trackslash
VAULT-85 P2

Test unlocking with real passwords, erasing and launch recovery

0
Sub-issue of VAULT-83 P2 Test that lock, unlock, encryption and restore work end to end

Description

Part of VAULT-83.

Why

The core is well covered:

  • VaultUnlockServiceTests (44 tests): real, duress and wrong passwords do the same work in the same time; NFC; recency; counting.
  • AppLockPasswordAttemptCounterTests (31 tests): the waits, and the threshold of 10.
  • VaultEraserTests: a failure or crash injected at every step.
  • EncryptedVaultPasswordServiceTests: set, wrong, right, duress, change, off and on, and erase on the tenth.

The gaps are in the code around the core.

Tests to add

  • No device passcode with an App Lock Password set:
    • Device authentication fails with .passcodeNotSet (mapped to .unavailable) before the password step.
    • Pin the VAULT-61 behaviour ("Passcode Required", never let through) for a vault that has a password. The password field isn't offered.
    • Adding a passcode back makes the vault open with its password again.
    • Snapshot the screen if there isn't one yet.
  • Erasing after 10 failed passwords: VaultDataModel.resetAfterErase() and VaultRoot.eraseVault() have no tests. eraseVault() runs the service's erase, then the reset, then reloads the fresh store. After it:
    • no items and no tags;
    • no backup password;
    • plain mode;
    • a new vault works normally.
  • Launch recovery:
    • Each result of VaultStorageRecovery.recoverAtLaunch() leads to the right screen through vaultStoreLoadFailureReason: a missing vault, an interrupted erase, and so on.
    • setup() finishes an interrupted erase.
    • VaultEraserTests already covers the eraser itself. These tests cover how it's wired in.
  • The wait between attempts, on screen: with an injected clock, AppLockView's countdown turns entry back on once passwordRetryAt passes. Today there are only static snapshots.
  • Switching vaults: after a duress vault has been opened, lock, then unlock with the real password. The real vault opens, and nothing from the duress vault is left in VaultDataModel, search or open detail state. The same holds the other way round.
  • Production Argon2 parameters: one test sets a password, unlocks with it and fails with a wrong one, all with the real parameters (64 MiB, calibrated t) instead of the cheap test ones. Keep it to one test and run nothing else in parallel with it.
  • Missing from the design doc's "Test strategy": Argon2 cancellation, and a memory high-water check.
  • Real LocalAuthentication: it can't run in unit tests. Note where it's checked (a device checklist in the PR or RELEASE.md), and check that DeviceAuthenticationServiceTests covers every LAError code the service maps.

Done when

Each bullet has a test, or a note explains where it's checked instead.

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1
Bradley

Done in https://github.com/badbundle/vault-app/pull/684, merged as 1120832e. The tests found no bugs.

Two things aren't called directly in unit tests. For each, the steps it runs are tested:

  • VaultRoot.eraseVault(): calling it would erase the simulator's App Group container, which the real app shares.
  • the setup() line that finishes an interrupted erase.

Argon2 is a single synchronous call into the reference C, so it can't be cancelled part way. Cancelling the unlock that runs it is tested, and the design doc now says so.

Face ID and the passcode can't run in tests, so RELEASE.md has a device checklist for them.