2018-06-21 14:28:34 +00:00
|
|
|
# This file is part of the Trezor project.
|
2017-01-03 18:40:05 +00:00
|
|
|
#
|
2019-05-29 16:44:09 +00:00
|
|
|
# Copyright (C) 2012-2019 SatoshiLabs and contributors
|
2017-01-03 18:40:05 +00:00
|
|
|
#
|
|
|
|
# This library is free software: you can redistribute it and/or modify
|
2018-06-21 14:28:34 +00:00
|
|
|
# it under the terms of the GNU Lesser General Public License version 3
|
|
|
|
# as published by the Free Software Foundation.
|
2017-01-03 18:40:05 +00:00
|
|
|
#
|
|
|
|
# This library is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU Lesser General Public License for more details.
|
|
|
|
#
|
2018-06-21 14:28:34 +00:00
|
|
|
# You should have received a copy of the License along with this library.
|
|
|
|
# If not, see <https://www.gnu.org/licenses/lgpl-3.0.html>.
|
2017-01-03 18:40:05 +00:00
|
|
|
|
2020-08-28 19:12:25 +00:00
|
|
|
import json
|
2023-05-12 09:19:35 +00:00
|
|
|
import re
|
2023-05-04 12:20:00 +00:00
|
|
|
import time
|
2020-08-28 19:12:25 +00:00
|
|
|
from pathlib import Path
|
2023-05-04 12:20:00 +00:00
|
|
|
from typing import TYPE_CHECKING, Generator, Optional
|
|
|
|
from unittest import mock
|
2020-08-28 19:12:25 +00:00
|
|
|
|
|
|
|
import pytest
|
|
|
|
|
2024-03-09 21:05:05 +00:00
|
|
|
from trezorlib import btc, messages, models, tools
|
2022-01-28 18:26:03 +00:00
|
|
|
|
|
|
|
if TYPE_CHECKING:
|
|
|
|
from _pytest.mark.structures import MarkDecorator
|
2019-09-02 08:20:51 +00:00
|
|
|
|
2023-08-15 15:58:32 +00:00
|
|
|
from trezorlib.debuglink import DebugLink
|
|
|
|
from trezorlib.debuglink import TrezorClientDebugLink as Client
|
|
|
|
from trezorlib.messages import ButtonRequest
|
|
|
|
|
2023-08-11 15:57:32 +00:00
|
|
|
PRIVATE_KEYS_DEV = [byte * 32 for byte in (b"\xdd", b"\xde", b"\xdf")]
|
2022-02-25 12:05:27 +00:00
|
|
|
|
2023-07-21 09:38:28 +00:00
|
|
|
BRGeneratorType = Generator[None, messages.ButtonRequest, None]
|
|
|
|
|
|
|
|
|
2019-08-27 12:48:16 +00:00
|
|
|
# fmt: off
|
|
|
|
# 1 2 3 4 5 6 7 8 9 10 11 12
|
|
|
|
MNEMONIC12 = "alcohol woman abuse must during monitor noble actual mixed trade anger aisle"
|
2019-09-19 07:37:23 +00:00
|
|
|
MNEMONIC_SLIP39_BASIC_20_3of6 = [
|
2019-09-02 08:20:51 +00:00
|
|
|
"extra extend academic bishop cricket bundle tofu goat apart victim enlarge program behavior permit course armed jerky faint language modern",
|
|
|
|
"extra extend academic acne away best indicate impact square oasis prospect painting voting guest either argue username racism enemy eclipse",
|
|
|
|
"extra extend academic arcade born dive legal hush gross briefing talent drug much home firefly toxic analysis idea umbrella slice",
|
|
|
|
]
|
2019-10-25 14:37:35 +00:00
|
|
|
MNEMONIC_SLIP39_BASIC_20_3of6_SECRET = "491b795b80fc21ccdf466c0fbc98c8fc"
|
2024-05-17 21:08:23 +00:00
|
|
|
MNEMONIC_SLIP39_BASIC_EXT_20_2of3 = [
|
|
|
|
"enemy favorite academic acid cowboy phrase havoc level response walnut budget painting inside trash adjust froth kitchen learn tidy punish",
|
|
|
|
"enemy favorite academic always academic sniff script carpet romp kind promise scatter center unfair training emphasis evening belong fake enforce",
|
|
|
|
]
|
|
|
|
MNEMONIC_SLIP39_BASIC_EXT_20_2of3_SECRET = "644c905b0c4da21692f06fff3ed8b3e1"
|
2019-09-19 07:37:23 +00:00
|
|
|
# Shamir shares (128 bits, 2 groups from 1 of 1, 1 of 1, 3 of 5, 2 of 6)
|
|
|
|
MNEMONIC_SLIP39_ADVANCED_20 = [
|
|
|
|
"eraser senior beard romp adorn nuclear spill corner cradle style ancient family general leader ambition exchange unusual garlic promise voice",
|
|
|
|
"eraser senior ceramic snake clay various huge numb argue hesitate auction category timber browser greatest hanger petition script leaf pickup",
|
|
|
|
"eraser senior ceramic shaft dynamic become junior wrist silver peasant force math alto coal amazing segment yelp velvet image paces",
|
|
|
|
"eraser senior ceramic round column hawk trust auction smug shame alive greatest sheriff living perfect corner chest sled fumes adequate",
|
|
|
|
]
|
|
|
|
# Shamir shares (256 bits, 2 groups from 1 of 1, 1 of 1, 3 of 5, 2 of 6):
|
|
|
|
MNEMONIC_SLIP39_ADVANCED_33 = [
|
|
|
|
"wildlife deal beard romp alcohol space mild usual clothes union nuclear testify course research heat listen task location thank hospital slice smell failure fawn helpful priest ambition average recover lecture process dough stadium",
|
|
|
|
"wildlife deal acrobat romp anxiety axis starting require metric flexible geology game drove editor edge screw helpful have huge holy making pitch unknown carve holiday numb glasses survive already tenant adapt goat fangs",
|
2019-09-02 08:20:51 +00:00
|
|
|
]
|
2024-04-11 14:21:17 +00:00
|
|
|
MNEMONIC_SLIP39_CUSTOM_1of1 = ["tolerate flexible academic academic average dwarf square home promise aspect temple cluster roster forward hand unfair tenant emperor ceramic element forget perfect knit adapt review usual formal receiver typical pleasure duke yield party"]
|
|
|
|
MNEMONIC_SLIP39_CUSTOM_SECRET = "3439316237393562383066633231636364663436366330666263393863386663"
|
2019-12-09 16:01:04 +00:00
|
|
|
# External entropy mocked as received from trezorlib.
|
|
|
|
EXTERNAL_ENTROPY = b"zlutoucky kun upel divoke ody" * 2
|
2019-09-19 07:37:23 +00:00
|
|
|
# fmt: on
|
2019-09-02 08:20:51 +00:00
|
|
|
|
2020-05-13 09:36:03 +00:00
|
|
|
TEST_ADDRESS_N = tools.parse_path("m/44h/1h/0h/0/0")
|
2020-08-28 19:12:25 +00:00
|
|
|
COMMON_FIXTURES_DIR = (
|
2022-01-28 15:02:17 +00:00
|
|
|
Path(__file__).resolve().parent.parent / "common" / "tests" / "fixtures"
|
2020-08-28 19:12:25 +00:00
|
|
|
)
|
|
|
|
|
2023-05-04 12:20:00 +00:00
|
|
|
# So that all the random things are consistent
|
|
|
|
MOCK_OS_URANDOM = mock.Mock(return_value=EXTERNAL_ENTROPY)
|
|
|
|
WITH_MOCK_URANDOM = mock.patch("os.urandom", MOCK_OS_URANDOM)
|
|
|
|
|
2020-08-28 19:12:25 +00:00
|
|
|
|
2022-01-28 18:26:03 +00:00
|
|
|
def parametrize_using_common_fixtures(*paths: str) -> "MarkDecorator":
|
2020-08-28 19:12:25 +00:00
|
|
|
fixtures = []
|
|
|
|
for path in paths:
|
|
|
|
fixtures.append(json.loads((COMMON_FIXTURES_DIR / path).read_text()))
|
|
|
|
|
|
|
|
tests = []
|
|
|
|
for fixture in fixtures:
|
|
|
|
for test in fixture["tests"]:
|
2021-01-20 16:06:30 +00:00
|
|
|
test_id = test.get("name")
|
|
|
|
if not test_id:
|
|
|
|
test_id = test.get("description")
|
|
|
|
if test_id is not None:
|
|
|
|
test_id = test_id.lower().replace(" ", "_")
|
|
|
|
|
2023-11-30 23:47:41 +00:00
|
|
|
