mirror of
https://github.com/permissionlesstech/bitchat.git
synced 2026-07-26 01:05:20 +00:00
CRITICAL BUG FIX - Infinite Render Loop:
Root Cause: Duplicate view identity in ContentView.swift:368
ForEach(messageItems) { item in // Already uses item.id via Identifiable
messageRow(...)
.id(item.id) // ❌ REDUNDANT modifier caused identity re-evaluation loop
}
When @Published properties updated, SwiftUI re-evaluated .id() → appeared as
'new' identity → triggered re-render → infinite loop. Caused UI freezes,
keyboard failures, and 100% CPU usage.
Fix: Remove redundant .id() modifier - ForEach already has stable identity.
PERFORMANCE FIXES:
1. Waveform Cache Deadlock (Waveform.swift)
- Removed nested queue.async(barrier) on cache hits
- Was causing task saturation and potential deadlocks
2. Async Send Pattern (ContentView.swift)
- Clear input immediately, defer actual send to next runloop
- Prevents blocking current event handler
3. Proper Swift Concurrency (VoiceNoteView.swift)
- Switch from .onAppear + DispatchQueue to .task
- Cleaner async/await pattern for loading
4. Remove Redundant objectWillChange (ChatViewModel.swift)
- @Published already triggers updates automatically
- Explicit send() was causing double update cycles
SECURITY FIXES (C1-C5, H1-H2):
C1. Path Traversal Protection (BLEService.swift)
- Unicode normalization, null byte removal
- Replace ALL path separators, reject dotfiles
- Validate paths don't escape directory
C2. Integer Overflow (BitchatFilePacket.swift)
- Use UInt64 for TLV parsing, safe Int conversion
C3. MIME Validation (BLEService.swift)
- Whitelist: JPEG, PNG, GIF, WebP, M4A, MP3, WAV, OGG, PDF
- Magic byte validation for all types
- Lenient on M4A (platform variations)
C4. Compression Bomb (BinaryProtocol.swift)
- Ratio validation <= 50,000:1
- Defense-in-depth with 1MB size cap
C5. TOCTOU Race (ChatViewModel.swift)
- Direct removeItem without fileExists check
H1. File Size Validation (ChatViewModel, ImageUtils)
- Check attributes BEFORE Data(contentsOf:)
- Prevents memory exhaustion
H2. Metadata Stripping (ImageUtils.swift)
- Remove ALL metadata keys from JPEG encoding
- Only compression quality set
- Protects GPS/EXIF/device info privacy
RESULT:
✅ No render loops
✅ Works with Xcode debugger
✅ Voice notes display properly
✅ All security vulnerabilities fixed
✅ 164 tests passing
Production ready.