Skip to content

transport: reset sessions on connect - #13

Merged
benma merged 1 commit into
BitBoxSwiss:masterfrom
benma-agent:benma-agent/reset-session
Sep 29, 2026
Merged

benma merged 1 commit into
BitBoxSwiss:masterfrom
benma-agent:benma-agent/reset-session

Conversation

@benma-agent

@benma-agent benma-agent commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Disconnecting after an intermediate signing response leaves the firmware
waiting for a continuation while the device stays powered. On reconnect,
the old workflow consumes the first unlock request and returns an
encrypted error. Pairing can still succeed because the unlock response is
ignored, masking the stale session.

Send HWW_REQ_RESET (0x03) after version discovery and before unlock and
Noise pairing on firmware v9.28.0 or newer. Keep the helper private, retry
BUSY responses once per second, and require an ACK without a payload.
Older firmware keeps its existing connection flow. Invalid reset replies
use the internal resetSession code and surface as
communication error: error resetting session through the public API.

Add unit coverage for the version gate, startup order, BUSY retries,
malformed reset replies and public error mapping. Add a simulator
regression that disconnects with signing unfinished, reconnects to the
same running process, checks the real unlock response, pairs, and reads
the root fingerprint.

Firmware counterpart: BitBoxSwiss/bitbox02-firmware#2111

Related client PRs in this change:

@bznein bznein left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK

Disconnecting after an intermediate signing response leaves the firmware
waiting for a continuation while the device stays powered. On reconnect,
the old workflow consumes the first unlock request and returns an
encrypted error. Pairing can still succeed because the unlock response is
ignored, masking the stale session.

Send HWW_REQ_RESET (0x03) after version discovery and before unlock and
Noise pairing on firmware v9.28.0 or newer. Keep the helper private, retry
BUSY responses once per second, and require an ACK without a payload.
Older firmware keeps its existing connection flow. Invalid reset replies
use the internal `resetSession` code and surface as
`communication error: error resetting session` through the public API.

Add unit coverage for the version gate, startup order, BUSY retries,
malformed reset replies and public error mapping. Add a simulator
regression that disconnects with signing unfinished, reconnects to the
same running process, checks the real unlock response, pairs, and reads
the root fingerprint.

Firmware counterpart: BitBoxSwiss/bitbox02-firmware#2111

Related client PRs in this change:

- [Go #187](BitBoxSwiss/bitbox02-api-go#187)
- [Rust #134](BitBoxSwiss/bitbox-api-rs#134)
@benma-agent
benma-agent force-pushed the benma-agent/reset-session branch from 6b473fd to 0989eff Compare September 29, 2026 10:13
@benma
benma merged commit 9f6d07f into BitBoxSwiss:master Sep 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants