Skip to content

fix(hmac): snapshot signatures before async verification - #423

Open
mnkj0021 wants to merge 1 commit into
google:masterfrom
mnkj0021:fix/421-hmac-signature-snapshot
Open

mnkj0021 wants to merge 1 commit into
google:masterfrom
mnkj0021:fix/421-hmac-signature-snapshot

Conversation

@mnkj0021

Copy link
Copy Markdown

Fixes #421

Summary

  • snapshot the caller-owned HMAC signature before asynchronous stream processing in the native backend
  • apply the same call-time snapshot to the JavaScript verifyStream path so stream verification has consistent mutation semantics across backends
  • keep the existing constant-time native comparison unchanged
  • add regressions for both mutation directions through verifyStream and for the reported verifyBytes case

#422 appears to be a duplicate report of the same bug; this change covers the same behavior without opening a second implementation.

Validation

  • dart format --output none --set-exit-if-changed on all changed Dart files
  • dart analyze --fatal-warnings on all changed Dart files — no issues
  • native VM focused regression run: 3/3 HMAC signature-snapshot tests passed
  • git diff --check
  • branch is current with upstream master

The focused native test was run in the official Dart container with CMake/native build dependencies installed so the package build hook compiled the FFI asset.

AI assistance was used while preparing the change; I reviewed the implementation and test behavior.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: native HMAC verification reads a mutated signature after verification starts

1 participant