Repository navigation
Restore USB sample timing guard, add usage homepage, bump advisories - #3
Merged
Merged
Conversation
The C reference driver discards any 512-byte sample whose USB write+read round trip exceeds MAX_MICROSEC_FOR_SAMPLES (5 ms), because a stalled bit-bang clock lets the INM's analog loop settle and lowers the entropy of the following bits. The infnoise-rs port dropped that check. Restore it in the reader loop for both warm-up and steady state, configurable via NAAS_MAX_SAMPLE_MICROS (default 5000), with rejections counted in a new per-device naas_timing_rejections_total counter. Serve a plain HTML usage page at / on the API listener. No stylesheet; the request limit, version and multiplier are baked in from the live config at startup so the page always matches what the server enforces. Bump dependencies flagged by cargo deny: h2 0.4.14 -> 0.4.19 RUSTSEC-2026-0258 anyhow 1.0.102 -> 1.0.104 RUSTSEC-2026-0190 crossbeam-epoch 0.9.18 -> 0.9.20 RUSTSEC-2026-0204 metrics 0.24.5 -> 0.24.6 yanked release Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NqAaMnufxqQd4ggw9duAMF
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-ups from a security review of the
infnoise-rsport against the C reference driver.Restore the sample timing guard. The C
readDatadiscards any sample whose USB write+read round trip exceedsMAX_MICROSEC_FOR_SAMPLES(5 ms), since a stalled bit-bang clock lets the INM's analog loop settle and reduces entropy in the following bits. The port dropped this. It is now applied in the reader loop during warm-up and steady state, configurable viaNAAS_MAX_SAMPLE_MICROS/--max-sample-micros(default 5000). Rejections count in a new per-device counternaas_timing_rejections_total.Usage homepage at
/. Plain HTML, no stylesheet. Lists endpoints, curl examples, status codes, and a description of how bytes are produced. The request cap, version, and multiplier are baked in from the live config at startup.Dependency bumps flagged by
cargo deny check advisories(the CI deny job was failing on these):Deploy note
The 5 ms threshold could not be exercised on hardware here. It matches what the C driver uses on the same device, but INTEGRATION.md quotes a ~16 ms USB latency figure that, if literal, would trip the guard on every sample. Watch
naas_timing_rejections_totalafter the first deploy; if it climbs alongside falling entropy throughput, raise the limit rather than disabling it.Test plan
cargo fmt --check,cargo clippy --all-targets --all-features -- -D warnings,cargo build --releasecargo deny check advisoriesclean/returns 200text/htmlwith the correct limit and multiplier;/api/v1/random/0and an over-limit request return 400; the new counter appears in/metricsnaas_timing_rejections_totalstays near zero under normal load🤖 Generated with Claude Code
https://claude.ai/code/session_01NqAaMnufxqQd4ggw9duAMF