mirror of
https://github.com/open-jarvis/OpenJarvis.git
synced 2026-07-28 14:07:55 +00:00
Follow-up on @tomaioo's signature-verification panic fix in PR #235. 1. Clippy on Rust 1.95+ flags `len() % 2 != 0` with the `manual_is_multiple_of` lint, which was failing the `rust` CI job on PR #235 and blocking merge. Switch to `is_multiple_of(2)`. 2. Add an explicit `is_ascii()` guard before slicing. With only the length check, a non-ASCII input (e.g. `"é"` — 2 bytes but 1 char) would survive the length check before `from_str_radix` caught it. The explicit guard makes the rejection intent clear and avoids relying on the post-slice error path. 3. Extract the hex-parsing into a private `parse_public_key_hex` helper. PyO3-bound `#[pymethods]` are awkward to unit-test from Rust (need a Python interpreter via `prepare_freethreaded_python`); a plain function is testable with no GIL boilerplate. 4. Add 5 unit tests covering the security boundary: - empty input -> Some(empty vec) - valid hex decodes to the right bytes - odd-length rejected without panic (the original bug) - non-hex chars rejected (previously silently filtered) - multi-byte UTF-8 rejected without panic Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>