skip_models = test.get("skip_models", [])
|
|
|
|
skip_marks = []
|
|
|
|
for skip_model in skip_models:
|
2024-03-09 21:05:05 +00:00
|
|
|
if skip_model in ("t1", "t1b1"):
|
2024-03-11 15:20:08 +00:00
|
|
|
skip_marks.append(pytest.mark.skip_t1b1)
|
2024-03-09 21:05:05 +00:00
|
|
|
if skip_model in ("t2", "t2t1"):
|
2024-03-11 15:20:08 +00:00
|
|
|
skip_marks.append(pytest.mark.skip_t2t1)
|
2024-03-09 21:05:05 +00:00
|
|
|
if skip_model in ("tr", "t2b1"):
|
2024-03-11 15:20:08 +00:00
|
|
|
skip_marks.append(pytest.mark.skip_t2b1)
|
2024-03-09 21:05:05 +00:00
|
|
|
if skip_model == "t3t1":
|
|
|
|
skip_marks.append(pytest.mark.skip_t3t1)
|
2023-11-30 23:47:41 +00:00
|
|
|
|
2020-08-28 19:12:25 +00:00
|
|
|
tests.append(
|
|
|
|
pytest.param(
|
|
|
|
test["parameters"],
|
|
|
|
test["result"],
|
2023-11-30 23:47:41 +00:00
|
|
|
marks=[
|
|
|
|
pytest.mark.setup_client(
|
|
|
|
passphrase=fixture["setup"]["passphrase"],
|
|
|
|
mnemonic=fixture["setup"]["mnemonic"],
|
|
|
|
)
|
|
|
|
]
|
|
|
|
+ skip_marks,
|
2021-01-20 16:06:30 +00:00
|
|
|
id=test_id,
|
2020-08-28 19:12:25 +00:00
|
|
|
)
|
|
|
|
)
|
|
|
|
|
|
|
|
return pytest.mark.parametrize("parameters, result", tests)
|
2020-05-13 09:36:03 +00:00
|
|
|
|
2016-11-28 15:01:45 +00:00
|
|
|
|
2022-01-28 18:26:03 +00:00
|
|
|
def generate_entropy(
|
|
|
|
strength: int, internal_entropy: bytes, external_entropy: bytes
|
|
|
|
) -> bytes:
|
2018-08-13 16:21:24 +00:00
|
|
|
"""
|
2017-06-28 15:56:58 +00:00
|
|
|
strength - length of produced seed. One of 128, 192, 256
|
|
|
|
random - binary stream of random data from external HRNG
|
2018-08-13 16:21:24 +00:00
|
|
|
"""
|
2017-12-23 20:20:49 +00:00
|
|
|
import hashlib
|
|
|
|
|
2017-06-28 15:56:58 +00:00
|
|
|
if strength not in (128, 192, 256):
|
2017-11-06 10:09:54 +00:00
|
|
|
raise ValueError("Invalid strength")
|
2017-06-28 15:56:58 +00:00
|
|
|
|
|
|
|
if not internal_entropy:
|
2017-11-06 10:09:54 +00:00
|
|
|
raise ValueError("Internal entropy is not provided")
|
2017-06-28 15:56:58 +00:00
|
|
|
|
|
|
|
if len(internal_entropy) < 32:
|
2017-11-06 10:09:54 +00:00
|
|
|
raise ValueError("Internal entropy too short")
|
2017-06-28 15:56:58 +00:00
|
|
|
|
|
|
|
if not external_entropy:
|
2017-11-06 10:09:54 +00:00
|
|
|
raise ValueError("External entropy is not provided")
|
2017-06-28 15:56:58 +00:00
|
|
|
|
|
|
|
if len(external_entropy) < 32:
|
2017-11-06 10:09:54 +00:00
|
|
|
raise ValueError("External entropy too short")
|
2017-06-28 15:56:58 +00:00
|
|
|
|
|
|
|
entropy = hashlib.sha256(internal_entropy + external_entropy).digest()
|
2018-08-13 16:21:24 +00:00
|
|
|
entropy_stripped = entropy[: strength // 8]
|
2017-06-28 15:56:58 +00:00
|
|
|
|
|
|
|
if len(entropy_stripped) * 8 != strength:
|
2017-11-06 10:09:54 +00:00
|
|
|
raise ValueError("Entropy length mismatch")
|
2017-06-28 15:56:58 +00:00
|
|
|
|
|
|
|
return entropy_stripped
|
2019-09-02 08:20:51 +00:00
|
|
|
|
|
|
|
|
2022-01-28 18:26:03 +00:00
|
|
|
def click_through(
|
2023-08-11 15:57:32 +00:00
|
|
|
debug: "DebugLink", screens: int, code: Optional[messages.ButtonRequestType] = None
|
2022-01-28 18:26:03 +00:00
|
|
|
) -> Generator[None, "ButtonRequest", None]:
|
2019-09-10 09:24:57 +00:00
|
|
|
"""Click through N dialog screens.
|
|
|
|
|
|
|
|
For use in an input flow function.
|
|
|
|
Example:
|
|
|
|
|
|
|
|
def input_flow():
|
|
|
|
# 1. Confirm reset
|
|
|
|
# 2. Backup your seed
|
|
|
|
# 3. Confirm warning
|
|
|
|
# 4. Shares info
|
2022-01-28 18:26:03 +00:00
|
|
|
yield from click_through(client.debug, screens=4, code=ButtonRequestType.ResetDevice)
|
2019-09-10 09:24:57 +00:00
|
|
|
"""
|
|
|
|
for _ in range(screens):
|
|
|
|
received = yield
|
|
|
|
if code is not None:
|
2021-06-17 14:31:26 +00:00
|
|
|
assert received.code == code
|
2019-09-10 09:24:57 +00:00
|
|
|
debug.press_yes()
|
|
|
|
|
|
|
|
|
2022-01-28 18:26:03 +00:00
|
|
|
def read_and_confirm_mnemonic(
|
|
|
|
debug: "DebugLink", choose_wrong: bool = False
|
2023-05-12 09:19:35 +00:00
|
|
|
) -> Generator[None, "ButtonRequest", Optional[str]]:
|
2024-03-27 10:09:03 +00:00
|
|
|
"""Read a given number of mnemonic words from the screen and answer
|
|
|
|
confirmation questions.
|
|
|
|
Return the full mnemonic or None if `choose_wrong` is True.
|
2019-09-10 09:24:57 +00:00
|
|
|
|
|
|
|
For use in an input flow function.
|
|
|
|
Example:
|
|
|
|
|
|
|
|
def input_flow():
|
|
|
|
yield from click_through(client.debug, screens=3)
|
|
|
|
|
2021-06-17 14:31:26 +00:00
|
|
|
mnemonic = yield from read_and_confirm_mnemonic(client.debug)
|
2019-09-10 09:24:57 +00:00
|
|
|
"""
|
2024-03-27 10:09:03 +00:00
|
|
|
if debug.model is models.T2T1:
|
|
|
|
mnemonic = yield from read_mnemonic_from_screen_tt(debug)
|
|
|
|
elif debug.model is models.T2B1:
|
|
|
|
mnemonic = yield from read_mnemonic_from_screen_tr(debug)
|
|
|
|
elif debug.model is models.T3T1:
|
|
|
|
mnemonic = yield from read_mnemonic_from_screen_mercury(debug)
|
|
|
|
else:
|
|
|
|
raise ValueError(f"Unknown model: {debug.model}")
|
|
|
|
|
|
|
|
if not check_share(debug, mnemonic, choose_wrong):
|
|
|
|
return None
|
|
|
|
return " ".join(mnemonic)
|
|
|
|
|
|
|
|
|
|
|
|
def read_mnemonic_from_screen_tt(
|
|
|
|
debug: "DebugLink",
|
|
|
|
) -> Generator[None, "ButtonRequest", list[str]]:
|
2023-05-04 12:20:00 +00:00
|
|
|
mnemonic: list[str] = []
|
2021-07-09 12:48:40 +00:00
|
|
|
br = yield
|
2022-01-28 18:26:03 +00:00
