Fail closed on corrupt peer records before content authentication

This commit is contained in:
archipelago
2026-10-06 06:40:59 -04:00
parent b8e512fed6
commit 1971aeb3e3
2 changed files with 4 additions and 2 deletions
+2 -1
View File
@@ -235,7 +235,8 @@ mod tests {
.unwrap_err(); .unwrap_err();
// The corrupt identity store fails before the separate missing-FIPS // The corrupt identity store fails before the separate missing-FIPS
// route error. It reaches the payment caller's existing refund branch. // route error. It reaches the payment caller's existing refund branch.
assert!(!error.to_string().contains("FIPS")); assert!(error.to_string().contains("Invalid federation nodes"));
assert_eq!(tokio::fs::read(dir.path().join("federation/nodes.json")).await.unwrap(), b"invalid");
assert!(!dir.path().join("identity").exists()); assert!(!dir.path().join("identity").exists());
} }
+2 -1
View File
@@ -84,7 +84,8 @@ async fn load_nodes_inner(data_dir: &Path) -> Result<Vec<FederatedNode>> {
let content = fs::read_to_string(&path) let content = fs::read_to_string(&path)
.await .await
.context("Failed to read federation nodes")?; .context("Failed to read federation nodes")?;
let file: NodesFile = serde_json::from_str(&content).unwrap_or_default(); let file: NodesFile = serde_json::from_str(&content)
.context("Invalid federation nodes; existing peer records were preserved")?;
Ok(dedup_nodes_by_onion(file.nodes)) Ok(dedup_nodes_by_onion(file.nodes))
} }