Skip to content

Restore USB sample timing guard, add usage homepage, bump advisories - #3

Merged
michaelpeterswa merged 1 commit into
mainfrom
feat/timing-guard-and-index
Sep 3, 2026
Merged

michaelpeterswa merged 1 commit into
mainfrom
feat/timing-guard-and-index

Conversation

@michaelpeterswa

Copy link
Copy Markdown
Member

Summary

Follow-ups from a security review of the infnoise-rs port against the C reference driver.

  • Restore the sample timing guard. The C readData discards any sample whose USB write+read round trip exceeds MAX_MICROSEC_FOR_SAMPLES (5 ms), since a stalled bit-bang clock lets the INM's analog loop settle and reduces entropy in the following bits. The port dropped this. It is now applied in the reader loop during warm-up and steady state, configurable via NAAS_MAX_SAMPLE_MICROS / --max-sample-micros (default 5000). Rejections count in a new per-device counter naas_timing_rejections_total.

  • Usage homepage at /. Plain HTML, no stylesheet. Lists endpoints, curl examples, status codes, and a description of how bytes are produced. The request cap, version, and multiplier are baked in from the live config at startup.

  • Dependency bumps flagged by cargo deny check advisories (the CI deny job was failing on these):

    Crate Issue Now
    h2 RUSTSEC-2026-0258 0.4.19
    anyhow RUSTSEC-2026-0190 1.0.104
    crossbeam-epoch RUSTSEC-2026-0204 0.9.20
    metrics yanked release 0.24.6

Deploy note

The 5 ms threshold could not be exercised on hardware here. It matches what the C driver uses on the same device, but INTEGRATION.md quotes a ~16 ms USB latency figure that, if literal, would trip the guard on every sample. Watch naas_timing_rejections_total after the first deploy; if it climbs alongside falling entropy throughput, raise the limit rather than disabling it.

Test plan

  • cargo fmt --check, cargo clippy --all-targets --all-features -- -D warnings, cargo build --release
  • cargo deny check advisories clean
  • Local run without hardware: / returns 200 text/html with the correct limit and multiplier; /api/v1/random/0 and an over-limit request return 400; the new counter appears in /metrics
  • On hardware: confirm naas_timing_rejections_total stays near zero under normal load

🤖 Generated with Claude Code

https://claude.ai/code/session_01NqAaMnufxqQd4ggw9duAMF

The C reference driver discards any 512-byte sample whose USB write+read
round trip exceeds MAX_MICROSEC_FOR_SAMPLES (5 ms), because a stalled
bit-bang clock lets the INM's analog loop settle and lowers the entropy
of the following bits. The infnoise-rs port dropped that check. Restore
it in the reader loop for both warm-up and steady state, configurable via
NAAS_MAX_SAMPLE_MICROS (default 5000), with rejections counted in a new
per-device naas_timing_rejections_total counter.

Serve a plain HTML usage page at / on the API listener. No stylesheet;
the request limit, version and multiplier are baked in from the live
config at startup so the page always matches what the server enforces.

Bump dependencies flagged by cargo deny:
  h2 0.4.14 -> 0.4.19            RUSTSEC-2026-0258
  anyhow 1.0.102 -> 1.0.104      RUSTSEC-2026-0190
  crossbeam-epoch 0.9.18 -> 0.9.20  RUSTSEC-2026-0204
  metrics 0.24.5 -> 0.24.6       yanked release

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NqAaMnufxqQd4ggw9duAMF
@michaelpeterswa
michaelpeterswa merged commit 3ac5eed into main Sep 3, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant