2019-09-10 09:53:31 +00:00
|
|
|
# This file is part of the Trezor project.
|
|
|
|
#
|
|
|
|
# Copyright (C) 2012-2019 SatoshiLabs and contributors
|
|
|
|
#
|
|
|
|
# This library is free software: you can redistribute it and/or modify
|
|
|
|
# it under the terms of the GNU Lesser General Public License version 3
|
|
|
|
# as published by the Free Software Foundation.
|
|
|
|
#
|
|
|
|
# This library is distributed in the hope that it will be useful,
|
|
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
# GNU Lesser General Public License for more details.
|
|
|
|
#
|
|
|
|
# You should have received a copy of the License along with this library.
|
|
|
|
# If not, see <https://www.gnu.org/licenses/lgpl-3.0.html>.
|
|
|
|
|
2019-07-19 13:50:42 +00:00
|
|
|
from itertools import combinations
|
2019-06-27 13:59:39 +00:00
|
|
|
from unittest import mock
|
|
|
|
|
|
|
|
import pytest
|
2019-07-19 13:50:42 +00:00
|
|
|
import shamir_mnemonic as shamir
|
|
|
|
from shamir_mnemonic import MnemonicError
|
2019-06-27 13:59:39 +00:00
|
|
|
|
|
|
|
from trezorlib import device, messages as proto
|
2019-09-23 12:49:54 +00:00
|
|
|
from trezorlib.exceptions import TrezorFailure
|
2019-09-19 07:37:23 +00:00
|
|
|
from trezorlib.messages import BackupType, ButtonRequestType as B
|
2019-06-27 13:59:39 +00:00
|
|
|
|
2019-09-11 12:43:32 +00:00
|
|
|
from ..common import click_through, generate_entropy, read_and_confirm_mnemonic
|
2019-06-27 13:59:39 +00:00
|
|
|
|
|
|
|
EXTERNAL_ENTROPY = b"zlutoucky kun upel divoke ody" * 2
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.skip_t1
|
2019-09-10 09:24:57 +00:00
|
|
|
class TestMsgResetDeviceT2:
|
2019-06-27 13:59:39 +00:00
|
|
|
# TODO: test with different options
|
2019-08-27 14:58:59 +00:00
|
|
|
@pytest.mark.setup_client(uninitialized=True)
|
2019-09-19 07:37:23 +00:00
|
|
|
def test_reset_device_slip39_basic(self, client):
|
2019-06-27 13:59:39 +00:00
|
|
|
strength = 128
|
2019-07-19 13:50:42 +00:00
|
|
|
member_threshold = 3
|
2019-08-14 13:46:08 +00:00
|
|
|
all_mnemonics = []
|
2019-06-27 13:59:39 +00:00
|
|
|
|
|
|
|
def input_flow():
|
2019-09-10 09:24:57 +00:00
|
|
|
# 1. Confirm Reset
|
|
|
|
# 2. Backup your seed
|
|
|
|
# 3. Confirm warning
|
|
|
|
# 4. shares info
|
|
|
|
# 5. Set & Confirm number of shares
|
|
|
|
# 6. threshold info
|
|
|
|
# 7. Set & confirm threshold value
|
|
|
|
# 8. Confirm show seeds
|
|
|
|
yield from click_through(client.debug, screens=8, code=B.ResetDevice)
|
2019-06-27 13:59:39 +00:00
|
|
|
|
|
|
|
# show & confirm shares
|
|
|
|
for h in range(5):
|
2019-09-10 09:24:57 +00:00
|
|
|
# mnemonic phrases
|
2019-06-27 13:59:39 +00:00
|
|
|
btn_code = yield
|
2019-09-19 07:37:23 +00:00
|
|
|
assert btn_code == B.ResetDevice
|
2019-09-10 09:24:57 +00:00
|
|
|
mnemonic = read_and_confirm_mnemonic(client.debug, words=20)
|
|
|
|
all_mnemonics.append(mnemonic)
|
2019-06-27 13:59:39 +00:00
|
|
|
|
|
|
|
# Confirm continue to next share
|
|
|
|
btn_code = yield
|
2019-07-26 09:41:47 +00:00
|
|
|
assert btn_code == B.Success
|
2019-08-27 14:58:59 +00:00
|
|
|
client.debug.press_yes()
|
2019-06-27 13:59:39 +00:00
|
|
|
|
|
|
|
# safety warning
|
|
|
|
btn_code = yield
|
2019-07-26 09:41:47 +00:00
|
|
|
assert btn_code == B.Success
|
2019-08-27 14:58:59 +00:00
|
|
|
client.debug.press_yes()
|
2019-06-27 13:59:39 +00:00
|
|
|
|
|
|
|
os_urandom = mock.Mock(return_value=EXTERNAL_ENTROPY)
|
2019-08-27 14:58:59 +00:00
|
|
|
with mock.patch("os.urandom", os_urandom), client:
|
|
|
|
client.set_expected_responses(
|
2019-06-27 13:59:39 +00:00
|
|
|
[
|
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
|
|
|
proto.EntropyRequest(),
|
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
2019-07-15 09:09:13 +00:00
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
2019-09-19 07:37:23 +00:00
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
2019-07-26 09:41:47 +00:00
|
|
|
proto.ButtonRequest(code=B.Success),
|
2019-09-19 07:37:23 +00:00
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
2019-07-26 09:41:47 +00:00
|
|
|
proto.ButtonRequest(code=B.Success),
|
2019-09-19 07:37:23 +00:00
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
2019-07-26 09:41:47 +00:00
|
|
|
proto.ButtonRequest(code=B.Success),
|
2019-09-19 07:37:23 +00:00
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
2019-07-26 09:41:47 +00:00
|
|
|
proto.ButtonRequest(code=B.Success),
|
2019-09-19 07:37:23 +00:00
|
|
|
proto.ButtonRequest(code=B.ResetDevice),
|
2019-07-26 09:41:47 +00:00
|
|
|
proto.ButtonRequest(code=B.Success),
|
|
|
|
proto.ButtonRequest(code=B.Success),
|
2019-06-27 13:59:39 +00:00
|
|
|
proto.Success(),
|
|
|
|
proto.Features(),
|
|
|
|
]
|
|
|
|
)
|
2019-08-27 14:58:59 +00:00
|
|
|
client.set_input_flow(input_flow)
|
2019-06-27 13:59:39 +00:00
|
|
|
|
|
|
|
# No PIN, no passphrase, don't display random
|
|
|
|
device.reset(
|
2019-08-27 14:58:59 +00:00
|
|
|
client,
|
2019-06-27 13:59:39 +00:00
|
|
|
display_random=False,
|
|
|
|
strength=strength,
|
|
|
|
passphrase_protection=False,
|
|
|
|
pin_protection=False,
|
|
|
|
label="test",
|
|
|
|
language="english",
|
2019-09-19 07:37:23 +00:00
|
|
|
backup_type=BackupType.Slip39_Basic,
|
2019-06-27 13:59:39 +00:00
|
|
|
)
|
|
|
|
|
2019-08-14 13:46:08 +00:00
|
|
|
# generate secret locally
|
2019-08-27 14:58:59 +00:00
|
|
|
internal_entropy = client.debug.state().reset_entropy
|
2019-08-14 13:46:08 +00:00
|
|
|
secret = generate_entropy(strength, internal_entropy, EXTERNAL_ENTROPY)
|
|
|
|
|
|
|
|
# validate that all combinations will result in the correct master secret
|
|
|
|
validate_mnemonics(all_mnemonics, member_threshold, secret)
|
|
|
|
|
2019-06-27 13:59:39 +00:00
|
|
|
# Check if device is properly initialized
|
2019-08-27 14:58:59 +00:00
|
|
|
assert client.features.initialized is True
|
|
|
|
assert client.features.needs_backup is False
|
|
|
|
assert client.features.pin_protection is False
|
|
|
|
assert client.features.passphrase_protection is False
|
2019-09-19 07:37:23 +00:00
|
|
|
assert client.features.backup_type is BackupType.Slip39_Basic
|
2019-06-27 13:59:39 +00:00
|
|
|
|
2019-09-23 12:49:54 +00:00
|
|
|
# backup attempt fails because backup was done in reset
|
|
|
|
with pytest.raises(TrezorFailure, match="ProcessError: Seed already backed up"):
|
|
|
|
device.backup(client)
|
|
|
|
|
2019-06-27 13:59:39 +00:00
|
|
|
|
2019-08-12 13:53:23 +00:00
|
|
|
def validate_mnemonics(mnemonics, threshold, expected_ems):
|
2019-07-19 13:50:42 +00:00
|
|
|
# We expect these combinations to recreate the secret properly
|
|
|
|
for test_group in combinations(mnemonics, threshold):
|
2019-08-12 10:27:02 +00:00
|
|
|
# TODO: HOTFIX, we should fix this properly by modifying and unifying the python-shamir-mnemonic API
|
|
|
|
ms = shamir.combine_mnemonics(test_group)
|
|
|
|
identifier, iteration_exponent, _, _, _ = shamir._decode_mnemonics(test_group)
|
|
|
|
ems = shamir._encrypt(ms, b"", iteration_exponent, identifier)
|
2019-08-12 13:53:23 +00:00
|
|
|
assert ems == expected_ems
|
2019-07-19 13:50:42 +00:00
|
|
|
# We expect these combinations to raise MnemonicError
|
|
|
|
for test_group in combinations(mnemonics, threshold - 1):
|
|
|
|
with pytest.raises(
|
|
|
|
MnemonicError, match=r".*Expected {} mnemonics.*".format(threshold)
|
|
|
|
):
|
2019-08-12 10:27:02 +00:00
|
|
|
shamir.combine_mnemonics(test_group)
|