000_000)) try await sleep(1)
throw TestError.timeout throw TestError.timeout
} }
@@ -121,14 +121,6 @@ enum TestError: Error {
case testFailure(String) case testFailure(String)
} }
// MARK: - PeerID String Helpers func sleep(_ seconds: TimeInterval) async throws {
try await Task.sleep(nanoseconds: UInt64(seconds * 1_000_000_000))
/// Raw String can be passed as PeerID
extension PeerID: @retroactive ExpressibleByStringLiteral {
public init(stringLiteral value: String) {
self.init(str: value)
}
} }
/// Interpolated String can be passed as PeerID
extension PeerID: @retroactive ExpressibleByStringInterpolation {}
+187 -202
View File
@@ -6,11 +6,11 @@
// For more information, see <https://unlicense.org> // For more information, see <https://unlicense.org>
// //
import XCTest import Testing
import Foundation
@testable import bitchat @testable import bitchat
final class PeerIDTests: XCTestCase { struct PeerIDTests {
private let hex16 = "0011223344556677" private let hex16 = "0011223344556677"
private let hex64 = "00112233445566778899aabbccddeeff00112233445566778899aabbccddeeff" private let hex64 = "00112233445566778899aabbccddeeff00112233445566778899aabbccddeeff"
@@ -22,212 +22,225 @@ final class PeerIDTests: XCTestCase {
// MARK: - Empty prefix // MARK: - Empty prefix
func test_init_empty_prefix_with16() { @Test func empty_prefix_with16() {
let peerID = PeerID(str: hex16) let peerID = PeerID(str: hex16)
XCTAssertEqual(peerID.id, hex16) #expect(peerID.id == hex16)
XCTAssertEqual(peerID.bare, hex16) #expect(peerID.bare == hex16)
XCTAssertEqual(peerID.prefix, .empty) #expect(peerID.prefix == .empty)
} }
func test_init_empty_prefix_with64() { @Test func empty_prefix_with64() {
let peerID = PeerID(str: hex64) let peerID = PeerID(str: hex64)
XCTAssertEqual(peerID.id, hex64) #expect(peerID.id == hex64)
XCTAssertEqual(peerID.bare, hex64) #expect(peerID.bare == hex64)
XCTAssertEqual(peerID.prefix, .empty) #expect(peerID.prefix == .empty)
} }
// MARK: - Mesh prefix // MARK: - Mesh prefix
func test_init_mesh_prefix_with16() { @Test func mesh_prefix_with16() {
let str = "mesh:" + hex16 let str = "mesh:" + hex16
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, hex16) #expect(peerID.bare == hex16)
XCTAssertEqual(peerID.prefix, .mesh) #expect(peerID.prefix == .mesh)
} }
func test_init_mesh_prefix_with64() { @Test func mesh_prefix_with64() {
let str = "mesh:" + hex64 let str = "mesh:" + hex64
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, hex64) #expect(peerID.bare == hex64)
XCTAssertEqual(peerID.prefix, .mesh) #expect(peerID.prefix == .mesh)
} }
// MARK: - Name prefix // MARK: - Name prefix
func test_init_name_prefix() { @Test func name_prefix() {
let str = "name:some_name" let str = "name:some_name"
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, "some_name") #expect(peerID.bare == "some_name")
XCTAssertEqual(peerID.prefix, .name) #expect(peerID.prefix == .name)
} }
// MARK: - Noise prefix // MARK: - Noise prefix
func test_init_noise_prefix_with16() { @Test func noise_prefix_with16() {
let str = "noise:" + hex16 let str = "noise:" + hex16
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, hex16) #expect(peerID.bare == hex16)
XCTAssertEqual(peerID.prefix, .noise) #expect(peerID.prefix == .noise)
} }
func test_init_noise_prefix_with64() { @Test func noise_prefix_with64() {
let str = "noise:" + hex64 let str = "noise:" + hex64
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, hex64) #expect(peerID.bare == hex64)
XCTAssertEqual(peerID.prefix, .noise) #expect(peerID.prefix == .noise)
} }
// MARK: - GeoDM prefix // MARK: - GeoDM prefix
func test_init_geoDM_prefix_with16() { @Test func geoDM_prefix_with16() {
let str = "nostr_" + hex16 let str = "nostr_" + hex16
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, hex16) #expect(peerID.bare == hex16)
XCTAssertEqual(peerID.prefix, .geoDM) #expect(peerID.prefix == .geoDM)
} }
func test_init_geoDM_prefix_with64() { @Test func geoDM_prefix_with64() {
let str = "nostr_" + hex64 let str = "nostr_" + hex64
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, hex64) #expect(peerID.bare == hex64)
XCTAssertEqual(peerID.prefix, .geoDM) #expect(peerID.prefix == .geoDM)
} }
// MARK: - GeoChat prefix // MARK: - GeoChat prefix
func test_init_geoChat_prefix_with16() { @Test func geoChat_prefix_with16() {
let str = "nostr:" + hex16 let str = "nostr:" + hex16
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, hex16) #expect(peerID.bare == hex16)
XCTAssertEqual(peerID.prefix, .geoChat) #expect(peerID.prefix == .geoChat)
} }
func test_init_geoChat_prefix_with64() { @Test func geoChat_prefix_with64() {
let str = "nostr:" + hex64 let str = "nostr:" + hex64
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, hex64) #expect(peerID.bare == hex64)
XCTAssertEqual(peerID.prefix, .geoChat) #expect(peerID.prefix == .geoChat)
} }
// MARK: - Edge cases // MARK: - Edge cases
func test_init_with_unknown_prefix() { @Test func with_unknown_prefix() {
let str = "unknown:" + hex16 let str = "unknown:" + hex16
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
// Falls back to .empty // Falls back to .empty
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, str) #expect(peerID.bare == str)
XCTAssertEqual(peerID.prefix, .empty) #expect(peerID.prefix == .empty)
} }
func test_init_with_only_prefix_no_bare() { @Test func with_only_prefix_no_bare() {
let str = "mesh:" let str = "mesh:"
let peerID = PeerID(str: str) let peerID = PeerID(str: str)
XCTAssertEqual(peerID.id, str) #expect(peerID.id == str)
XCTAssertEqual(peerID.bare, "") #expect(peerID.bare == "")
XCTAssertEqual(peerID.prefix, .mesh) #expect(peerID.prefix == .mesh)
} }
// MARK: - init?(data:) // MARK: - init?(data:)
func test_init_data_valid_utf8() { @Test func data_valid_utf8() {
let peerID = PeerID(data: Data(hex16.utf8)) let peerID = PeerID(data: Data(hex16.utf8))
XCTAssertNotNil(peerID) #expect(peerID != nil)
XCTAssertEqual(peerID?.bare, hex16) #expect(peerID?.bare == hex16)
XCTAssertEqual(peerID?.prefix, .empty) #expect(peerID?.prefix == .empty)
} }
func test_init_data_invalid_utf8() { @Test func data_invalid_utf8() {
// Random invalid UTF8 // Random invalid UTF8
let bytes: [UInt8] = [0xFF, 0xFE, 0xFA] let bytes: [UInt8] = [0xFF, 0xFE, 0xFA]
let peerID = PeerID(data: Data(bytes)) let peerID = PeerID(data: Data(bytes))
XCTAssertNil(peerID) #expect(peerID == nil)
} }
// MARK: - init(str: Substring) // MARK: - init(str: Substring)
func test_init_substring() { @Test func substring() {
let substring = hex64.prefix(16) let substring = hex64.prefix(16)
let peerID = PeerID(str: substring) let peerID = PeerID(str: substring)
XCTAssertEqual(peerID.id, String(substring)) #expect(peerID.id == String(substring))
XCTAssertEqual(peerID.bare, String(substring)) #expect(peerID.bare == String(substring))
XCTAssertEqual(peerID.prefix, .empty) #expect(peerID.prefix == .empty)
} }
// MARK: - init(nostr_ pubKey:) // MARK: - init(nostr_ pubKey:)
func test_init_nostrUnderscore_pubKey() { @Test func nostrUnderscore_pubKey() {
let pubKey = hex64 let pubKey = hex64
let peerID = PeerID(nostr_: pubKey) let peerID = PeerID(nostr_: pubKey)
XCTAssertEqual(peerID.id, "nostr_\(pubKey.prefix(TransportConfig.nostrConvKeyPrefixLength))") #expect(peerID.id == "nostr_\(pubKey.prefix(TransportConfig.nostrConvKeyPrefixLength))")
XCTAssertEqual(peerID.bare, String(pubKey.prefix(TransportConfig.nostrConvKeyPrefixLength))) #expect(peerID.bare == String(pubKey.prefix(TransportConfig.nostrConvKeyPrefixLength)))
XCTAssertEqual(peerID.prefix, .geoDM) #expect(peerID.prefix == .geoDM)
} }
// MARK: - init(nostr pubKey:) // MARK: - init(nostr pubKey:)
func test_init_nostr_pubKey() { @Test func nostr_pubKey() {
let pubKey = hex64 let pubKey = hex64
let peerID = PeerID(nostr: pubKey) let peerID = PeerID(nostr: pubKey)
XCTAssertEqual(peerID.id, "nostr:\(pubKey.prefix(TransportConfig.nostrShortKeyDisplayLength))") #expect(peerID.id == "nostr:\(pubKey.prefix(TransportConfig.nostrShortKeyDisplayLength))")
XCTAssertEqual(peerID.bare, String(pubKey.prefix(TransportConfig.nostrShortKeyDisplayLength))) #expect(peerID.bare == String(pubKey.prefix(TransportConfig.nostrShortKeyDisplayLength)))
XCTAssertEqual(peerID.prefix, .geoChat) #expect(peerID.prefix == .geoChat)
} }
// MARK: - init(publicKey:) // MARK: - init(publicKey:)
func test_init_publicKey_derivesFingerprint() { @Test func publicKey_derivesFingerprint() {
let publicKey = Data(hex64.utf8) let publicKey = Data(hex64.utf8)
let expected = publicKey.sha256Fingerprint().prefix(16) let expected = publicKey.sha256Fingerprint().prefix(16)
let peerID = PeerID(publicKey: publicKey) let peerID = PeerID(publicKey: publicKey)
XCTAssertEqual(peerID.bare, String(expected)) #expect(peerID.bare == String(expected))
XCTAssertEqual(peerID.prefix, .empty) #expect(peerID.prefix == .empty)
} }
// MARK: - toShort() // MARK: - toShort()
func test_toShort_whenNoiseKeyExists() { @Test func toShort_whenNoiseKeyExists() {
let peerID = PeerID(str: hex64) let peerID = PeerID(str: hex64)
let short = peerID.toShort() let short = peerID.toShort()
// `toShort()` should derive 16-hex peerID
let expected = Data(hexString: hex64)!.sha256Fingerprint().prefix(16) let expected = Data(hexString: hex64)!.sha256Fingerprint().prefix(16)
#expect(short.bare == String(expected))
XCTAssertEqual(short.bare, String(expected)) #expect(short.prefix == .empty)
XCTAssertEqual(short.prefix, .empty)
} }
func test_toShort_whenNoiseKeyExists_withNoisePrefix() { @Test func toShort_whenNoiseKeyExists_withNoisePrefix() {
let peerID = PeerID(str: "noise:" + hex64) let peerID = PeerID(str: "noise:" + hex64)
let short = peerID.toShort() let short = peerID.toShort()
// `toShort()` should derive 16-hex peerID
let expected = Data(hexString: hex64)!.sha256Fingerprint().prefix(16) let expected = Data(hexString: hex64)!.sha256Fingerprint().prefix(16)
#expect(short.bare == String(expected))
XCTAssertEqual(short.bare, String(expected)) #expect(short.prefix == .empty)
XCTAssertEqual(short.prefix, .empty) #expect(peerID.prefix == .noise)
XCTAssertEqual(peerID.prefix, .noise)
} }
func test_toShort_whenNoNoiseKey() { @Test func toShort_whenNoNoiseKey() {
let peerID = PeerID(str: "some_random_key") let peerID = PeerID(str: "some_random_key")
let short = peerID.toShort() let short = peerID.toShort()
XCTAssertEqual(short, peerID) // unchanged #expect(short == peerID)
}
@Test func routingData_fromShortID() throws {
let peerID = PeerID(str: hex16)
let routing = try #require(peerID.routingData)
#expect(routing.count == 8)
#expect(routing == Data(hexString: hex16))
}
@Test func routingData_fromNoiseKey() throws {
let peerID = PeerID(str: hex64)
let routing = try #require(peerID.routingData)
let expectedShort = peerID.toShort()
#expect(routing == Data(hexString: expectedShort.id))
}
@Test func routingPeerRoundTrip() throws {
let raw = try #require(Data(hexString: hex16))
let peerID = try #require(PeerID(routingData: raw))
#expect(peerID.routingData == raw)
} }
// MARK: - Codable // MARK: - Codable
func test_codable_emptyPrefix() throws { @Test func codable_emptyPrefix() throws {
struct Dummy: Codable, Equatable { struct Dummy: Codable, Equatable {
let name: String let name: String
let peerID: PeerID let peerID: PeerID
@@ -237,13 +250,13 @@ final class PeerIDTests: XCTestCase {
let jsonString = "{\"name\":\"some name\",\"peerID\":\"\(str)\"}" let jsonString = "{\"name\":\"some name\",\"peerID\":\"\(str)\"}"
let decoded = try JSONDecoder().decode(Dummy.self, from: Data(jsonString.utf8)) let decoded = try JSONDecoder().decode(Dummy.self, from: Data(jsonString.utf8))
XCTAssertEqual(decoded.peerID, PeerID(str: str)) #expect(decoded.peerID == PeerID(str: str))
let encoded = try encoder.encode(decoded) let encoded = try encoder.encode(decoded)
XCTAssertEqual(String(data: encoded, encoding: .utf8), jsonString) #expect(String(data: encoded, encoding: .utf8) == jsonString)
} }
func test_codable_withPrefix() throws { @Test func codable_withPrefix() throws {
struct Dummy: Codable, Equatable { struct Dummy: Codable, Equatable {
let peerID: PeerID let peerID: PeerID
} }
@@ -252,193 +265,165 @@ final class PeerIDTests: XCTestCase {
let jsonString = "{\"peerID\":\"\(str)\"}" let jsonString = "{\"peerID\":\"\(str)\"}"
let decoded = try JSONDecoder().decode(Dummy.self, from: Data(jsonString.utf8)) let decoded = try JSONDecoder().decode(Dummy.self, from: Data(jsonString.utf8))
XCTAssertEqual(decoded.peerID, PeerID(str: str)) #expect(decoded.peerID == PeerID(str: str))
XCTAssertEqual(decoded.peerID.bare, hex16) #expect(decoded.peerID.bare == hex16)
XCTAssertEqual(decoded.peerID.prefix, .geoDM) #expect(decoded.peerID.prefix == .geoDM)
let encoded = try encoder.encode(decoded) let encoded = try encoder.encode(decoded)
XCTAssertEqual(String(data: encoded, encoding: .utf8), jsonString) #expect(String(data: encoded, encoding: .utf8) == jsonString)
} }
func test_codable_multiplePrefixes() throws { @Test func codable_multiplePrefixes() throws {
// Loop across all Prefix cases (except .empty since already tested) // Loop across all Prefix cases (except .empty since already tested)
for prefix in PeerID.Prefix.allCases where prefix != .empty { for prefix in PeerID.Prefix.allCases where prefix != .empty {
let bare = hex16 let bare = hex16
let str = prefix.rawValue + bare let str = prefix.rawValue + bare
let decoded = try JSONDecoder().decode(PeerID.self, from: Data("\"\(str)\"".utf8)) let decoded = try JSONDecoder().decode(PeerID.self, from: Data("\"\(str)\"".utf8))
XCTAssertEqual(decoded.prefix, prefix) #expect(decoded.prefix == prefix)
XCTAssertEqual(decoded.bare, bare) #expect(decoded.bare == bare)
let encoded = try encoder.encode(decoded) let encoded = try encoder.encode(decoded)
XCTAssertEqual(String(data: encoded, encoding: .utf8), "\"\(str)\"") #expect(String(data: encoded, encoding: .utf8) == "\"\(str)\"")
} }
} }
// MARK: - Comparable // MARK: - Comparable
func test_comparable_sorting_and_equality() { @Test func comparable_sorting_and_equality() {
let p1 = PeerID(str: "aaa") let p1 = PeerID(str: "aaa")
let p2 = PeerID(str: "bbb") let p2 = PeerID(str: "bbb")
let p3 = PeerID(str: "bbb") let p3 = PeerID(str: "BBB")
XCTAssertTrue(p1 < p2) #expect(p1 < p2)
XCTAssertFalse(p2 < p1) #expect(p2 >= p1)
XCTAssertEqual(p2, p3) #expect(p2 == p3)
let sorted = [p2, p1].sorted() let sorted = [p2, p1].sorted()
XCTAssertEqual(sorted, [p1, p2]) #expect(sorted == [p1, p2])
} }
func test_equality() { @Test func equality() {
let string = "aaa" let peerID = PeerID(str: "aaa")
let peerID = PeerID(str: string)
let badString = "bbb"
// PeerID == String // Regular PeerID <> PeerID
XCTAssertTrue(peerID == string) #expect(peerID == PeerID(str: "AAA"))
XCTAssertTrue(peerID == Optional(string)) #expect(peerID == Optional(PeerID(str: "AAA")))
XCTAssertTrue(Optional(peerID) == string) #expect(PeerID(str: "AAA") == peerID)
XCTAssertTrue(Optional(peerID) == Optional(string)) #expect(Optional(PeerID(str: "AAA")) == Optional(peerID))
// PeerID != String
XCTAssertTrue(peerID != badString)
XCTAssertTrue(peerID != Optional(badString))
XCTAssertTrue(Optional(peerID) != badString)
XCTAssertTrue(Optional(peerID) != Optional(badString))
// String == PeerID #expect(peerID != PeerID(str: "BBB"))
XCTAssertTrue(string == peerID) #expect(peerID != Optional(PeerID(str: "BBB")))
XCTAssertTrue(Optional(string) == peerID) #expect(PeerID(str: "BBB") != peerID)
XCTAssertTrue(string == Optional(peerID)) #expect(Optional(PeerID(str: "BBB")) != Optional(peerID))
XCTAssertTrue(Optional(string) == Optional(peerID))
// String != PeerID
XCTAssertTrue(badString != peerID)
XCTAssertTrue(Optional(badString) != peerID)
XCTAssertTrue(badString != Optional(peerID))
XCTAssertTrue(Optional(badString) != Optional(peerID))
// Make sure the regular PeerID <> PeerID is not broken
XCTAssertTrue(peerID == PeerID(str: "aaa"))
XCTAssertTrue(peerID == Optional(PeerID(str: "aaa")))
XCTAssertTrue(PeerID(str: "aaa") == peerID)
XCTAssertTrue(Optional(PeerID(str: "aaa")) == Optional(peerID))
XCTAssertTrue(peerID != PeerID(str: "bbb"))
XCTAssertTrue(peerID != Optional(PeerID(str: "bbb")))
XCTAssertTrue(PeerID(str: "bbb") != peerID)
XCTAssertTrue(Optional(PeerID(str: "bbb")) != Optional(peerID))
} }
// MARK: - Computed properties // MARK: - Computed properties
func test_isEmpty_true_and_false() { @Test func isEmpty_true_and_false() {
XCTAssertTrue(PeerID(str: "").isEmpty) #expect(PeerID(str: "").isEmpty)
XCTAssertFalse(PeerID(str: "abc").isEmpty) #expect(!PeerID(str: "abc").isEmpty)
} }
func test_isGeoChat() { @Test func isGeoChat() {
XCTAssertTrue(PeerID(str: "nostr:abcdef").isGeoChat) #expect(PeerID(str: "nostr:abcdef").isGeoChat)
XCTAssertFalse(PeerID(str: "nostr_abcdef").isGeoChat) // different prefix #expect(!PeerID(str: "nostr_abcdef").isGeoChat)
} }
func test_isGeoDM() { @Test func isGeoDM() {
XCTAssertTrue(PeerID(str: "nostr_abcdef").isGeoDM) #expect(PeerID(str: "nostr_abcdef").isGeoDM)
XCTAssertFalse(PeerID(str: "nostr:abcdef").isGeoDM) #expect(!PeerID(str: "nostr:abcdef").isGeoDM)
} }
func test_toPercentEncoded() { @Test func toPercentEncoded() {
let peerID = PeerID(str: "name:some value/with spaces?") let peerID = PeerID(str: "name:some value/with spaces?")
let encoded = peerID.toPercentEncoded() let encoded = peerID.toPercentEncoded()
// spaces and ? should be percent-encoded in urlPathAllowed // spaces and ? should be percent-encoded in urlPathAllowed
XCTAssertEqual(encoded, "name%3Asome%20value/with%20spaces%3F") #expect(encoded == "name%3Asome%20value/with%20spaces%3F")
} }
// MARK: - Validation // MARK: - Validation
func test_accepts_short_hex_peer_id() { @Test func accepts_short_hex_peer_id() {
XCTAssertTrue(PeerID(str: "0011223344556677").isValid) #expect(PeerID(str: "0011223344556677").isValid)
XCTAssertTrue(PeerID(str: "aabbccddeeff0011").isValid) #expect(PeerID(str: "aabbccddeeff0011").isValid)
} }
func test_accepts_full_noise_key_hex() { @Test func accepts_full_noise_key_hex() {
let hex64 = String(repeating: "ab", count: 32) // 64 hex chars let hex64 = String(repeating: "ab", count: 32) // 64 hex chars
XCTAssertTrue(PeerID(str: hex64).isValid) #expect(PeerID(str: hex64).isValid)
} }
func test_accepts_internal_alnum_dash_underscore() { @Test func accepts_internal_alnum_dash_underscore() {
XCTAssertTrue(PeerID(str: "peer_123-ABC").isValid) #expect(PeerID(str: "peer_123-ABC").isValid)
XCTAssertTrue(PeerID(str: "nostr_user_01").isValid) #expect(PeerID(str: "nostr_user_01").isValid)
} }
func test_rejects_invalid_characters() { @Test func rejects_invalid_characters() {
XCTAssertFalse(PeerID(str: "peer!@#").isValid) #expect(!PeerID(str: "peer!@#").isValid)
XCTAssertFalse(PeerID(str: "gggggggggggggggg").isValid) // not hex for short form #expect(!PeerID(str: "gggggggggggggggg").isValid) // not hex for short form
} }
func test_rejects_too_long() { @Test func rejects_too_long() {
let tooLong = String(repeating: "a", count: 65) let tooLong = String(repeating: "a", count: 65)
XCTAssertFalse(PeerID(str: tooLong).isValid) #expect(!PeerID(str: tooLong).isValid)
} }
func test_isShort() { @Test func isShort() {
XCTAssertTrue(PeerID(str: hex16).isShort) #expect(PeerID(str: hex16).isShort)
XCTAssertFalse(PeerID(str: "abcd").isShort) // wrong length #expect(!PeerID(str: "abcd").isShort) // wrong length
} }
func test_isNoiseKeyHex_and_noiseKey() { @Test func isNoiseKeyHex_and_noiseKey() {
let hex64 = String(repeating: "ab", count: 32) // 64 chars valid hex let hex64 = String(repeating: "ab", count: 32) // 64 chars valid hex
let peerID = PeerID(str: hex64) let peerID = PeerID(str: hex64)
XCTAssertTrue(peerID.isNoiseKeyHex) #expect(peerID.isNoiseKeyHex)
XCTAssertNotNil(peerID.noiseKey) #expect(peerID.noiseKey != nil)
let prefixedPeerID = PeerID(str: "noise:" + hex64) let prefixedPeerID = PeerID(str: "noise:" + hex64)
XCTAssertTrue(prefixedPeerID.isNoiseKeyHex) #expect(prefixedPeerID.isNoiseKeyHex)
XCTAssertNotNil(prefixedPeerID.noiseKey) #expect(prefixedPeerID.noiseKey != nil)
let bad = String(repeating: "z", count: 64) // invalid hex let bad = String(repeating: "z", count: 64) // invalid hex
let badPeerID = PeerID(str: bad) let badPeerID = PeerID(str: bad)
XCTAssertFalse(badPeerID.isNoiseKeyHex) #expect(!badPeerID.isNoiseKeyHex)
XCTAssertNil(badPeerID.noiseKey) #expect(badPeerID.noiseKey == nil)
} }
func test_prefixes() { @Test func prefixes() {
let hex64 = String(repeating: "a", count: 64) let hex64 = String(repeating: "a", count: 64)
XCTAssertTrue(PeerID(str: "noise:\(hex64)").isValid) #expect(PeerID(str: "noise:\(hex64)").isValid)
XCTAssertTrue(PeerID(str: "nostr:\(hex64)").isValid) #expect(PeerID(str: "nostr:\(hex64)").isValid)
XCTAssertTrue(PeerID(str: "nostr_\(hex64)").isValid) #expect(PeerID(str: "nostr_\(hex64)").isValid)
let hex63 = String(repeating: "a", count: 63) let hex63 = String(repeating: "a", count: 63)
XCTAssertTrue(PeerID(str: "noise:\(hex63)").isValid) #expect(PeerID(str: "noise:\(hex63)").isValid)
XCTAssertTrue(PeerID(str: "nostr:\(hex63)").isValid) #expect(PeerID(str: "nostr:\(hex63)").isValid)
XCTAssertTrue(PeerID(str: "nostr_\(hex63)").isValid) #expect(PeerID(str: "nostr_\(hex63)").isValid)
let hex16 = String(repeating: "a", count: 16) let hex16 = String(repeating: "a", count: 16)
XCTAssertTrue(PeerID(str: "noise:\(hex16)").isValid) #expect(PeerID(str: "noise:\(hex16)").isValid)
XCTAssertTrue(PeerID(str: "nostr:\(hex16)").isValid) #expect(PeerID(str: "nostr:\(hex16)").isValid)
XCTAssertTrue(PeerID(str: "nostr_\(hex16)").isValid) #expect(PeerID(str: "nostr_\(hex16)").isValid)
let hex8 = String(repeating: "a", count: 8) let hex8 = String(repeating: "a", count: 8)
XCTAssertTrue(PeerID(str: "noise:\(hex8)").isValid) #expect(PeerID(str: "noise:\(hex8)").isValid)
XCTAssertTrue(PeerID(str: "nostr:\(hex8)").isValid) #expect(PeerID(str: "nostr:\(hex8)").isValid)
XCTAssertTrue(PeerID(str: "nostr_\(hex8)").isValid) #expect(PeerID(str: "nostr_\(hex8)").isValid)
let mesh = "mesh:abcdefg" let mesh = "mesh:abcdefg"
XCTAssertTrue(PeerID(str: "name:\(mesh)").isValid) #expect(PeerID(str: "name:\(mesh)").isValid)
let name = "name:some_name" let name = "name:some_name"
XCTAssertTrue(PeerID(str: "name:\(name)").isValid) #expect(PeerID(str: "name:\(name)").isValid)
let badName = "name:bad:name" let badName = "name:bad:name"
XCTAssertFalse(PeerID(str: "name:\(badName)").isValid) #expect(!PeerID(str: "name:\(badName)").isValid)
// Too long // Too long
let hex65 = String(repeating: "a", count: 65) let hex65 = String(repeating: "a", count: 65)
XCTAssertFalse(PeerID(str: "noise:\(hex65)").isValid) #expect(!PeerID(str: "noise:\(hex65)").isValid)
XCTAssertFalse(PeerID(str: "nostr:\(hex65)").isValid) #expect(!PeerID(str: "nostr:\(hex65)").isValid)
XCTAssertFalse(PeerID(str: "nostr_\(hex65)").isValid) #expect(!PeerID(str: "nostr_\(hex65)").isValid)
} }
} }
+4
View File
@@ -18,6 +18,10 @@ let package = Package(
.target( .target(
name: "BitLogger", name: "BitLogger",
path: "Sources" path: "Sources"
),
.testTarget(
name: "BitLoggerTests",
dependencies: ["BitLogger"]
) )
] ]
) )
@@ -6,11 +6,13 @@
// For more information, see <https://unlicense.org> // For more information, see <https://unlicense.org>
// //
#if canImport(os.log)
import os.log import os.log
#endif
public extension OSLog { public extension OSLog {
private static let subsystem = "chat.bitchat" private static let subsystem = "chat.bitchat"
static let noise = OSLog(subsystem: subsystem, category: "noise") static let noise = OSLog(subsystem: subsystem, category: "noise")
static let encryption = OSLog(subsystem: subsystem, category: "encryption") static let encryption = OSLog(subsystem: subsystem, category: "encryption")
static let keychain = OSLog(subsystem: subsystem, category: "keychain") static let keychain = OSLog(subsystem: subsystem, category: "keychain")
@@ -7,7 +7,53 @@
// //
import Foundation import Foundation
#if canImport(os.log)
import os.log import os.log
#else
public struct OSLog {
public let subsystem: String
public let category: String
public init(subsystem: String, category: String) {
self.subsystem = subsystem
self.category = category
}
}
public struct OSLogType: CustomStringConvertible {
private let label: String
private init(_ label: String) {
self.label = label
}
public var description: String { label }
public static let debug = OSLogType("debug")
public static let info = OSLogType("info")
public static let `default` = OSLogType("default")
public static let error = OSLogType("error")
public static let fault = OSLogType("fault")
}
@usableFromInline
let secureLoggerFallbackFormatter: ISO8601DateFormatter = {
let formatter = ISO8601DateFormatter()
formatter.formatOptions = [.withInternetDateTime, .withFractionalSeconds]
return formatter
}()
@usableFromInline
func os_log(_ message: StaticString, log: OSLog, type: OSLogType, _ args: CVarArg...) {
let rawFormat = String(describing: message)
let format = rawFormat
.replacingOccurrences(of: "%{public}@", with: "%@")
.replacingOccurrences(of: "%{private}@", with: "%@")
let formatted = String(format: format, arguments: args)
let timestamp = secureLoggerFallbackFormatter.string(from: Date())
print("[\(timestamp)] [\(log.subsystem)::\(log.category)] [\(type.description)] \(formatted)")
}
#endif
/// Centralized security-aware logging framework /// Centralized security-aware logging framework
/// Provides safe logging that filters sensitive data and security events /// Provides safe logging that filters sensitive data and security events
@@ -22,22 +68,6 @@ public final class SecureLogger {
return formatter return formatter
}() }()
// MARK: - Cached Regex Patterns
private static let fingerprintPattern = #/[a-fA-F0-9]{64}/#
private static let base64Pattern = #/[A-Za-z0-9+/]{40,}={0,2}/#
private static let passwordPattern = #/password["\s:=]+["']?[^"'\s]+["']?/#
private static let peerIDPattern = #/peerID: ([a-zA-Z0-9]{8})[a-zA-Z0-9]+/#
// MARK: - Sanitization Cache
private static let sanitizationCache: NSCache<NSString, NSString> = {
let cache = NSCache<NSString, NSString>()
cache.countLimit = 100 // Keep last 100 sanitized strings
return cache
}()
private static let cacheQueue = DispatchQueue(label: "chat.bitchat.securelogger.cache", attributes: .concurrent)
// MARK: - Log Levels // MARK: - Log Levels
enum LogLevel { enum LogLevel {
@@ -115,8 +145,8 @@ public extension SecureLogger {
static func error(_ error: Error, context: @autoclosure () -> String, category: OSLog = .noise, static func error(_ error: Error, context: @autoclosure () -> String, category: OSLog = .noise,
file: String = #file, line: Int = #line, function: String = #function) { file: String = #file, line: Int = #line, function: String = #function) {
let location = formatLocation(file: file, line: line, function: function) let location = formatLocation(file: file, line: line, function: function)
let sanitized = sanitize(context()) let sanitized = context().sanitized()
let errorDesc = sanitize(error.localizedDescription) let errorDesc = error.localizedDescription.sanitized()
#if DEBUG #if DEBUG
os_log("%{public}@ Error in %{public}@: %{public}@", log: category, type: .error, location, sanitized, errorDesc) os_log("%{public}@ Error in %{public}@: %{public}@", log: category, type: .error, location, sanitized, errorDesc)
@@ -140,15 +170,15 @@ public extension SecureLogger {
var message: String { var message: String {
switch self { switch self {
case .handshakeStarted(let peerID): case .handshakeStarted(let peerID):
return "Handshake started with peer: \(sanitize(peerID))" return "Handshake started with peer: \(peerID.sanitized())"
case .handshakeCompleted(let peerID): case .handshakeCompleted(let peerID):
return "Handshake completed with peer: \(sanitize(peerID))" return "Handshake completed with peer: \(peerID.sanitized())"
case .handshakeFailed(let peerID, let error): case .handshakeFailed(let peerID, let error):
return "Handshake failed with peer: \(sanitize(peerID)), error: \(error)" return "Handshake failed with peer: \(peerID.sanitized()), error: \(error)"
case .sessionExpired(let peerID): case .sessionExpired(let peerID):
return "Session expired for peer: \(sanitize(peerID))" return "Session expired for peer: \(peerID.sanitized())"
case .authenticationFailed(let peerID): case .authenticationFailed(let peerID):
return "Authentication failed for peer: \(sanitize(peerID))" return "Authentication failed for peer: \(peerID.sanitized())"
} }
} }
} }
@@ -203,7 +233,7 @@ private extension SecureLogger {
file: String, line: Int, function: String) { file: String, line: Int, function: String) {
guard shouldLog(level) else { return } guard shouldLog(level) else { return }
let location = formatLocation(file: file, line: line, function: function) let location = formatLocation(file: file, line: line, function: function)
let sanitized = sanitize("\(location) \(message())") let sanitized = "\(location) \(message())".sanitized()
#if DEBUG #if DEBUG
os_log("%{public}@", log: category, type: level.osLogType, sanitized) os_log("%{public}@", log: category, type: level.osLogType, sanitized)
@@ -236,58 +266,6 @@ private extension SecureLogger {
let timestamp = timestampFormatter.string(from: Date()) let timestamp = timestampFormatter.string(from: Date())
return "[\(timestamp)] [\(fileName):\(line) \(function)]" return "[\(timestamp)] [\(fileName):\(line) \(function)]"
} }
/// Sanitize strings to remove potentially sensitive data
static func sanitize(_ input: String) -> String {
let key = input as NSString
// Check cache first
var cachedValue: String?
cacheQueue.sync {
cachedValue = sanitizationCache.object(forKey: key) as String?
}
if let cached = cachedValue {
return cached
}
// Perform sanitization
var sanitized = input
// Remove full fingerprints (keep first 8 chars for debugging)
sanitized = sanitized.replacing(fingerprintPattern) { match in
let fingerprint = String(match.output)
return String(fingerprint.prefix(8)) + "..."
}
// Remove base64 encoded data that might be keys
sanitized = sanitized.replacing(base64Pattern) { _ in
"<base64-data>"
}
// Remove potential passwords (assuming they're in quotes or after "password:")
sanitized = sanitized.replacing(passwordPattern) { _ in
"password: <redacted>"
}
// Truncate peer IDs to first 8 characters
sanitized = sanitized.replacing(peerIDPattern) { match in
"peerID: \(match.1)..."
}
// Cache the result
cacheQueue.sync {
sanitizationCache.setObject(sanitized as NSString, forKey: key)
}
return sanitized
}
/// Sanitize individual values
static func sanitize<T>(_ value: T) -> String {
let stringValue = String(describing: value)
return sanitize(stringValue)
}
} }
// MARK: - Migration Helper // MARK: - Migration Helper
@@ -0,0 +1,67 @@
//
// String+Sanitization.swift
// BitLogger
//
// This is free and unencumbered software released into the public domain.
// For more information, see <https://unlicense.org>
//
import Foundation
extension String {
/// Sanitize strings to remove potentially sensitive data
func sanitized() -> String {
let key = self as NSString
// Check cache first
if let cached = Self.queue.sync(execute: { Self.cache.object(forKey: key) }) {
return cached as String
}
var sanitized = self
// Remove full fingerprints (keep first 8 chars for debugging)
let fingerprintPattern = #/[a-fA-F0-9]{64}/#
sanitized = sanitized.replacing(fingerprintPattern) { match in
let fingerprint = String(match.output)
return String(fingerprint.prefix(8)) + "..."
}
// Remove base64 encoded data that might be keys
let base64Pattern = #/[A-Za-z0-9+/]{40,}={0,2}/#
sanitized = sanitized.replacing(base64Pattern) { _ in
"<base64-data>"
}
// Remove potential passwords (assuming they're in quotes or after "password:")
let passwordPattern = #/password["\s:=]+["']?[^"'\s]+["']?/#
sanitized = sanitized.replacing(passwordPattern) { _ in
"password: <redacted>"
}
// Truncate peer IDs to first 8 characters
let peerIDPattern = #/peerID: ([a-zA-Z0-9]{8})[a-zA-Z0-9]+/#
sanitized = sanitized.replacing(peerIDPattern) { match in
"peerID: \(match.1)..."
}
// Cache the result
Self.queue.sync {
Self.cache.setObject(sanitized as NSString, forKey: key)
}
return sanitized
}
}
// MARK: - Cache Helpers
private extension String {
static let queue = DispatchQueue(label: "chat.bitchat.securelogger.cache", attributes: .concurrent)
static let cache: NSCache<NSString, NSString> = {
let cache = NSCache<NSString, NSString>()
cache.countLimit = 100 // Keep last 100 sanitized strings
return cache
}()
}
@@ -0,0 +1,143 @@
//
// StringSanitizationTests.swift
// BitLogger
//
// Created by Islam on 19/10/2025.
//
import Testing
@testable import BitLogger
struct StringSanitizationTests {
@Test("64-hex fingerprint is truncated to first 8 chars followed by ellipsis")
func fingerprintTruncation() async throws {
let fingerprint = "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef"
#expect(fingerprint.count == 64)
let input = "fingerprint=\(fingerprint)"
let output = input.sanitized()
#expect(output.contains("fingerprint=01234567..."))
// Ensure no full fingerprint remains
#expect(output.contains(fingerprint) == false)
}
@Test("Multiple fingerprints in a string are all truncated")
func multipleFingerprintTruncation() async throws {
let fp1 = String(repeating: "a", count: 64)
let fp2 = String(repeating: "b", count: 64)
let input = "fp1=\(fp1) fp2=\(fp2)"
let output = input.sanitized()
#expect(output.contains("fp1=aaaaaaaa..."))
#expect(output.contains("fp2=bbbbbbbb..."))
#expect(output.contains(fp1) == false)
#expect(output.contains(fp2) == false)
}
@Test("Base64-like long data is replaced with <base64-data>")
func base64Replacement() async throws {
// 44+ chars of base64 characters
let base64ish = "QUJDREVGR0hJSktMTU5PUFFSU1RVVldYWVo5ODc2NTQzMjE="
let input = "payload=\(base64ish)"
let output = input.sanitized()
#expect(output == "payload=<base64-data>")
}
@Test("Base64-like without padding is replaced with <base64-data>")
func base64NoPaddingReplacement() async throws {
let base64ish = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
#expect(base64ish.count >= 40)
let input = "b64:\(base64ish)"
let output = input.sanitized()
#expect(output == "b64:<base64-data>")
}
@Test("Short base64-like strings (below threshold) are not replaced")
func shortBase64NotReplaced() async throws {
let short = "QUJDREVGR0hJSktMTU5P" // < 40 chars
let input = "payload=\(short)"
let output = input.sanitized()
#expect(output == input)
}
@Test("Password redaction for key:value formats", arguments: [
"password: secret123",
"password=secret123",
"password = secret123",
"password: 'secret123'",
"password:\"secret123\"",
"password='secret123'"
])
func passwordRedactionKeyValue(password: String) async throws {
#expect(password.sanitized() == "password: <redacted>")
}
@Test("Password redaction inside wider messages")
func passwordRedactionInContext() async throws {
let input = "user=john password: 'p@ssW0rd' attempt=1"
let output = input.sanitized()
#expect(output == "user=john password: <redacted> attempt=1")
}
@Test("PeerID is truncated to first 8 chars followed by ellipsis")
func peerIDTruncation() async throws {
let peer = "ABCDEF12GHIJKL34"
let input = "peerID: \(peer)"
let output = input.sanitized()
#expect(output == "peerID: ABCDEF12...")
}
@Test("PeerID not truncated when exactly 8 chars")
func peerIDExactlyEightNotTruncated() async throws {
let peer = "ABCDEF12"
let input = "peerID: \(peer)"
let output = input.sanitized()
// Pattern only matches when there are more than 8 trailing chars, so unchanged
#expect(output == input)
}
@Test("Non-matching content remains unchanged")
func nonMatchingUnchanged() async throws {
let input = "Hello world 123 - nothing sensitive here."
let output = input.sanitized()
#expect(output == input)
}
@Test("Idempotency: sanitizing twice yields same result")
func idempotentSanitization() async throws {
let input = """
fingerprint=0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef \
password: "superSecret" \
peerID: ZYXWVUT987654321 \
payload=ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
"""
let once = input.sanitized()
let twice = once.sanitized()
#expect(once == twice)
}
@Test("Mixed content: all rules apply in a single string")
func mixedContent() async throws {
let fingerprint = "fedcba9876543210fedcba9876543210fedcba9876543210fedcba9876543210"
let base64ish = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"
let peer = "PEERID01EXTRA"
let input = "fp=\(fingerprint) password='x' peerID: \(peer) data=\(base64ish)"
let output = input.sanitized()
#expect(output.contains("fp=fedcba98..."))
#expect(output.contains("password: <redacted>"))
#expect(output.contains("peerID: PEERID01..."))
#expect(output.contains("data=<base64-data>"))
#expect(output.contains(fingerprint) == false)
#expect(output.contains(base64ish) == false)
}
@Test("Cache returns consistent result for repeated inputs")
func cacheHitConsistency() async throws {
let input = "password: hunter2"
let first = input.sanitized()
let second = input.sanitized()
#expect(first == "password: <redacted>")
#expect(first == second)
}
}
+15 -151
View File
@@ -1,11 +1,23 @@
import BitLogger import BitLogger
import Foundation import Foundation
#if canImport(Network)
import Network import Network
#endif
#if canImport(Darwin)
import Darwin import Darwin
#elseif canImport(Glibc)
import Glibc
#endif
// Declare C entrypoint for Tor when statically linked from an xcframework. #if !canImport(Network)
@_silgen_name("tor_main") private final class NWPathMonitor {
private func tor_main_c(_ argc: Int32, _ argv: UnsafeMutablePointer<UnsafeMutablePointer<CChar>?>?) -> Int32 var pathUpdateHandler: ((Any) -> Void)?
func start(queue: DispatchQueue) {
// Path monitoring is unavailable on this platform; nothing to do.
}
}
#endif
// Preferred: tiny C glue that uses Tor's embedding API (tor_api.h) // Preferred: tiny C glue that uses Tor's embedding API (tor_api.h)
@_silgen_name("tor_host_start") @_silgen_name("tor_host_start")
@@ -286,150 +298,6 @@ public final class TorManager: ObservableObject {
} }
} }
// MARK: - Dynamic loader path (no Swift module required)
/// Attempt to locate an embedded tor framework binary and launch Tor via `tor_run_main`.
/// Returns true if the attempt started and port probing was scheduled.
private func startTorViaDlopen() -> Bool {
guard let fwURL = frameworkBinaryURL() else {
SecureLogger.warning("TorManager: no embedded tor framework found", category: .session)
return false
}
// Load the library
let mode = RTLD_NOW | RTLD_LOCAL
SecureLogger.info("TorManager: dlopen(\(fwURL.lastPathComponent))…", category: .session)
guard let handle = dlopen(fwURL.path, mode) else {
let err = String(cString: dlerror())
self.lastError = NSError(domain: "TorManager", code: -10, userInfo: [NSLocalizedDescriptionKey: "dlopen failed: \(err)"])
self.isStarting = false
return false
}
// Resolve tor_main(argc, argv)
typealias TorMainType = @convention(c) (Int32, UnsafeMutablePointer<UnsafeMutablePointer<CChar>?>?) -> Int32
guard let sym = dlsym(handle, "tor_main") else {
// Keep handle open but report error
let err = String(cString: dlerror())
self.lastError = NSError(domain: "TorManager", code: -11, userInfo: [NSLocalizedDescriptionKey: "dlsym tor_main failed: \(err)"])
self.isStarting = false
return false
}
let torMain = unsafeBitCast(sym, to: TorMainType.self)
self._dlHandle = handle
// Prepare args: tor -f <torrc>
var argv: [String] = ["tor"]
if let torrc = torrcURL()?.path {
argv.append(contentsOf: ["-f", torrc])
}
// Run Tor on a background thread to avoid blocking the main actor
SecureLogger.info("TorManager: launching tor_main with torrc", category: .session)
let argc = Int32(argv.count)
DispatchQueue.global(qos: .utility).async {
// Build stable C argv in this thread
let cStrings: [UnsafeMutablePointer<CChar>?] = argv.map { strdup($0) }
let cArgv = UnsafeMutablePointer<UnsafeMutablePointer<CChar>?>.allocate(capacity: cStrings.count + 1)
for i in 0..<cStrings.count { cArgv[i] = cStrings[i] }
cArgv[cStrings.count] = nil
_ = torMain(argc, cArgv)
// Free args after exit (Tor usually never returns)
for ptr in cStrings.compactMap({ $0 }) { free(ptr) }
cArgv.deallocate()
}
// Start control-port monitor and probe readiness asynchronously
startControlMonitorIfNeeded()
Task.detached(priority: .userInitiated) { [weak self] in
guard let self else { return }
let ready = await self.waitForSocksReady(timeout: 60.0)
await MainActor.run {
self.socksReady = ready
if !ready {
self.lastError = NSError(domain: "TorManager", code: -12, userInfo: [NSLocalizedDescriptionKey: "Tor SOCKS not reachable after dlopen start"])
SecureLogger.error("TorManager: SOCKS not reachable (timeout)", category: .session)
} else {
SecureLogger.info("TorManager: SOCKS ready at \(self.socksHost):\(self.socksPort)", category: .session)
}
// isStarting will be cleared when bootstrap reaches 100%
}
}
return true
}
private var _dlHandle: UnsafeMutableRawPointer?
private func frameworkBinaryURL() -> URL? {
// Try common embedded locations for the framework binary name
let candidates = [
"tor-nolzma.framework/tor-nolzma",
"Tor.framework/Tor",
]
if let base = Bundle.main.privateFrameworksURL {
for rel in candidates {
let url = base.appendingPathComponent(rel)
if FileManager.default.fileExists(atPath: url.path) { return url }
}
}
// For macOS apps, also try Contents/Frameworks explicitly
#if os(macOS)
if let appURL = Bundle.main.bundleURL as URL?,
let frameworksURL = Optional(appURL.appendingPathComponent("Contents/Frameworks", isDirectory: true)) {
for rel in candidates {
let url = frameworksURL.appendingPathComponent(rel)
if FileManager.default.fileExists(atPath: url.path) { return url }
}
}
#endif
return nil
}
// MARK: - Static-link path (no module import)
private func startTorViaLinkedSymbol() -> Bool {
// Attempt to start tor_run_main directly (statically linked). If the
// symbol is not present at link-time, builds will fail which is
// expected when the xcframework is absent.
var argv: [String] = ["tor"]
if let torrc = torrcURL()?.path { argv.append(contentsOf: ["-f", torrc]) }
SecureLogger.info("TorManager: starting tor_main (static)", category: .session)
let argc = Int32(argv.count)
DispatchQueue.global(qos: .utility).async {
// Build stable C argv in this thread
let cStrings: [UnsafeMutablePointer<CChar>?] = argv.map { strdup($0) }
let cArgv = UnsafeMutablePointer<UnsafeMutablePointer<CChar>?>.allocate(capacity: cStrings.count + 1)
for i in 0..<cStrings.count { cArgv[i] = cStrings[i] }
cArgv[cStrings.count] = nil
_ = tor_main_c(argc, cArgv)
// If tor_main ever returns, free memory
for ptr in cStrings.compactMap({ $0 }) { free(ptr) }
cArgv.deallocate()
}
// Start control monitor early
startControlMonitorIfNeeded()
Task.detached(priority: .userInitiated) { [weak self] in
guard let self else { return }
let ready = await self.waitForSocksReady(timeout: 60.0)
await MainActor.run {
self.socksReady = ready
if ready {
SecureLogger.info("TorManager: SOCKS ready at \(self.socksHost):\(self.socksPort)", category: .session)
} else {
self.lastError = NSError(domain: "TorManager", code: -13, userInfo: [NSLocalizedDescriptionKey: "Tor SOCKS not reachable after static start"])
SecureLogger.error("TorManager: SOCKS not reachable (timeout)", category: .session)
}
// isStarting will be cleared when bootstrap reaches 100%
}
}
return true
}
// MARK: - ControlPort monitoring (bootstrap progress) // MARK: - ControlPort monitoring (bootstrap progress)
private func startControlMonitorIfNeeded() { private func startControlMonitorIfNeeded() {
guard !controlMonitorStarted else { return } guard !controlMonitorStarted else { return }
@@ -440,10 +308,6 @@ public final class TorManager: ObservableObject {
} }
} }
private func controlMonitorLoop() async {}
private func tryControlSessionOnce() async -> Bool { false }
// iOS: Poll GETINFO periodically to track bootstrap progress without long-lived control readers. // iOS: Poll GETINFO periodically to track bootstrap progress without long-lived control readers.
private func bootstrapPollLoop() async { private func bootstrapPollLoop() async {
let deadline = Date().addingTimeInterval(75) let deadline = Date().addingTimeInterval(75)