项目文件夹

文件
wehub-resource-sync 9740bc64c9
Bench Regression Guard / bench compile-verify (--no-run) (push) Failing after 0s
Continuous Deployment / Pre-deployment Checks (push) Has been skipped
Bench Regression Guard / bench fast-run (informational, non-gating) (push) Has been skipped
Firmware CI / Verify version.txt matches release tag (push) Has been skipped
Dashboard a11y + cross-browser / a11y (push) Failing after 0s
nvsim Dashboard → GitHub Pages / build-and-deploy (push) Failing after 2s
Firmware CI / Build firmware (esp32s3 / 4mb) (push) Failing after 15s
Firmware CI / Build firmware (esp32c6 / c6-4mb) (push) Failing after 15s
Firmware QEMU Tests (ADR-061) / Build Espressif QEMU (push) Failing after 1s
Firmware QEMU Tests (ADR-061) / Fuzz Testing (ADR-061 Layer 6) (push) Failing after 1s
Firmware QEMU Tests (ADR-061) / QEMU Test (boundary-max) (push) Has been skipped
Firmware CI / Build firmware (esp32s3 / 8mb) (push) Failing after 15s
Firmware QEMU Tests (ADR-061) / QEMU Test (boundary-min) (push) Has been skipped
Firmware QEMU Tests (ADR-061) / QEMU Test (default) (push) Has been skipped
Firmware QEMU Tests (ADR-061) / QEMU Test (edge-tier0) (push) Has been skipped
Firmware QEMU Tests (ADR-061) / QEMU Test (edge-tier1) (push) Has been skipped
Firmware QEMU Tests (ADR-061) / QEMU Test (full-adr060) (push) Has been skipped
Firmware QEMU Tests (ADR-061) / QEMU Test (tdm-3node) (push) Has been skipped
Firmware QEMU Tests (ADR-061) / Swarm Test (ADR-062) (push) Has been skipped
Firmware QEMU Tests (ADR-061) / NVS Matrix Generation (push) Failing after 1s
Fix-Marker Regression Guard / Verify fix markers (push) Failing after 1s
ADR-115 MQTT integration tests / mqtt-integration (push) Failing after 1s
npm packages / harness/ruview (node 20) (push) Failing after 1s
npm packages / tools/ruview-mcp (node 20) (push) Failing after 1s
npm packages / tools/ruview-cli (node 20) (push) Failing after 1s
npm packages / tools/ruview-cli (node 22) (push) Failing after 1s
npm packages / tools/ruview-mcp (node 22) (push) Failing after 1s
nvsim-server → ghcr.io / build-and-publish (push) Failing after 1s
ruview-swarm CI guard / tests (full+train) (push) Failing after 2s
ruview-swarm CI guard / tests (ruflo) (push) Failing after 1s
ruview-swarm CI guard / tests (train) (push) Failing after 2s
BFLD MQTT Integration / cargo test --features mqtt (live mosquitto) (push) Failing after 29s
ruview-swarm CI guard / tests (default) (push) Failing after 2s
Point Cloud Viewer → GitHub Pages / build-and-deploy (push) Failing after 8s
ruview-swarm CI guard / ITAR / publish guard (push) Failing after 0s
ruview-swarm CI guard / build train_marl bin (push) Failing after 2s
ruview-swarm CI guard / clippy (-D warnings, --no-deps) (push) Failing after 3s
Security Scanning / Dependency Vulnerability Scan (push) Failing after 0s
Security Scanning / Static Application Security Testing (push) Failing after 1s
Security Scanning / Infrastructure Security Scan (push) Failing after 1s
Security Scanning / Secret Scanning (push) Failing after 1s
npm packages / harness/ruview (node 22) (push) Failing after 17s
Security Scanning / License Compliance Scan (push) Failing after 1s
Security Scanning / Container Security Scan (push) Failing after 4s
Security Scanning / Security Policy Compliance (push) Failing after 0s
wifi-densepose sensing-server → Docker Hub + ghcr.io / build · push · smoke-test (push) Failing after 1s
three.js demos → GitHub Pages / build-and-deploy (push) Failing after 1s
Verify Pipeline Determinism / Verify Pipeline Determinism (3.11) (push) Failing after 1s
Continuous Deployment / Deploy to Production (push) Has been cancelled
Continuous Deployment / Rollback Deployment (push) Has been cancelled
Continuous Deployment / Post-deployment Monitoring (push) Has been cancelled
Continuous Deployment / Notify Deployment Status (push) Has been cancelled
Continuous Deployment / Deploy to Staging (push) Has been cancelled
Security Scanning / Security Report (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 11:59:54 +08:00