|
|
|
assert br.pages is not None
|
2021-07-09 12:48:40 +00:00
|
|
|
|
2023-05-04 12:20:00 +00:00
|
|
|
debug.wait_layout()
|
|
|
|
|
|
|
|
for i in range(br.pages):
|
|
|
|
words = debug.wait_layout().seed_words()
|
|
|
|
mnemonic.extend(words)
|
|
|
|
# Not swiping on the last page
|
|
|
|
if i < br.pages - 1:
|
|
|
|
debug.swipe_up()
|
|
|
|
|
2021-07-09 12:48:40 +00:00
|
|
|
debug.press_yes()
|
2024-03-27 10:09:03 +00:00
|
|
|
return mnemonic
|
2020-05-13 09:36:03 +00:00
|
|
|
|
|
|
|
|
2024-03-27 10:09:03 +00:00
|
|
|
def read_mnemonic_from_screen_tr(
|
|
|
|
debug: "DebugLink",
|
|
|
|
) -> Generator[None, "ButtonRequest", list[str]]:
|
2023-05-12 09:19:35 +00:00
|
|
|
mnemonic: list[str] = []
|
2023-06-26 08:50:28 +00:00
|
|
|
yield # write down all 12 words in order
|
|
|
|
debug.press_yes()
|
2023-05-12 09:19:35 +00:00
|
|
|
br = yield
|
|
|
|
assert br.pages is not None
|
2023-06-26 08:50:28 +00:00
|
|
|
for _ in range(br.pages - 1):
|
2023-05-12 09:19:35 +00:00
|
|
|
layout = debug.wait_layout()
|
2023-06-26 08:50:28 +00:00
|
|
|
words = layout.seed_words()
|
|
|
|
mnemonic.extend(words)
|
2023-05-12 09:19:35 +00:00
|
|
|
debug.press_right()
|
|
|
|
debug.press_yes()
|
|
|
|
|
|
|
|
yield # Select correct words...
|
|
|
|
debug.press_right()
|
2024-03-27 10:09:03 +00:00
|
|
|
return mnemonic
|
|
|
|
|
2023-05-12 09:19:35 +00:00
|
|
|
|
2024-03-27 10:09:03 +00:00
|
|
|
def read_mnemonic_from_screen_mercury(
|
|
|
|
debug: "DebugLink",
|
|
|
|
) -> Generator[None, "ButtonRequest", list[str]]:
|
|
|
|
mnemonic: list[str] = []
|
|
|
|
br = yield
|
|
|
|
assert br.pages is not None
|
|
|
|
|
|
|
|
debug.wait_layout()
|
|
|
|
|
2024-04-28 11:46:39 +00:00
|
|
|
for _ in range(br.pages):
|
2024-03-27 10:09:03 +00:00
|
|
|
words = debug.wait_layout().seed_words()
|
|
|
|
mnemonic.extend(words)
|
|
|
|
debug.swipe_up()
|
|
|
|
|
|
|
|
return mnemonic
|
|
|
|
|
|
|
|
|
|
|
|
def check_share(
|
|
|
|
debug: "DebugLink", mnemonic: list[str], choose_wrong: bool = False
|
|
|
|
) -> bool:
|
|
|
|
"""
|
|
|
|
Given the mnemonic word list, proceed with the backup check:
|
|
|
|
three rounds of `Select word X of Y` choices.
|
|
|
|
"""
|
2023-05-12 09:19:35 +00:00
|
|
|
for _ in range(3):
|
2024-05-22 13:45:49 +00:00
|
|
|
if debug.model is models.T2B1:
|
|
|
|
# T2B1 has the instruction in the title
|
|
|
|
word_pos_match = re.search(r"\d+", debug.wait_layout().title())
|
|
|
|
else:
|
|
|
|
# Other models has position as the first number in the text
|
|
|
|
word_pos_match = re.search(r"\d+", debug.wait_layout().text_content())
|
2023-05-12 09:19:35 +00:00
|
|
|
assert word_pos_match is not None
|
|
|
|
word_pos = int(word_pos_match.group(0))
|
2024-03-27 10:09:03 +00:00
|
|
|
|
2023-05-12 09:19:35 +00:00
|
|
|
index = word_pos - 1
|
|
|
|
if choose_wrong:
|
|
|
|
debug.input(mnemonic[(index + 1) % len(mnemonic)])
|
2024-03-27 10:09:03 +00:00
|
|
|
return False
|
2023-05-12 09:19:35 +00:00
|
|
|
else:
|
|
|
|
debug.input(mnemonic[index])
|
|
|
|
|
2024-03-27 10:09:03 +00:00
|
|
|
return True
|
2023-05-12 09:19:35 +00:00
|
|
|
|
|
|
|
|
2023-06-29 15:26:51 +00:00
|
|
|
def click_info_button_tt(debug: "DebugLink"):
|
2023-05-04 12:20:00 +00:00
|
|
|
"""Click Shamir backup info button and return back."""
|
|
|
|
debug.press_info()
|
|
|
|
yield # Info screen with text
|
|
|
|
debug.press_yes()
|
|
|
|
|
|
|
|
|
|
|
|
def check_pin_backoff_time(attempts: int, start: float) -> None:
|
|
|
|
"""Helper to assert the exponentially growing delay after incorrect PIN attempts"""
|
|
|
|
expected = (2**attempts) - 1
|
|
|
|
got = round(time.time() - start, 2)
|
|
|
|
assert got >= expected
|
|
|
|
|
|
|
|
|
2022-01-28 18:26:03 +00:00
|
|
|
def get_test_address(client: "Client") -> str:
|
2020-05-22 10:22:06 +00:00
|
|
|
"""Fetch a testnet address on a fixed path. Useful to make a pin/passphrase
|
|
|
|
protected call, or to identify the root secret (seed+passphrase)"""
|
2020-05-13 09:36:03 +00:00
|
|
|
return btc.get_address(client, "Testnet", TEST_ADDRESS_N)
|
2023-08-28 07:57:38 +00:00
|
|
|
|
|
|
|
|
2023-08-11 15:57:32 +00:00
|
|
|
def compact_size(n: int) -> bytes:
|
2023-08-28 07:57:38 +00:00
|
|
|
if n < 253:
|
|
|
|
return n.to_bytes(1, "little")
|
|
|
|
elif n < 0x1_0000:
|
|
|
|
return bytes([253]) + n.to_bytes(2, "little")
|
|
|
|
elif n < 0x1_0000_0000:
|
|
|
|
return bytes([254]) + n.to_bytes(4, "little")
|
|
|
|
else:
|
|
|
|
return bytes([255]) + n.to_bytes(8, "little")
|
2023-08-11 15:57:32 +00:00
|
|
|
|
|
|
|
|
|
|
|
def get_text_possible_pagination(debug: "DebugLink", br: messages.ButtonRequest) -> str:
|
|
|
|
text = debug.wait_layout().text_content()
|
|
|
|
if br.pages is not None:
|
|
|
|
for _ in range(br.pages - 1):
|
|
|
|
debug.swipe_up()
|
|
|
|
text += " "
|
|
|
|
text += debug.wait_layout().text_content()
|
|
|
|
return text
|
|
|
|
|
|
|
|
|
|
|
|
def swipe_if_necessary(
|
|
|
|
debug: "DebugLink", br_code: messages.ButtonRequestType | None = None
|
|
|
|
) -> BRGeneratorType:
|
|
|
|
br = yield
|
|
|
|
if br_code is not None:
|
|
|
|
assert br.code == br_code
|
|
|
|
swipe_till_the_end(debug, br)
|
|
|
|
|
|
|
|
|
|
|
|
def swipe_till_the_end(debug: "DebugLink", br: messages.ButtonRequest) -> None:
|
|
|
|
if br.pages is not None:
|
|
|
|
for _ in range(br.pages - 1):
|
|
|
|
debug.swipe_up()
|
2024-03-09 21:05:05 +00:00
|
|
|
|
|
|
|
|
|
|
|
def is_core(client: "Client") -> bool:
|
2024-05-21 21:49:08 +00:00
|
|
|
return client.model is not models.T1B1
|