Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
205 lines
10 KiB
Swift
205 lines
10 KiB
Swift
import CryptoKit
|
|
import Foundation
|
|
import Testing
|
|
@testable import OpenClawKit
|
|
|
|
@Suite(.serialized)
|
|
struct DeviceIdentityStoreTests {
|
|
@Test
|
|
func `state directory override wins over shared app group storage`() {
|
|
let tempDir = FileManager.default.temporaryDirectory
|
|
.appendingPathComponent(UUID().uuidString, isDirectory: true)
|
|
defer { try? FileManager.default.removeItem(at: tempDir) }
|
|
let overrideURL = tempDir.appendingPathComponent("override", isDirectory: true)
|
|
let legacyURL = tempDir.appendingPathComponent("legacy", isDirectory: true)
|
|
let sharedURL = tempDir.appendingPathComponent("shared", isDirectory: true)
|
|
|
|
let selected = DeviceIdentityPaths.stateDirURL(
|
|
overrideURL: overrideURL,
|
|
legacyStateDirURL: legacyURL,
|
|
appGroupStateDirURL: sharedURL,
|
|
temporaryDirectory: tempDir)
|
|
|
|
#expect(selected == overrideURL)
|
|
#expect(!FileManager.default.fileExists(atPath: sharedURL.path))
|
|
}
|
|
|
|
@Test
|
|
func `shared app group storage wins over legacy app support storage`() throws {
|
|
let tempDir = FileManager.default.temporaryDirectory
|
|
.appendingPathComponent(UUID().uuidString, isDirectory: true)
|
|
defer { try? FileManager.default.removeItem(at: tempDir) }
|
|
let legacyURL = tempDir.appendingPathComponent("legacy", isDirectory: true)
|
|
let sharedURL = tempDir.appendingPathComponent("shared", isDirectory: true)
|
|
let legacyIdentityURL = legacyURL.appendingPathComponent("identity", isDirectory: true)
|
|
let legacyDeviceURL = legacyIdentityURL.appendingPathComponent("device.json", isDirectory: false)
|
|
let sharedIdentityURL = sharedURL.appendingPathComponent("identity", isDirectory: true)
|
|
let sharedDeviceURL = sharedIdentityURL.appendingPathComponent("device.json", isDirectory: false)
|
|
try FileManager.default.createDirectory(at: legacyIdentityURL, withIntermediateDirectories: true)
|
|
try "legacy-device\n".write(to: legacyDeviceURL, atomically: true, encoding: .utf8)
|
|
|
|
let selected = DeviceIdentityPaths.stateDirURL(
|
|
overrideURL: nil,
|
|
legacyStateDirURL: legacyURL,
|
|
appGroupStateDirURL: sharedURL,
|
|
temporaryDirectory: tempDir)
|
|
|
|
#expect(selected == sharedURL)
|
|
#expect(!FileManager.default.fileExists(atPath: sharedDeviceURL.path))
|
|
}
|
|
|
|
@Test
|
|
func `secondary profiles use separate identity and auth files`() throws {
|
|
let tempDir = FileManager.default.temporaryDirectory
|
|
.appendingPathComponent(UUID().uuidString, isDirectory: true)
|
|
try FileManager.default.createDirectory(at: tempDir, withIntermediateDirectories: true)
|
|
let previousStateDir = ProcessInfo.processInfo.environment["OPENCLAW_STATE_DIR"]
|
|
setenv("OPENCLAW_STATE_DIR", tempDir.path, 1)
|
|
defer {
|
|
if let previousStateDir {
|
|
setenv("OPENCLAW_STATE_DIR", previousStateDir, 1)
|
|
} else {
|
|
unsetenv("OPENCLAW_STATE_DIR")
|
|
}
|
|
try? FileManager.default.removeItem(at: tempDir)
|
|
}
|
|
|
|
let primaryIdentity = DeviceIdentityStore.loadOrCreate()
|
|
let nodeIdentity = DeviceIdentityStore.loadOrCreate(profile: .node)
|
|
let shareIdentity = DeviceIdentityStore.loadOrCreate(profile: .shareExtension)
|
|
_ = DeviceAuthStore.storeToken(
|
|
deviceId: primaryIdentity.deviceId,
|
|
role: "node",
|
|
token: "primary-token")
|
|
_ = DeviceAuthStore.storeToken(
|
|
deviceId: nodeIdentity.deviceId,
|
|
role: "node",
|
|
token: "node-token",
|
|
profile: .node)
|
|
_ = DeviceAuthStore.storeToken(
|
|
deviceId: shareIdentity.deviceId,
|
|
role: "node",
|
|
token: "share-token",
|
|
profile: .shareExtension)
|
|
|
|
let identityDir = tempDir.appendingPathComponent("identity", isDirectory: true)
|
|
#expect(primaryIdentity.deviceId != nodeIdentity.deviceId)
|
|
#expect(primaryIdentity.deviceId != shareIdentity.deviceId)
|
|
#expect(FileManager.default.fileExists(atPath: identityDir.appendingPathComponent("device.json").path))
|
|
#expect(FileManager.default.fileExists(atPath: identityDir.appendingPathComponent("node-device.json").path))
|
|
#expect(FileManager.default.fileExists(atPath: identityDir.appendingPathComponent("share-device.json").path))
|
|
#expect(FileManager.default.fileExists(atPath: identityDir.appendingPathComponent("device-auth.json").path))
|
|
#expect(FileManager.default
|
|
.fileExists(atPath: identityDir.appendingPathComponent("node-device-auth.json").path))
|
|
#expect(FileManager.default
|
|
.fileExists(atPath: identityDir.appendingPathComponent("share-device-auth.json").path))
|
|
#expect(DeviceAuthStore.loadToken(deviceId: primaryIdentity.deviceId, role: "node")?.token == "primary-token")
|
|
#expect(DeviceAuthStore.loadToken(
|
|
deviceId: nodeIdentity.deviceId,
|
|
role: "node",
|
|
profile: .node)?.token == "node-token")
|
|
#expect(
|
|
DeviceAuthStore
|
|
.loadToken(deviceId: shareIdentity.deviceId, role: "node", profile: .shareExtension)?.token ==
|
|
"share-token")
|
|
|
|
DeviceAuthStore.clearAll(profile: .shareExtension)
|
|
|
|
#expect(DeviceAuthStore.loadToken(deviceId: primaryIdentity.deviceId, role: "node")?.token == "primary-token")
|
|
#expect(DeviceAuthStore.loadToken(
|
|
deviceId: nodeIdentity.deviceId,
|
|
role: "node",
|
|
profile: .node)?.token == "node-token")
|
|
#expect(DeviceAuthStore
|
|
.loadToken(deviceId: shareIdentity.deviceId, role: "node", profile: .shareExtension) == nil)
|
|
}
|
|
|
|
@Test
|
|
func `loads TypeScript PEM identity schema without rewriting or regenerating`() throws {
|
|
let tempDir = FileManager.default.temporaryDirectory
|
|
.appendingPathComponent(UUID().uuidString, isDirectory: true)
|
|
let identityURL = tempDir
|
|
.appendingPathComponent("identity", isDirectory: true)
|
|
.appendingPathComponent("device.json", isDirectory: false)
|
|
defer { try? FileManager.default.removeItem(at: tempDir) }
|
|
try FileManager.default.createDirectory(
|
|
at: identityURL.deletingLastPathComponent(),
|
|
withIntermediateDirectories: true)
|
|
let stored = try Self.identityJSON(
|
|
publicKeyPem: Self.pem(
|
|
label: "PUBLIC KEY",
|
|
body: "MCowBQYDK2VwAyEAA6EHv/POEL4dcN0Y50vAmWfk1jCbpQ1fHdyGZBJVMbg="),
|
|
privateKeyPem: Self.pem(
|
|
label: "PRIVATE KEY",
|
|
body: "MC4CAQAwBQYDK2VwBCIEIAABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4f"))
|
|
try stored.write(to: identityURL, atomically: true, encoding: .utf8)
|
|
let before = try String(contentsOf: identityURL, encoding: .utf8)
|
|
|
|
let identity = DeviceIdentityStore.loadOrCreate(fileURL: identityURL)
|
|
|
|
#expect(identity.deviceId == "56475aa75463474c0285df5dbf2bcab73da651358839e9b77481b2eab107708c")
|
|
#expect(identity.publicKey == "A6EHv/POEL4dcN0Y50vAmWfk1jCbpQ1fHdyGZBJVMbg=")
|
|
#expect(identity.privateKey == "AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8=")
|
|
#expect(DeviceIdentityStore.publicKeyBase64Url(identity) == "A6EHv_POEL4dcN0Y50vAmWfk1jCbpQ1fHdyGZBJVMbg")
|
|
let signature = try #require(DeviceIdentityStore.signPayload("hello", identity: identity))
|
|
let publicKeyData = try #require(Data(base64Encoded: identity.publicKey))
|
|
let signatureData = try #require(Self.base64UrlDecode(signature))
|
|
let publicKey = try Curve25519.Signing.PublicKey(rawRepresentation: publicKeyData)
|
|
#expect(publicKey.isValidSignature(signatureData, for: Data("hello".utf8)))
|
|
#expect(try String(contentsOf: identityURL, encoding: .utf8) == before)
|
|
}
|
|
|
|
@Test
|
|
func `does not overwrite a recognized invalid TypeScript identity schema`() throws {
|
|
let tempDir = FileManager.default.temporaryDirectory
|
|
.appendingPathComponent(UUID().uuidString, isDirectory: true)
|
|
let identityURL = tempDir
|
|
.appendingPathComponent("identity", isDirectory: true)
|
|
.appendingPathComponent("device.json", isDirectory: false)
|
|
defer { try? FileManager.default.removeItem(at: tempDir) }
|
|
try FileManager.default.createDirectory(
|
|
at: identityURL.deletingLastPathComponent(),
|
|
withIntermediateDirectories: true)
|
|
let stored = """
|
|
{
|
|
"version": 1,
|
|
"deviceId": "stale-device-id",
|
|
"publicKeyPem": "not-a-valid-public-key",
|
|
"privateKeyPem": "not-a-valid-private-key",
|
|
"createdAtMs": 1700000000000
|
|
}
|
|
"""
|
|
try stored.write(to: identityURL, atomically: true, encoding: .utf8)
|
|
let before = try String(contentsOf: identityURL, encoding: .utf8)
|
|
|
|
let identity = DeviceIdentityStore.loadOrCreate(fileURL: identityURL)
|
|
|
|
#expect(identity.deviceId != "stale-device-id")
|
|
#expect(try String(contentsOf: identityURL, encoding: .utf8) == before)
|
|
}
|
|
|
|
private static func base64UrlDecode(_ value: String) -> Data? {
|
|
let normalized = value
|
|
.replacingOccurrences(of: "-", with: "+")
|
|
.replacingOccurrences(of: "_", with: "/")
|
|
let padded = normalized + String(repeating: "=", count: (4 - normalized.count % 4) % 4)
|
|
return Data(base64Encoded: padded)
|
|
}
|
|
|
|
private static func identityJSON(publicKeyPem: String, privateKeyPem: String) throws -> String {
|
|
let object: [String: Any] = [
|
|
"version": 1,
|
|
"deviceId": "stale-device-id",
|
|
"publicKeyPem": publicKeyPem,
|
|
"privateKeyPem": privateKeyPem,
|
|
"createdAtMs": 1_700_000_000_000,
|
|
]
|
|
let data = try JSONSerialization.data(withJSONObject: object, options: [.prettyPrinted, .sortedKeys])
|
|
return String(decoding: data, as: UTF8.self) + "\n"
|
|
}
|
|
|
|
private static func pem(label: String, body: String) -> String {
|
|
"-----BEGIN \(label)-----\n\(body)\n-----END \(label)-----\n"
|
|
}
|
|
}
|