4.0 KiB

ADR-166: Quality Engineering Response — Security Hardening & Code Quality

Field Value
Status Accepted
Date 2026-03-06
Deciders ruv
Depends on ADR-032 (Multistatic Mesh Security)
Issue #170

Context

An independent quality engineering analysis (issue #170) identified 7 critical findings across the Rust codebase. After verification against the source code, the following findings are confirmed and require action:

Confirmed Critical Findings

# Finding Location Verified
1 Fake HMAC in secure_tdm.rs — XOR fold with hardcoded key hardware/src/esp32/secure_tdm.rs:253 YES — comments say "sufficient for testing"
2 sensing-server/main.rs is 3,741 lines — CC=65, god object sensing-server/src/main.rs YES — confirmed 3,741 lines
3 WebSocket server has zero authentication Rust WS codebase YES — no auth/token checks found
4 Zero security tests in Rust codebase Entire workspace YES — no auth/injection/tampering tests
5 54K fps claim has no supporting benchmark No criterion benchmarks YES — no benchmarks exist

Findings Requiring Further Investigation

# Finding Status
6 Unauthenticated OTA firmware endpoint Not found in Rust code — may be ESP32 C firmware level
7 WASM upload without mandatory signatures Needs review of WASM loader
8 O(n^2) autocorrelation in heart rate detection Needs profiling to confirm impact

Decision

Address findings in 3 priority sprints as recommended by the report.

Sprint 1: Security (Blocks Deployment)

  1. Replace fake HMAC with real HMAC-SHA256 in secure_tdm.rs

    • Use the hmac + sha2 crates (already in Cargo.lock)
    • Remove XOR fold implementation
    • Add key derivation (no more hardcoded keys)
  2. Add WebSocket authentication

    • Token-based auth on WS upgrade handshake
    • Optional API key for local-network deployments
    • Configurable via environment variable
  3. Add security test suite

    • Auth bypass attempts
    • Malformed CSI frame injection
    • Protocol tampering (TDM beacon replay, nonce reuse)

Sprint 2: Code Quality & Testability

  1. Decompose main.rs (3,741 lines -> ~14 focused modules)

    • Extract HTTP routes, WebSocket handler, CSI pipeline, config, state
    • Target: no file over 500 lines
  2. Add criterion benchmarks

    • CSI frame parsing throughput
    • Signal processing pipeline latency
    • WebSocket broadcast fanout

Sprint 3: Functional Verification

  1. Vital sign accuracy verification

    • Reference signal tests with known BPM
    • False-negative rate measurement
  2. Fix O(n^2) autocorrelation (if confirmed by profiling)

    • Replace brute-force lag with FFT-based autocorrelation

Consequences

Positive

  • Addresses all critical security findings before any production deployment
  • main.rs decomposition enables unit testing of server components
  • Criterion benchmarks provide verifiable performance claims
  • Security test suite prevents regression

Negative

  • Sprint 1 security changes are breaking for any existing TDM mesh deployments (fake HMAC -> real HMAC requires firmware update)
  • main.rs decomposition is a large refactor with merge conflict risk

Neutral

  • The report correctly identifies that life-safety claims (disaster detection, vital signs) require rigorous verification — this is an ongoing process, not a single sprint

Acknowledgment

Thanks to @proffesor-for-testing for the thorough 10-report analysis. The full report is archived at the original gist.

References

  • Issue #170: Quality Engineering Analysis
  • ADR-032: Multistatic Mesh Security Hardening
  • ADR-028: ESP32 Capability Audit