red-team send-path hardening: hold pada verify False/None, _send_rejected whitelist, fee guard, non-dict skip (V61/B20-B23)

This commit is contained in:
proitlab committed 2026-08-13 23:12:51 +07:00
1 parent 69704fa23d
commit d6b5927307
8 files changed
+182 -32

No files matched your search

+29 -1
View File
@@ -39,7 +39,10 @@ class FakeSigned:
def send(self):
if self._exc is not None:
raise self._exc
return {'processed': True}
# V61: bentuk sukses nodeos asli (whitelist `_send_rejected` di
# `_send_fee` butuh `transaction_id` + receipt `executed`).
return {'transaction_id': self._txid,
'processed': {'receipt': {'status': 'executed'}}}
def fresh_db(tag):
@@ -587,6 +590,31 @@ def main():
check('V34 resume → sent',
last_claim_row()[5] == 'sent' and last_claim_row()[6] == 'txr1')
# ————— V61: fee ditolak chain (HTTP-500 body, V46/B11) → ⊖ 'sent' —————
# `_send_fee` ⊖ boleh tandai 'sent' utk fee yang chain TOLAK — pyntelope
# mengembalikan 500 sbg body, ⊖ raise (V61-F1). Fee harus tersisa
# 'failed' utk diulang, ⊖ pernah 'sent' dgn txid yg ⊥ mendarat.
fresh_db('feereject')
db.record_claim('2026-08-05', 'txz', 10.0, 1.0, 'failed',
'2026-08-05T08:00:00')
class FakeFeeReject:
def id(self):
return 'txfeej'
def send(self):
return {'code': 500, 'error': {'what': 'duplicate transaction'}}
dist.build_signed_transfer = (lambda to, amount, memo:
FakeFeeReject())
dist.verify_txid = lambda txid: False # txid penolakan ⊥ mendarat
check('V61 fee rejection-500 → fee_failed (⊥ sent)',
claim.step() == 'fee_failed')
row = last_claim_row()
check('V61 fee rejection → status failed (diulang), ⊖ sent',
row[5] == 'failed')
dist.build_signed_transfer = lambda to, amount, memo: FakeSigned('txr1')
# ————— V36: klaim reward → kanal INTERNAL saja, ⊥ komunitas —————
tg = {'posts': []}